Jobs.ca
Jobs.ca
Language
Jobgether logo

Senior Security Engineer - Pentester

Jobgetherabout 17 hours ago
Remote
Canada
Senior Level
Full-Time

Top Benefits

Stock-based compensation
Comprehensive benefits package
Fully remote work

About the role

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer - Pentester based in Canada. The Senior Security Engineer - Pentester will play a critical role in strengthening product security through advanced offensive testing, cloud security assessments, and vulnerability analysis. This position focuses on identifying and mitigating security risks across complex multi-cloud environments, applications, APIs, and infrastructure platforms. You will work closely with engineering and security teams to validate security controls, improve resilience, and support secure product releases. The role combines deep technical expertise with modern security practices, including AI-assisted security testing and automation. As a security specialist, you will help uncover vulnerabilities, communicate risks clearly, and influence security improvements across the organization. This is an opportunity to contribute to a high-impact cybersecurity environment where innovation, speed, and technical excellence are highly valued. \n

Accountabilities

Conduct comprehensive penetration tests across applications, APIs, cloud environments, and infrastructure components to identify security vulnerabilities before product releases. Assess security controls across multi-cloud environments, including AWS and GCP architectures, cloud configurations, IAM policies, and resource permissions. Review and test cloud-native systems, container environments, virtual machines, and hybrid infrastructure for security weaknesses. Perform dynamic security testing of web applications, APIs, and user interfaces using industry-standard offensive security methodologies. Analyze findings, develop reproducible proof-of-concepts, and provide clear remediation guidance to engineering and product teams. Collaborate with penetration testing and cloud security teams to execute targeted security assessments aligned with release timelines. Monitor and triage vulnerability reports from bug bounty programs and external researchers, validating findings and coordinating responses. Use AI and large language models to accelerate reconnaissance, generate attack scenarios, analyze configurations, improve testing efficiency, and support vulnerability reporting. Develop automation scripts and security tooling to streamline vulnerability discovery, validation processes, and recurring security assessments. Review Infrastructure as Code configurations, including Terraform deployments, to identify potential security risks before implementation. Support improvements to security practices by identifying recurring issues, recommending solutions, and helping teams adopt secure development approaches. Create high-quality technical documentation and security reports that communicate risks, findings, and recommendations effectively to technical and non-technical stakeholders.

Requirements

Strong professional experience in security engineering, penetration testing, offensive security, application security, or a related cybersecurity discipline. Deep understanding of cloud security concepts with hands-on experience assessing AWS and GCP environments, including IAM, resource permissions, and cloud-native services. Proven experience securing and testing containerized environments, including managed platforms such as Kubernetes, GKE, EKS, or ECS, as well as unmanaged container workloads. Expert knowledge of web application security principles, OWASP Top 10 vulnerabilities, API security, and modern exploitation techniques. Extensive hands-on experience with manual security testing tools such as Burp Suite Professional, OWASP ZAP, or similar solutions. Strong understanding of browser security mechanisms, including CSP, CORS, SameSite cookies, Subresource Integrity, authentication flows, OAuth 2.0, OIDC, JWT, and security headers. Ability to identify complex vulnerabilities beyond automated scanner results, validate findings, and create effective proof-of-concept demonstrations. Experience using AI-assisted security tools and large language models to improve penetration testing workflows, research, automation, and reporting. Strong scripting and automation skills using Python, Go, Bash, or similar programming languages. Experience reviewing and auditing Infrastructure as Code, particularly Terraform and cloud deployment configurations. Understanding of security automation, vulnerability management processes, and secure software development practices. Strong analytical and problem-solving abilities with excellent attention to detail. Ability to communicate complex technical risks clearly through high-quality reports and presentations. Experience with security policy enforcement tools such as Gatekeeper or Binary Authorization is considered an asset.

Benefits

Competitive base salary range of CAD 158,000 to CAD 237,000, depending on experience, skills, qualifications, and location. Eligibility for stock-based compensation opportunities based on company and individual performance. Comprehensive benefits package. Fully remote work opportunity from Canada. Opportunity to work on advanced cybersecurity challenges protecting critical enterprise environments. Collaborative and inclusive culture focused on innovation, technical excellence, and continuous learning. Opportunity to influence security practices, tooling, and engineering processes at scale. Environment that encourages creativity, initiative, and ownership of impactful security initiatives.

\n How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time. #LI-CL1

About Jobgether

Internet Marketplace Platforms
11-50
Founded in 2019

Your future of work, like you've always dreamt it, is now possible with Jobgether !

The Covid crisis has accelerated its revolution but work, as we knew it, doesn't exist anymore. Tomorrow, jobs will be hybrid, remote and asynchronous. Flexibility will be the norm.

Jobgether helps you find your next remote job, wherever you are.

Similar Jobs