Senior Penetration Tester
Lead complex black-box and white-box penetration tests across web applications, APIs, networks, and cloud environments. Develop custom exploits and provide precise reports to guide clients through remediation while mentoring junior testers.
- Hybrid
- North Glengarry, ON
- Posted Aug 1, 2026
- Apply by Aug 31, 2026
- 1 position
Job summary
Careers/Senior Penetration Tester 03 / 07 Senior Penetration Tester Lead complex penetration tests across web applications, infrastructure, cloud environments and other applications. Identify non-obvious vulnerabilities, develop proof-of-concept exploits and produce reports that support effective remediation. Offensive Security Remote / hybrid Baltics Full-time from €2,200 / mo Published2026-06-24 Apply for this role Send your CV and a note to [email protected] What you’ll do Scope and lead black-box and white-box penetration tests covering web applications, APIs, networks, cloud environments and mobile applications. Develop custom exploits, scripts and tools to bypass controls and demonstrate concrete impact. Test manually and in depth beyond automated scanners, combining individual findings into realistic attack paths and business risk. Write precise, reproducible reports and guide clients through remediation. Help shape testing methodology, tooling and quality standards across the team. Mentor junior testers and review their work. What you bring At least four years of penetration-testing or offensive-security experience, including experience leading engagements. Strong across the OWASP Top 10, network and Active Directory attacks, and at least one cloud (Azure/AWS/GCP). Fluency in at least one scripting language, such as Python, Bash or Ruby, for custom tooling and automation. Practical experience with Burp Suite, Nmap, Metasploit, BloodHound and comparable tools. OSCP or equivalent skills, together with strong technical writing in English. Additional advantages Source-code review OT/ICS, mobile or thick-client testing Public Burp/Ghidra extensions CVEs or CTF placings Apply for this roleCareers
What you’ll do
Lead complex black-box and white-box penetration tests across web applications, APIs, networks, and cloud environments. Develop custom exploits and provide precise reports to guide clients through remediation while mentoring junior testers.
Requirements
Requires at least four years of offensive security experience with proficiency in OWASP Top 10, Active Directory, and at least one major cloud provider. Candidates should possess OSCP or equivalent skills and fluency in scripting languages like Python, Bash, or Ruby.
Listed skills
- PythonPreferred
- RubyPreferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Penetration Testing
- Web Application Security
- Infrastructure Security
- Cloud Security
- Exploit Development
- OWASP Top 10
- Active Directory Attacks
- Python
- Bash
- Ruby
- Burp Suite
- Nmap
- Metasploit
- BloodHound
- Technical Writing
- Source-code Review
Job areas
- Security & Safety
- Technology
- Software
- Consulting
- Engineering
Additional details
- Minimum education
- Professional degree
- Minimum experience
- 2+ years
- Apply by
- Aug 31, 2026
- Posting language
- English
- Working hours
- 40 hours per week
- Seniority
- Mid-Senior level
