Back to job search
O
OffSeqVerified Job Source

Senior Penetration Tester

Lead complex black-box and white-box penetration tests across web applications, APIs, networks, and cloud environments. Develop custom exploits and provide precise reports to guide clients through remediation while mentoring junior testers.

  • Hybrid
  • North Glengarry, ON
  • Posted Aug 1, 2026
  • Apply by Aug 31, 2026
  • 1 position

Job summary

Careers/Senior Penetration Tester 03 / 07 Senior Penetration Tester Lead complex penetration tests across web applications, infrastructure, cloud environments and other applications. Identify non-obvious vulnerabilities, develop proof-of-concept exploits and produce reports that support effective remediation. Offensive Security Remote / hybrid Baltics Full-time from €2,200 / mo Published2026-06-24 Apply for this role Send your CV and a note to [email protected] What you’ll do Scope and lead black-box and white-box penetration tests covering web applications, APIs, networks, cloud environments and mobile applications. Develop custom exploits, scripts and tools to bypass controls and demonstrate concrete impact. Test manually and in depth beyond automated scanners, combining individual findings into realistic attack paths and business risk. Write precise, reproducible reports and guide clients through remediation. Help shape testing methodology, tooling and quality standards across the team. Mentor junior testers and review their work. What you bring At least four years of penetration-testing or offensive-security experience, including experience leading engagements. Strong across the OWASP Top 10, network and Active Directory attacks, and at least one cloud (Azure/AWS/GCP). Fluency in at least one scripting language, such as Python, Bash or Ruby, for custom tooling and automation. Practical experience with Burp Suite, Nmap, Metasploit, BloodHound and comparable tools. OSCP or equivalent skills, together with strong technical writing in English. Additional advantages Source-code review OT/ICS, mobile or thick-client testing Public Burp/Ghidra extensions CVEs or CTF placings Apply for this roleCareers

What you’ll do

Lead complex black-box and white-box penetration tests across web applications, APIs, networks, and cloud environments. Develop custom exploits and provide precise reports to guide clients through remediation while mentoring junior testers.

Requirements

Requires at least four years of offensive security experience with proficiency in OWASP Top 10, Active Directory, and at least one major cloud provider. Candidates should possess OSCP or equivalent skills and fluency in scripting languages like Python, Bash, or Ruby.

Listed skills

  • PythonPreferred
  • RubyPreferred

Other relevant skills

Identified from the job description. Confirm important requirements above.

  • Penetration Testing
  • Web Application Security
  • Infrastructure Security
  • Cloud Security
  • Exploit Development
  • OWASP Top 10
  • Active Directory Attacks
  • Python
  • Bash
  • Ruby
  • Burp Suite
  • Nmap
  • Metasploit
  • BloodHound
  • Technical Writing
  • Source-code Review

Job areas

  • Security & Safety
  • Technology
  • Software
  • Consulting
  • Engineering

Additional details

Minimum education
Professional degree
Minimum experience
2+ years
Apply by
Aug 31, 2026
Posting language
English
Working hours
40 hours per week
Seniority
Mid-Senior level