Security and API Test Specialist
The specialist will design and execute API and security test scenarios to validate the integrity and performance of system integrations during a cloud migration. They are also responsible for identifying vulnerabilities, producing governance reports, and mentoring team members on testing best practices.
- Hybrid
- Winnipeg, MB
- Posted Jul 30, 2026
- 1 position
Job summary
Who We Are PLATO is Canada’s largest Indigenous-owned software testing and technology services company. For nearly 30 years, our expert teams have helped our clients deliver reliable products that users enjoy interacting with. Our 100% Canada‑based team brings deep experience in QA, software testing, and IT services, along with a shared commitment to collaboration, mentorship, and continuous improvement. We’re a team that shows up for each other, whether that’s tackling complex client challenges or helping colleagues grow through coaching and knowledge‑sharing. As Canada’s largest Indigenous‑owned software testing company, we’re proud of our roots and our mission to build a stronger, more inclusive technology workforce. At the same time, we warmly welcome applicants of all backgrounds and experiences who are passionate about quality, teamwork, and making an impact. Contract Duration: Sept 1 to Nov 30, 2026 (3 months) Security Clearance: Not required Location: Winnipeg MB preferred, remote may be possible Role Summary The Security and API Test Specialist is responsible for validating the security, reliability, performance, and integrity of APIs and system integrations supporting a cloud migration program. Working with development, integration, cybersecurity, infrastructure, and QA teams, the specialist designs and executes API and security test scenarios, validates authentication and security controls, identifies defects and vulnerabilities, and provides reporting and evidence to support production readiness. The role also contributes to reusable test assets, governance standards, traceability, and operational readiness practices. Key Responsibilities Design, develop, execute, and maintain API, security, and non-functional test plans, scripts, and test suites. Validate APIs, integrations, data flows, interfaces, and end-to-end business processes. Verify authentication, authorization, encryption, and security controls. Perform API functional, integration, security, and performance testing. Utilize approved testing, monitoring, and reporting tools including Azure DevOps, Azure Monitor, Application Insights, Power BI, JMeter, LoadRunner, and approved equivalents. Conduct SAST, DAST, SCA, vulnerability assessments, penetration testing, and API security testing Analyze results, identify defects, vulnerabilities, bottlenecks, and root causes, and support remediation efforts. Collaborate with developers, architects, infrastructure, cybersecurity, and business stakeholders. Produce reports, dashboards, metrics, and test evidence for governance and production-readiness decisions. Support monitoring, troubleshooting, risk assessment, continuous improvement, mentoring, and testing best practices. Requirements Computer Science degree or equivalent experience. 5+ years of proven experience designing and executing large-scale API and security testing initiatives using industry-standard tools. Strong experience in API Testing, Security Testing, and Performance Testing. Experience with: API functional, integration, and end-to-end testing Authentication, authorization, encryption, and access control validation Baseline and benchmark testing Load, stress, spike, soak/endurance, scalability, and capacity testing Failover, recovery, and disaster recovery validation Integration and data migration performance testing SAST, DAST, SCA, vulnerability assessments, and penetration testing Familiarity with Azure DevOps, Azure Monitor, Application Insights, Power BI, Fortify, SonarQube, Checkmarx, Burp Suite, OWASP ZAP, Snyk, Black Duck, Mend, Nessus, Nmap, or equivalent tools. Strong troubleshooting, analytical, and root-cause analysis skills. Self-motivated, adaptable, and able to manage multiple priorities and deliverables. Strong verbal and written communication/documentation skills, experience with IT Consulting is preferred. Work With Us At PLATO, we believe that great work happens when people feel supported, connected, and challenged in the right ways. You’ll be part of a collaborative environment where experienced professionals share knowledge, mentor others, and contribute to solving complex, real‑world client projects. We are committed to inclusive hiring practices and encourage applications from individuals of all backgrounds, including women, persons with disabilities, visible minorities, and Indigenous peoples. If you require accommodation at any stage of the recruitment process, we’re here to support you. PLATO respectfully acknowledges that we operate on treaty territories, unceded First Nations and Inuit territories, and within Métis homelands. We honour the long history of these lands and actively work toward reconciliation between Indigenous and non‑Indigenous peoples on Turtle Island.
What you’ll do
The specialist will design and execute API and security test scenarios to validate the integrity and performance of system integrations during a cloud migration. They are also responsible for identifying vulnerabilities, producing governance reports, and mentoring team members on testing best practices.
Requirements
Candidates must hold a Computer Science degree or equivalent and possess at least 5 years of experience in large-scale API and security testing. Proficiency with industry-standard tools like Azure DevOps, JMeter, and various security scanning software is required.
Other relevant skills
Identified from the job description. Confirm important requirements above.
- API Testing
- Security Testing
- Performance Testing
- Azure DevOps
- Azure Monitor
- Application Insights
- Power BI
- JMeter
- LoadRunner
- SAST
- DAST
- SCA
- Vulnerability Assessment
- Penetration Testing
- Troubleshooting
- Root-cause Analysis
- Non-Functional Testing
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Cloud Migration
- Production Readiness
- Black Duck
- Self-Motivation
- Access Controls
- Application Programming Interface (API)
- Software Testing
- Authentications
- Reconciliation
- Burp Suite
- Dashboard
- Business Process
- Computer Science
- Consulting
- Continuous Improvement Process
- Security Controls
- Cyber Security
- Data Migration
- Encryption
- Disaster Recovery
- Failover
- Traceability
- Governance
- Scalability
- Micro Focus LoadRunner
- IT Service Management
- Apache JMeter
- Mentorship
- Nmap
- Open Web Application Security Project (OWASP)
- Coaching
Job areas
- Technology
- Software
- Consulting
- Security & Safety
- Data & Analytics
- API Tester
- Vulnerability Analyst / Penetration Tester
- Database and Network Professionals Not Elsewhere Classified
- Penetration Testers
- Computer Occupations, All Other
Additional details
- Minimum education
- Bachelor’s degree
- Minimum experience
- 5+ years
- Posting language
- English
- Working hours
- 40 hours per week
