Penetration Testing Analyst
The Penetration Testing Analyst will perform hands-on security testing of applications, infrastructure, and systems while producing detailed reports on vulnerabilities and remediation. The role also involves supporting Red Team activities and contributing to adversary simulation exercises.
- On-site
- Toronto, ON
- Posted Aug 6, 2026
- Apply by Dec 31, 2026
- 1 position
Job summary
You are as unique as your background, experience and point of view. Here, you’ll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll have new and exciting opportunities to make life brighter for our Clients - who are at the heart of everything we do. At Sun Life, we're driven by our Purpose: helping our Clients achieve lifetime financial security and live healthier lives. Our values shape how we work: caring, authentic, bold, inspiring, and impactful. When you join Sun Life, you'll work with passionate colleagues and empowering leaders who support your growth and celebrate your contributions, so you can make a meaningful difference in our Clients' lives. Discover how you can make a difference in the lives of individuals, families and communities around the world. Job Description: At Sun Life, we work together, share common values, and encourage growth and achievement. We are seeking a skilled Penetration Testing Analyst to perform hands-on security testing of applications, infrastructure, and systems. This role is primarily focused on Penetration Testing delivery, with secondary exposure to Red Team activities, contributing to adversary simulation exercises where required. The successful candidate will have strong technical testing capabilities, with an interest in developing broader offensive security skills. Key Responsibilities Perform web, API, mobile, and infrastructure penetration testing across enterprise applications. Identify, exploit, and validate security vulnerabilities using manual testing techniques and industry tools. Conduct testing in line with established methodologies and security frameworks (e.g., OWASP). Produce clear, structured reports outlining: Vulnerabilities and root cause Business impact and risk rating Practical remediation recommendations Perform research into new vulnerabilities, exploits, and attack techniques to enhance testing coverage. Support re-testing activities to validate remediation of identified issues. Support Red Team activities where required. Contribute to reconnaissance and attack surface mapping, Identification of potential attack paths. Support documentation of attack paths and identified security gaps. Assist in controlled exploitation activities under guidance, including: Initial access techniques Limited post-exploitation validation (e.g., privilege escalation concepts, lateral movement awareness) Collaborate with senior team members to understand real-world attacker behaviour and techniques. Required Skills & Experience Core Penetration Testing Skills (Essential) 2+ years of hands-on experience in: Web application security testing (OWASP Top 10) API security testing Basic network/infrastructure testing Strong understanding of: Authentication, session management, and access control flaws Input validation and injection vulnerabilities Experience with tools such as: Burp Suite, Nmap, sqlmap, or similar Ability to perform manual testing beyond automated scanning. Strong documentation and reporting skills, with focus on clear risk articulation. Red Teaming Skills (Desirable – Foundational Level) Basic understanding of adversary simulation concepts and attack lifecycle. Familiarity with: Reconnaissance techniques Common initial compromise methods Awareness of: Privilege escalation and lateral movement concepts Attack paths across enterprise environments Interest in developing Red Team and offensive security capabilities over time. Qualifications Bachelor's degree in Computer Science, Information Security, or a related field. Certifications such as OSCP, OSWA, CISSP or CompTIA are desired but not required. Job Category: IT - Technology Services Posting End Date: 30/12/2026
What you’ll do
The Penetration Testing Analyst will perform hands-on security testing of applications, infrastructure, and systems while producing detailed reports on vulnerabilities and remediation. The role also involves supporting Red Team activities and contributing to adversary simulation exercises.
Requirements
Candidates must have at least 2 years of experience in web, API, and network security testing along with proficiency in industry-standard tools like Burp Suite and Nmap. A bachelor's degree in Computer Science or Information Security is required, and professional certifications such as OSCP or CISSP are highly desired.
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Penetration testing
- Web application security
- API security
- Network security
- Infrastructure testing
- Burp Suite
- Nmap
- Sqlmap
- OWASP Top 10
- Vulnerability assessment
- Red teaming
- Adversary simulation
- Reporting
- Risk assessment
- Manual testing
- Red Teaming
- Network Infrastructure
- CompTIA Certification
- Attack Surface Management
- Research
- Access Controls
- Application Programming Interface (API)
- Penetration Testing
- Authentications
- Automation
- Business Continuity Planning
- Certified Information Systems Security Professional
- Computer Science
- Data Validation
- Manual Testing
- Offensive Security
- Offensive Security Certified Professional
- Open Web Application Security Project (OWASP)
- Privilege Escalation
- Reconnaissance
- Web Application Security
- Security Testing
Job areas
- Security & Safety
- Technology
- Software
- Penetration Tester
- Vulnerability Analyst / Penetration Tester
- Database and Network Professionals Not Elsewhere Classified
- Penetration Testers
- Computer Occupations, All Other
Additional details
- Minimum education
- Professional degree
- Minimum experience
- 2+ years
- Apply by
- Dec 31, 2026
- Posting language
- English
- Working hours
- 40 hours per week
