
Senior Security Engineer – Pentester
Posted Aug 4

Posted Aug 4
This is a fully remote position, open to applicants in Canada.
• Perform comprehensive penetration tests on products within AWS and GCP environments, collaborating with a fellow pentester.
• Evaluate IAM policies, service configurations, and cloud-native permission architectures within the Control Plane against established security standards.
• Conduct dynamic testing on web interfaces and API endpoints throughout the Data Plane and Web UI.
• Analyze the security posture of hybrid infrastructures that include both containers and virtual machines.
• Prioritize findings and produce clear, reproducible proofs of concept.
• Collaborate with product teams to articulate risks and facilitate remediation efforts.
• Leverage AI and large language models to streamline reconnaissance, generate attack vectors, analyze configurations, and prepare vulnerability reports.
• Supervise bug bounty pipelines and external reports, verify findings, and manage communications with researchers.
• Ensure rigorous security testing of product features and multi-cloud infrastructures prior to release.
• Monitor assessment coverage, triage efficiency, vulnerability escape rates, time savings attributed to AI assistance, and report quality.
• In-depth architectural knowledge of GCP and AWS.
• Capability to conduct manual reviews of intricate IAM and resource hierarchies.
• Familiarity with native cloud APIs or CSPM frameworks.
• Proven track record in auditing and fortifying GKE Autopilot/Standard, EKS, ECS, Kubernetes, k3s, and OCI-runc workloads.
• Demonstrated experience in integrating AI/LLM tools like Gemini and Claude into the pentesting workflow.
• Expert understanding of web application security and offensive testing techniques.
• Extensive knowledge of OWASP Top 10 vulnerabilities, exploitation of modern web frameworks, and REST/WebSocket API security.
• Proficient hands-on experience with Burp Suite Professional, OWASP ZAP, or comparable tools.
• Knowledgeable in CSP, CORS, SameSite cookies, Subresource Integrity, OAuth 2.0, OIDC, JWT, HSTS, X-Frame-Options, and Permissions-Policy.
• Ability to spot complex vulnerabilities beyond the reach of automated scanners and validate them with proofs of concept.
• Proficiency in programming languages such as Python, Go, or Bash.
• Strong understanding of Terraform, cloud-native deployment models, and HCL auditing.
• Capable of producing high-quality technical reports for product teams.
• Experience with Gatekeeper policies and Binary Authorization is a plus.
• Base salary range of 158,000 CAD - 237,000 CAD.
• Eligibility for stock-based compensation grants contingent upon company and individual performance.
• Engaging, inclusive, and enjoyable workplace culture.
• Opportunities to take initiative and introduce innovative ideas.
• Supportive communication and encouragement for new suggestions.
Legacy Community Health
NeoGuardian
Fresh Consulting
CrowdStrike
Get handpicked remote jobs straight to your inbox weekly.