Remotery

Senior Security Engineer – Pentester

Posted Aug 4

This is a fully remote position, open to applicants in Canada.

📋 Description

• Perform comprehensive penetration tests on products within AWS and GCP environments, collaborating with a fellow pentester.

• Evaluate IAM policies, service configurations, and cloud-native permission architectures within the Control Plane against established security standards.

• Conduct dynamic testing on web interfaces and API endpoints throughout the Data Plane and Web UI.

• Analyze the security posture of hybrid infrastructures that include both containers and virtual machines.

• Prioritize findings and produce clear, reproducible proofs of concept.

• Collaborate with product teams to articulate risks and facilitate remediation efforts.

• Leverage AI and large language models to streamline reconnaissance, generate attack vectors, analyze configurations, and prepare vulnerability reports.

• Supervise bug bounty pipelines and external reports, verify findings, and manage communications with researchers.

• Ensure rigorous security testing of product features and multi-cloud infrastructures prior to release.

• Monitor assessment coverage, triage efficiency, vulnerability escape rates, time savings attributed to AI assistance, and report quality.


⛳️ Requirements

• In-depth architectural knowledge of GCP and AWS.

• Capability to conduct manual reviews of intricate IAM and resource hierarchies.

• Familiarity with native cloud APIs or CSPM frameworks.

• Proven track record in auditing and fortifying GKE Autopilot/Standard, EKS, ECS, Kubernetes, k3s, and OCI-runc workloads.

• Demonstrated experience in integrating AI/LLM tools like Gemini and Claude into the pentesting workflow.

• Expert understanding of web application security and offensive testing techniques.

• Extensive knowledge of OWASP Top 10 vulnerabilities, exploitation of modern web frameworks, and REST/WebSocket API security.

• Proficient hands-on experience with Burp Suite Professional, OWASP ZAP, or comparable tools.

• Knowledgeable in CSP, CORS, SameSite cookies, Subresource Integrity, OAuth 2.0, OIDC, JWT, HSTS, X-Frame-Options, and Permissions-Policy.

• Ability to spot complex vulnerabilities beyond the reach of automated scanners and validate them with proofs of concept.

• Proficiency in programming languages such as Python, Go, or Bash.

• Strong understanding of Terraform, cloud-native deployment models, and HCL auditing.

• Capable of producing high-quality technical reports for product teams.

• Experience with Gatekeeper policies and Binary Authorization is a plus.


🏝️ Benefits

• Base salary range of 158,000 CAD - 237,000 CAD.

• Eligibility for stock-based compensation grants contingent upon company and individual performance.

• Engaging, inclusive, and enjoyable workplace culture.

• Opportunities to take initiative and introduce innovative ideas.

• Supportive communication and encouragement for new suggestions.

People also viewed

Legacy Community Health3 days ago

IT Security Engineer

US flagTexas OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
NeoGuardian3 days ago

Cyber Security Engineer I – Blue Team

BR flagBrazil OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Fresh Consulting3 days ago

Staff Software Engineer – Security, Cryptography

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
CrowdStrike4 days ago

Staff AI Security Scientist

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$235k – $350k/year
ApplyView job
CrowdStrike4 days ago

Security Advisor, Falcon Complete

AU flagAustralia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Supply Chimp4 days ago

Cybersecurity Specialist

PH flagPhilippines OnlyFull-timeCybersecurity / Security EngineerPHP 62.5k/month
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers