23 Aug
|
Stantec Consulting International
|
Burnaby
23 Aug
Stantec Consulting International
Burnaby
Our business teams include finance, procurement, human resources, information technology, marketing, corporate development, HSSE, real estate, legal, and practice services. Through teamwork and collaboration, we’re building a stronger, more resilient Stantec every day.
The Senior Ethical
Hacker will conduct security assessments on web applications and cloud services by emulating real-world attacks using the Mitre Attack Framework. Their goal is to identify security weaknesses, help prevent data breaches and enhance the security posture by uncovering vulnerabilities, misconfigurations, and risks proactively before they are discovered by threat actors. Collaborate with cross-functional teams (security, engineering, cloud and network operations).
Create reports and communicate findings to various technical teams, architects and engineers. Create and communicate processes that could help engineering teams meet remediation goals. Create and verbally present your test findings in debrief meetings with the C-Suite or sponsors.
Conduct penetration tests on cloud systems, applications and APIs to identify vulnerabilities. Assess cloud/application specific configurations, access controls, and encryption mechanisms. Validate and exploit security findings within web/thick client apps and cloud environments.
Validate various app services, databases, Kubernetes, serverless functions, container instances, Project work/Knowledge Share Assist/Create rules of engagement for recent pen test projects. Establish and enforce security baseline controls through Policy-as-Code implementations Engineer custom Python, Terraform, and Ansible extensions to enable specialized security and Create or populate content in the internal training lab so developers and security champions can stay Minimum 5-7+ years working in some aspect of cybersecurity (Offensive Security,
Red Team Proficient with manual web/cloud penetration testing without using any tools. Proficient writing custom attack tools in Python, PHP, Golang and Bash Scripting.
Proficient building/maintaining attack automation systems (Commercial or Open-Source). Proficient building containers and automation pipelines for attacking purposes. Comfortable working exclusively from Windows or Linux command line.
Comfortable with writing XSS attacks, System/SQL injection payloads or weaponizing binaries. Comfortable attacking various popular public cloud services in (Azure/AWS/GCP/Oracle). Comfortable taking ownership for testing actions and performing blameless post-mortems.
OffSec Web Expert (OSWE) - Preferred GIAC Web Application Penetration Tester (GWAPT) AI/LLM Penetration testing experience Acknowledged findings in a responsible disclosure or public, private Bug Bounty program.
Related
Degree or Certificate, preferably in areas of Offensive Security, AI Red Teaming or Application At Stantec certain roles are bonus eligible. Actual compensation for part-time roles will be pro-rated based on the agreed number of working hours per week. Regular full-time and part-time employees (working at least 20 hours per week) will have access to health, dental, and vision plans, a wellness program, health care spending account, wellness spending account, group registered retirement savings plan, employee stock purchase program, group tax-free savings account, life and accidental death & dismemberment (AD&D;) insurance, short-term/long-term disability plans, emergency travel benefits, tuition reimbursement, professional membership fee coverage, and paid time off.
Temporary/casual employees will have access to group registered retirement savings plan, employee stock purchase program, and group tax-free savings account. BC-1374 IT Services-CA Corporate Business Justification: Replacement Travel: No Schedule: Full time
📌 Senior Penetration Tester |Cybersecurity (Burnaby)
🏢 Stantec Consulting International
📍 Burnaby