17 Sep
|
SecuSolutions
|
Calgary
17 Sep
SecuSolutions
Calgary
About SecuSolutions
SecuSolutions is a Canadian cybersecurity firm with more than 27 years of experience helping organizations protect critical systems, infrastructure and data. Our team supports clients across Canada and the United States, ranging from small and mid-sized businesses and municipalities to large enterprises and critical-infrastructure environments.
SecuSolutions is a boutique cybersecurity firm built around a highly specialized and experienced team. We work with organizations of every size, from municipalities and small and mid-sized businesses through to large enterprise and critical-infrastructure clients. Many members of our team have been with SecuSolutions for well over a decade, with some approaching or exceeding two decades with the company.
That continuity has created a strong culture of trust, collaboration and deep technical knowledge. At the same time, SecuSolutions continues to grow, with an expanding client base and partner network across both Canada and the United States.
Our offensive security work is hands-on, independent and focused on meaningful security outcomes. We are not a “check-the-box” penetration testing firm. Automated tooling supports our methodology, but it does not replace manual testing, validation, exploitation and professional judgment. The Role
We are looking for a senior web application penetration tester who can manually conduct secure source code reviews and penetration testing at an advanced level. The successful candidate will work across diverse customer environments and will be expected to combine technical depth with sound judgment and transparent client communication.
Key Responsibilities
- Perform manual source-code reviews to identify, exploit, and document vulnerabilities and design weaknesses.
- Conduct comprehensive penetration testing of web applications, APIs, mobile applications, network services and supporting infrastructure as applicable to the engagement.
- Perform manual testing to identify vulnerabilities that automated tools may miss, including business-logic flaws, authorization weaknesses, chained attack paths and application-specific issues.
- Identify and validate vulnerabilities aligned with recognized standards and methodologies, including OWASP guidance, and provide practical remediation recommendations.
- Use offensive-security tools responsibly and effectively, such as Burp Suite and other appropriate commercial or open-source tooling.
- Prepare clear and technically accurate penetration-testing reports containing executive summaries, findings, evidence, risk ratings and remediation guidance.
- Present findings to both technical and non-technical stakeholders and explain risk, exploitability, business impact and remediation options.
- Collaborate closely with other consultants and technical team members, contributing to shared methodologies, tooling and knowledge.
- Limited participation in scoping and technical walkthroughs
- Research emerging attack techniques, vulnerabilities, application-security trends and offensive-security tooling, and contribute improvements to internal practices.
Technical Qualifications & Experience
- Experience manually reviewing source code and reasoning about security issues across application logic and supporting components.
- A university degree is not required. Demonstrated capability, experience, curiosity and technical depth are valued more highly than formal academic credentials.
- Strong understanding of web and mobile application architecture, software-development principles and common application-security weaknesses.
- Hands-on knowledge of OWASP Top 10, OWASP Web Security Testing Guide, OWASP API Security Top 10 and related application-security practices.
- Experience testing authentication, authorization, session management, access control, REST/GraphQL APIs and modern web application architectures.
- Familiarity with common authentication and federation technologies such as OAuth, OIDC and SAML is an asset.
- Full stack development experience (non-Ai assisted) is a major asset
- Proficiency with HTTP/HTTPS, HTML, JavaScript, CSS, JSON, REST and other technologies used to deliver modern web services.
- Working knowledge of Windows and Linux operating systems and service administration.
- Familiarity with cloud platforms and modern deployment technologies such as AWS, Azure, Google Cloud, containers, Kubernetes, CI/CD and infrastructure-as-code is an asset.
- Experience with AI-enabled applications, LLM integrations, agentic workflows or emerging AI-security risks is considered an asset.
Certifications
Relevant offensive-security certifications are considered assets, including OSCP, OSWE, OSEP, PNPT, GIAC certifications or equivalent demonstrated experience. Certifications are not a substitute for proven technical capability. SecuSolutions supports continued professional development and role-appropriate certification.
Skilled Skills We Value
- Ability to learn new technologies, frameworks and concepts in a self-directed manner.
- Excellent troubleshooting, analytical and problem-solving capability.
- Clear written and verbal communication in English, with the ability to translate technical issues into understandable business risk.
- Professional, confident client communication and strong customer-service instincts.
- Ability to work independently while contributing effectively within a remote, collaborative team.
- Strong time management, organization and ownership of assigned engagements.
- Curiosity, initiative and a genuine motivation to continuously improve technical capability.
- Comfort working in a consulting environment across multiple customer technologies and industries.
What Success Looks Like
- Deliver technically thorough engagements within agreed scope and timelines.
- Identify meaningful vulnerabilities beyond automated scanning results and explain how issues could be exploited in the real world.
- Produce reports that are accurate, defensible, understandable and useful to clients.
- Communicate complex vulnerabilities clearly to technical teams, management and executives.
- Maintain strong client relationships through professionalism, responsiveness and technical credibility.
- Continuously improve testing methodology, tooling and internal knowledge.
- Support fellow team members and contribute to the collective capability of the SecuSolutions offensive-security practice.
What We Offer
- A remote-first working environment, with access to our Calgary office if desired.
- Join a stable, highly experienced team with exceptionally strong employee tenure, while being part of a company that continues to expand its presence across Canada and the United States.
- Exposure to a broad range of technologies, industries and customer environments, from mid-sized organizations through large enterprises and critical infrastructure.
- Real penetration-testing engagements with carefully defined scopes that allow our team to perform meaningful technical work rather than simply generate scanner output.
- An experienced, collaborative, offensive-security team that actively shares knowledge and supports professional growth.
- Support for continued education, role-relevant certifications and advancement of technical goals.
- A culture where team members are encouraged to challenge existing methodologies, improve tools and processes, and bring forward new ideas.
- Opportunities to expand into additional offensive-security disciplines as skills and interests develop.
Professional Ethics, Authorization & Confidentiality
Candidates must demonstrate strong professional ethics, discretion, respect for client confidentiality and discipline when handling sensitive customer information and testing data. Depending on client requirements, background or security screening may be required for certain engagements.
Our Approach
We are looking for people who understand how systems can actually be compromised, not simply whether a scanner can flag an issue. If you enjoy digging into applications, finding weaknesses others miss, explaining what those weaknesses mean and helping clients become more resilient, we would like to hear from you.
📌 Senior Web Application Penetration Tester (Calgary)
🏢 SecuSolutions
📍 Calgary