Penetration Tester (Web & Mobile Applications)
Parabellyx Cybersecurity | Remote (Canada) | Full-time
Applicants must be legally eligible to work in Canada. No sponsorship is available.
Parabellyx Cybersecurity is a boutique security testing firm headquartered in Metro Toronto. We provide penetration testing, red teaming, and GRC services to leading Canadian and North American organizations, and we build Luma, our continuous security testing platform. Our entire testing team is based in North America.
We are looking for a penetration tester with a few years of hands-on experience to join our security assurance practice. You will run customer-facing engagements against web applications, mobile applications, APIs, and cloud and on-premises infrastructure, and you will help the team grow its tooling, methodology, and findings library.
WHAT YOU WILL DO
- Perform penetration tests and security assessments of web applications, mobile applications (iOS/Android), and APIs following OWASP methodologies, including ASVS
- Perform external and internal infrastructure penetration tests, including vulnerability exploitation, confirmation, and validation
- Participate in red team exercises alongside senior consultants
- Write transparent, well-structured reports with concrete tactical and strategic recommendations, and walk clients through findings
- Manage standard-scope engagements independently, with senior review on complex or novel scopes
- Contribute to internal tooling, methodology, and the Luma platform's testing capabilities
WHAT WE ARE LOOKING FOR
- Currently residing in Canada and legally eligible to work in Canada without sponsorship, now and in the future (Canadian citizen or permanent resident preferred)
- Able to obtain Canadian security clearance
- 3+ years in security, IT, or software development, including 1 to 2+ years of hands-on penetration testing
- Solid working knowledge of web application security and application security testing
- Practical experience with at least one of: mobile application testing (API and client-side), infrastructure testing, or code review
- Some experience in a customer-facing or consulting role
- Ability to work independently and to draft documentation with minimal supervision
- Fluent written and spoken English, with the ability to explain technical risk to both engineers and management
NICE TO HAVE
- OSCP, OSWE, OSEP, or comparable offensive security certification
- Software development background
- Experience with DevOps, CI/CD, and SAST/DAST/SCA tooling
- Cloud security testing experience (AWS, Azure, GCP)
- Familiarity with LLM/AI application security testing
- Awareness of CIS hardening standards or GRC frameworks (TRA/PIA, PCI DSS, ISO 27001, SOC 2)
If you do not yet hold an offensive security certification, include links to your HackTheBox, TryHackMe, or CTF profiles showing web-focused work.
WHY PARABELLYX
Fully remote within Canada. Small team, direct access to senior testers and leadership, and a wide variety of engagements across industries. Candidates in the Greater Toronto Area are preferred but not required.
ELIGIBILITY
This role is open only to candidates who currently live in Canada and are legally eligible to work here without employer sponsorship. We are not able to sponsor work permits or visas. Applications from outside Canada, or from candidates requiring sponsorship, will not be reviewed.
- To apply, send your resume to
[email protected] or apply through LinkedIn.
📌 Penetration Testing Consultant (Canada)
🏢 Parabellyx Cybersecurity
📍 Canada