Junior Web Application Security Penetration Tester (British Columbia)

Junior Web Application Security Penetration Tester (British Columbia)

06 Oct
|
Aon
|
British Columbia

06 Oct

Aon

British Columbia

The Proactive Security Testing team is looking for smart, energetic, and motivated individuals to add to its team. We provide a challenging and exciting work environment that offers a healthy combination of autonomy and senior level support. Our team publishes books and security blogs, delivers conference talks, contributes to open-source software projects, and are engaged in a variety of continuous security research projects.

The location of this position flexible within BC and ON to work near an office or remotely. This role is not eligible for sponsorship, and we are unable to sponsor or take over sponsorship of an employment visa or work permit. The salary range for this position is $93k - $155K CAD.

The actual salary will vary based on applicant’s education, experience, skills, and abilities, as well as internal equity. As an organization, we are united through trust as one inclusive, diverse team, and we are passionate about helping our colleagues and clients succeed. As a Principal Application Security Tester (termed internally as a “Security Testing Manager”), you will serve as a senior member of the penetration testing team.

Conduct complex hybrid web application security assessments, involving code review and energetic application testing applying a combination of static and dynamic source code analysis techniques. Write test harnesses to help identify and proof-of-concept potential security vulnerabilities. Document technical issues identified during security assessments, outlining the associated risks for clients, and providing tailored recommendations for remediation.

Assist colleagues in pre-sales scoping activities for penetration testing engagements. Offer technical mentorship and career development guidance to junior engineers within the organization. Contribute to internal business operations by participating in and suggesting process improvements.

Develop, update, and improve internal tooling used for reporting and penetration testing.



Partner with the team in the recruitment of new penetration testing talent including reviewing resumes and conducting interviews. 4+ years of hands-on penetration testing and/or bug bounty experience. ~ Some expertise in development and/or source code review, focusing on languages such as Java, C#, C/C++, PHP, Ruby, Python, Go, Swift, Objective C/C++, Kotlin, etc. ~ Up to date experience with testing techniques and tooling, such as Burp Suite and other fuzzers/proxies. ~ Deep knowledge of common software vulnerabilities, such as those described in the OWASP Top 10 and CWE/SANS Top 25. ~ Possesses a solid grasp of Unix, Windows, and network security. ~ Ability to work remotely as part of a distributed team and travel to client sites when required. ~ Excellent communication skills (written & verbal) in English, to present complex technical topics concisely to both technical and business audiences.

These skills/experiences are a plus: Experience performing hands-on mobile application penetration testing on iOS and/or Android platforms.

Experience with Bug Bounties, reporting critical/high risk issues to programs. Degree in Computer Science, Information Systems, Engineering or related major and/or equivalent experience. Reputable security certifications, including but not limited to: OSCP, OSWE, GWAPT, OSEE OSCE/OSED, GPEN, GXPN, BSCP Produced public facing research and/or delivered presentations at well-known industry security conferences.

Plus, our agile, inclusive environment allows you to manage your wellbeing and work/life balance, ensuring you can be your best self at Aon. Our continuous learning culture inspires and equips you to learn, share and grow, helping you achieve your fullest potential. Aon provides equal employment opportunities to all employees and applicants for employment without regard to race, color, religion, creed, sex, sexual orientation, gender identity, national origin, age, disability, veteran, marital, domestic partner status, or other legally protected status.

We welcome applications from all and provide individuals with disabilities with reasonable adjustments to participate in the job application, interview process and to perform essential job functions once onboard.

📌 Junior Web Application Security Penetration Tester (British Columbia)
🏢 Aon
📍 British Columbia

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: junior web application security penetration tester (british columbia) / british columbia

Subscribe to this job alert:

Get the latest job offers by email for: junior web application security penetration tester (british columbia) / british columbia