09 Oct
|
Stingrai
|
Ontario
Stingrai is a CREST-accredited premier offensive security firm specializing in expert-led penetration testing. Headquartered in Toronto, Canada, with a European hub in London, UK, we serve a global client base across Canada, the US, and Europe, from high-growth SaaS and fintech startups to large enterprises.
We are on a mission to transform offensive security. Alongside a team of experienced penetration testers, we operate an agentic penetration testing as a service (PTaaS) platform that delivers autonomous penetration testing, powered by Snipe, our AI pentesting agent, along with expert human pentesters. The result is world-class, real-world security validation that keeps pace with how rapid modern environments change.
We are a team of security researchers, exploit developers and penetration testers. Our team holds the industry's most rigorous certifications, including OSCE³, OSCP, OSWE, and OSEP, has published dozens of CVEs, and presents research at conferences including DEF CON, BSides, and NATO Locked Shields.
THE ROLE
We are hiring a Penetration Tester on a 6 month contract, with potential to convert to a permanent full-time position within 3 to 6 months. This is a hands-on role for someone who already has experience in web application, API, and network penetration testing.
The role is based in Toronto and is currently fully remote, with roughly 5 to 10 percent of engagements requiring onsite presence at client sites in the Greater Toronto Area. We may transition to a hybrid arrangement in the future.
WHAT YOU'LL DO
Plan and execute penetration tests across web applications, APIs, and internal and external networks
Dig into every finding until you have proven real, exploitable impact,
then document it with explicit, prioritized remediation guidance
Validate and triage findings from Snipe, our AI pentesting agent, applying human judgment to separate real risk from noise
Where it matters, chain application flaws into adjacent areas such as cloud or Active Directory to demonstrate full impact
Write professional reports and debrief findings to both technical teams and executives
Work directly with clients through our PTaaS platform, including live support during active engagements
Keep current with new attack techniques, tooling, and disclosed vulnerabilities, and bring what you learn back to the team
Participate in our research and development (R&D;) initiatives to further enhance our offensive security solutions, publish security blogs, and contribute back to the community
WHO YOU ARE
You think like an attacker. You are not satisfied flagging a vulnerability. You prove its impact.
You communicate clearly and on time, with clients, project leads, and teammates alike.
You take ownership of your work. Your name is on every report you deliver, and it shows.
You go toward hard problems, not around them, and you adapt fast in client environments.
You keep learning, because offensive security changes constantly.
You leave the ego at the door. The strongest finding wins,
whoever surfaces it.
MINIMUM REQUIREMENTS
OSCP certification
2 to 3 years of hands-on experience in web application, API, and network penetration testing
Strong grasp of OWASP Top 10 and common attack techniques across web, API, and network
Located in the Greater Toronto Area and available for occasional onsite presence at client sites
Legally authorized to work in Canada without restrictions
We do not offer sponsorship for this role.
PREFERRED QUALIFICATIONS
These are not required, but will strengthen your application:
Experience in a consulting or client-facing role
Red teaming and adversary simulation
Physical perimeter security
Wi-Fi security testing
Social engineering and phishing
Cloud security across AWS, Azure, or GCP
Secret clearance, or eligibility to obtain one
A bug bounty track record
Published security research, such as CVEs or conference talks
WHY STINGRAI
A clear path from contract to permanent, with real room to grow your craft
Work alongside an elite team of top bug bounty hunters, OSCE³ certified senior penetration testers, dozens of published CVEs, and talks at DEF CON, BSides, and NATO Locked Shields
Test real targets for a global client base across Canada, the US, and Europe, from high-growth startups to large enterprises
Use and help shape our agentic PTaaS platform and Snipe, our AI pentesting agent, instead of grinding through checklists
COMPENSATION
Conversion to a permanent full-time position with salary and benefits within 3 to 6 months, based on performance during the contract term
#J-18808-Ljbffr
📌 Penetration Tester (Ontario)
🏢 Stingrai
📍 Ontario