Offensive Security Lead - Penetration Testing

RSM Canada

Canada

On-site

CAD 80,000 - 100,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

A leading consulting firm in Canada is seeking candidates for a position in their Security, Privacy, and Risk Consulting team. Ideal applicants will have over 4 years of cyber security experience, including skills in vulnerability assessments and penetration testing. Responsibilities include conducting various security tests and articulating findings to clients. Preferred qualifications include a degree in computer science and certifications in ethical hacking or information systems security.

Qualifications

  • 4+ years of experience in cyber security, preferably in consulting.
  • Strong communication skills to articulate findings to management.
  • Ability to travel as required.

Responsibilities

  • Perform security testing and vulnerability assessments.
  • Identify and articulate findings to clients and management.
  • Supervise staff during engagements.

Skills

Vulnerability assessments
Penetration testing
Secure architecture reviews
Project management
Integrity and confidentiality

Education

Bachelor's degree in computer science or related field

Tools

Nessus
Metasploit
Wireshark
Kali Linux suite

Job description

We are currently looking for team members to join our Security, Privacy, and Risk Consulting practice. The candidate will work with teams of security and privacy staff in a wide variety of systems environments. Our Security, Privacy and Risk Consulting team serves the Information Security and Data Privacy related needs of our clients. This team helps organizations identify their cyber risk, and design and implement program to address those risks and improve their cyber security posture. We serve a diverse base of clients in a variety of industries and understanding how technology impacts the operation and growth of organizations is what we do best. We are seeking individuals skilled at performing vulnerability assessments, penetration testing, and secure architecture reviews of a variety of operating systems, network devices, wireless solutions, and their related infrastructure.

Examples of candidate's responsibilities include:
  • Perform analysis and testing to verify the strengths and weaknesses of client IT environments utilizing commercial and open source security testing tools
  • Perform Internet penetration testing (blackbox/greybox /whitebox testing) and network architecture reviews (manual/automated)
  • Perform other security testing tasks such as wireless penetration testing, social engineering campaigns (email, web, phone, physical, etc.), mobile application testing, embedded device testing, and similar activities meant to identify critical weaknesses within client environments
  • Assist with the development of remediation recommendations for identified findings
  • Identify and clearly articulate (written and verbal) findings to senior management and clients
  • Supervise and provide engagement management for other staff working on assigned engagements
Required Qualifications:
  • This position is for individuals with 4+ years of experience within the cyber security space, with a preference for prior consulting or professional services backgrounds. Other candidates may be considered based on experience and skill sets.
  • Ability to travel as needed
  • Must possess a high degree of integrity and confidentiality, as well as the ability to adhere to both company policies and best practices
  • Strong multitasking and project management skills
Preferred Qualifications:
  • Bachelor's degree in computer science or related field from an accredited college/university
  • Technical background in networking/system administration, security testing or related fields
  • In-depth knowledge of TCP/IP
  • Two or more years of Perl, Python, Bash, or C experience
  • Operating System Configuration and Security experience (Windows, HP-UX, Linux, Solaris, AIX, etc.)
  • Configuration and Security experience with firewalls, switches, routers, VPNs
  • Experience with security and architecture testing and development frameworks, such as the Open Web
  • Application Security Project (OWASP), Open Source Security Testing Methodology Manual (OSSTMM), the Penetration Testing Execution Standard (PTES), Information Systems Security Assessment Framework (ISSAF), and NIST SP800-115
  • Familiar with security testing techniques such as threat modeling, network discovery, port and service identification, vulnerability scanning, network sniffing, penetration testing, configuration reviews, firewall rule reviews, social engineering, wireless penetration testing, fuzzing, and password cracking and can perform these techniques from a variety of adversarial perspectives (white-, grey-, black-box)
  • Experience with discovering, utilizing, and possibly writing exploits for such vulnerabilities as buffer and stack overflows
  • Familiar with the logistics of security testing such as acquiring authorization for testing, reporting, risk analysis of findings, data handling, and legal considerations
  • Commercial Application Security tools experience (Nessus, Nexpose, Qualys, Appdetective, Appscan, etc.)
  • Open source and free tools experience (Kali Linux suite, Metasploit, nmap, airsnort, Wireshark, Burp Suite, Paros, etc.)
  • One or more of the following testing certifications: Certified Ethical Hacker (CEH); GIAC Certified Penetration Tester (GPEN); Offensive Security Certified Professional (OSCP); or equivalent development or testing certification (ECSA, CEPT, CPTE, CPTS, etc)
  • In addition, one or more of the following governance certifications is preferred: Certified Information Systems Security Professionals® (CISSP®); Certified Information Systems Auditor® (CISA®); Certified Information Security Manager® (CISM®)
  • Strong leadership and communication skills, technical knowledge, and the ability to write at a "publication" quality level in order to communicate findings and recommendations to the client's senior management
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Consultant (Web Application Penetration Tester)
Senior Security Consultant (Web Application Penetration Tester)

NetSPI • Toronto

On-site
CAD 100,000 - 150,000
Senior Penetration Tester
Senior Penetration Tester

OffSeq • North Glengarry

Hybrid
CAD 36,000 - 43,000
Source-code review
OT/ICS testing
Mobile/thick-client testing
+2
Consultant, Offensive Security
Consultant, Offensive Security

Kroll • Toronto

On-site
CAD 90,000 - 130,000
Manager, Security & Privacy - SWO
Manager, Security & Privacy - SWO

ROSS • Canada

On-site
CAD 80,000 - 110,000
Consultant, Offensive Security
Consultant, Offensive Security

Socket.dev • Toronto

On-site
CAD 90,000 - 110,000
Senior Cybersecurity Test Architect
Senior Cybersecurity Test Architect

Myticas Consulting • Ottawa

On-site
CAD 120,000 - 160,000
Senior Manager, Security & Privacy
Senior Manager, Security & Privacy

ROSS • Canada

On-site
CAD 100,000 - 130,000
Offensive Security Consultant - Penetration Testing
Offensive Security Consultant - Penetration Testing

RSM Canada • Calgary

On-site
CAD 98,000 - 167,000
Competitive compensation
Flexible work schedule
Bonus eligibility
Penetration Testing Lead — Security & Risk Advisory
Penetration Testing Lead — Security & Risk Advisory

RSM Canada • Canada

On-site
CAD 80,000 - 100,000
Cyber Security Consultant
Cyber Security Consultant

HireOn Tech • Toronto

On-site
CAD 90,000 - 130,000