Offensive Security Engineer

Epsilon Solutions Ltd.

Toronto

On-site

CAD 140,000 - 230,000

Full time

37 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

Epsilon Solutions Ltd. in Toronto seeks a Principal Consultant, Agentic AI Cybersecurity Engineer to lead hands-on development and operation of agentic AI vulnerability management across our app and infra estate.

You will guide exploitation and remediation in production code, integrate fixes into CI/CD, and design safe human-in-the-loop controls while expanding AI skills and tooling. The role blends offensive and defensive security with secure coding practices and requires deep architectural

Qualifications

  • 10+ years hands-on software engineering and security leadership.
  • Deep fluency in vulnerability classes and exploit development.
  • Experience with enterprise security tooling and CI/CD integration.
  • Proven record of publishing vulnerability research or pentests.

Responsibilities

  • Architect and operationalize the end-to-end agentic AI patching pipeline spanning detection, fix generation, automated testing, and release across SAST, DAST, SCA, IAST, container, and server vulnerabilities.
  • Use frontier AI models to discover novel vulnerabilities in production code, develop proof-of-concept exploits, and validate AI-generated fixes.
  • Build and maintain the library of reusable AI skills, prompts, evaluation harness, and tooling for agentic vulnerability discovery and remediation at scale.
  • Design AI-driven false positive analysis and exemption processes to reduce manual triage burden.
  • Conduct hands-on penetration testing and red team exercises against critical apps and infra to validate defenses.
  • Extend agentic remediation coverage across SAST, SCA, DAST, IAST, container, and server vulnerabilities, linking findings to source.
  • Design agent prompting, guardrails, evaluation frameworks, and human-in-the-loop controls for safe autonomous changes.
  • Drive integration of agentic remediation into enterprise CI/CD pipelines across the deployment landscape.
  • Communicate technical design, risk trade-offs, and delivery progress to CIO, CISO, 2LOD, and Audit functions.

Skills

Software engineering
Offensive security
Defensive security
Memory safety
Injection flaws
Cryptographic misuse
Deserialization
Race conditions
Supply chain attacks
Penetration testing
Red teaming
Exploit development
Reverse engineering
Secure code review
SAST
DAST
IAST
SCA
Claude
Devin
Copilot
Windsurf
Cursor
MCP
CI/CD
Docker
Kubernetes
Cloud-native deployment
Security automation

Job description

As “Principal Consultant, Agentic AI Cybersecurity Engineer” you will work hands‑on alongside our cybersecurity engineering and application security teams to build, operate, and advance the agentic AI systems that find, exploit, and remediate vulnerabilities end‑to‑end across our application and infrastructure estate. Operating at a principal engineer level, you will personally direct frontier AI models do discover vulnerabilities in production code, develop proof‑of‑concept exploits, generate and validate fixes, and integrate them into CI/CD pipelines with safe human‑in‑the‑loop controls. You will also build reusable AI skills, prompts, and tooling that make agentic vulnerability management efficient and scalable across the estate. You will bring deep dual expertise across offensive and defensive security, penetration testing, and software engineering, and apply that fluency to push the boundaries of what is possible with agentic AI in a regulated enterprise environment.

What will you do?

  • Architect and operationalize the end‑to‑end agentic AI patching pipeline spanning detection, fix generation, automated testing, and release across SAST, DAST, SCA, IAST, container, and server vulnerabilities.
  • Use frontier AI models to discover novel vulnerabilities in production application and infrastructure code, develop proof‑of‑concept exploits, and validate that AI‑generated fixes close the underlying root cause.
  • Build and maintain the library of reusable AI skills, prompts, evaluation harness, and tooling that power agentic vulnerability discovery, triage, remediation, false positive analysis, and exemption workflows at scale.
  • Design and operationalize AI‑driven false positive analysis and exemption processes to reduce manual triage burden and surface only actionable findings to development teams.
  • Conduct hands‑on penetration testing and red team exercise against critical applications and infrastructure to validate defensive controls and agent‑generated remediations.
  • Extend agentic remediation coverage across SAST, SCA, DAST, IAST, container, and server vulnerabilities, including the data and tooling needed to connect findings back to source.
  • Design agent prompting, guardrails, evaluation frameworks, and appropriate human‑in‑the‑loop controls to ensure safe autonomous code changes, testing, and deployment.
  • Drive integration of agentic remediation into enterprise CI/CD pipelines (Github, Jenkins, etc.) across the deployment landscape.
  • Communicate technical design, risk trade‑offs, and delivery progress clearly to senior stakeholders including CIO, CISO, 2LOD, and Audit functions.
Must‑have:
  • 10+ years hands‑on experience across software engineering, offensive security, and defensive security at a principal engineer level, with demonstrated personal contributions to production codebases and published vulnerability research or penetration testing engagements.
  • Deep fluency in vulnerability classes including memory safety, injection authentication and authorization flaws, cryptographic misuse, deserialization, race conditions, and supply chain attacks, with hands‑on experience finding and exploiting each.
  • Extensive hands‑on experience with penetration testing, red teaming, exploit development, reverse engineering, and secure code review against OWASP Top 10 and SANS 25, combined with defensive engineering experience building detection and remediation capabilities.
  • Extensive hands‑on experience with application security testing tools (SAST, DAST, IAST, SCA), including tuning, false positive analysis, exemption workflow design, and enterprise vulnerability management at scale.
  • Deep technical fluency with agentic AI coding tools and frameworks (Claude, Devin, Copilot, Windsurf, Cursor, MCP, including prompt engineering, agent orchestration, reusable skill and tool design, guardrail design, and evaluation.
  • Strong architectural knowledge of modern CI.CD, container platforms (Docker, Kubernetes), cloud‑native deployment patterns, and integration of security automation into developer workflows.
Nice‑to‑have:
  • Relevant security certifications (OSCP, OSCE, OSEP, GXPN, GWAPT, CISSP, or equivalent).
  • Experience in financial services or highly regulated industries with exposure to SOX, SOC1, and regulatory audit.
  • Public evidence of offensive capability: published CVEs, bug bounty track record, conference talks (DEFCON, Black Hat, Offensive Con, Recon), CTF placements, or open‑source security tooling contributions.
  • Hands‑on experience with enterprise vulnerability tooling (Tenable, Aqua, Snyk, BrightSec) and remediation at scale.
  • Demonstrated ability to advise senior technology leaders and deliver within complex, multi‑stakeholder enterprise environments.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Offensive Security Engineer -SAST, DAST, SCA, IAST
Senior Offensive Security Engineer -SAST, DAST, SCA, IAST

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision! • Toronto

On-site
CAD 120,000 - 160,000
Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Oakville

On-site
CAD 120,000 - 180,000
Senior Software Engineer (Security)
Senior Software Engineer (Security)

Super • Toronto

Hybrid
CAD 90,000 - 120,000
Competitive salary
Learning & development allowance
Generous equity options
+2
Offensive Security Engineer
Offensive Security Engineer

Synechron • Toronto

Hybrid
CAD 130,000 - 140,000
15 days paid annual leave
Comprehensive insurance (medical, etc)
Flexible hybrid policy
+3
Principal Consultant - Cybersecurity & Agentic AI
Principal Consultant - Cybersecurity & Agentic AI

Synechron • Toronto

Hybrid
CAD 180,000 - 280,000
Paid annual leave
Personal leave
Comprehensive insurance plan (medical,
+7
Security Architect
Security Architect

Ateko, backed by Bell Canada • Montreal (administrative region)

On-site
CAD 120,000 - 160,000
Application Security Engineer
Application Security Engineer

Segment (Twilio) • Toronto

On-site
CAD 100,000 - 130,000
Principal Agentic AI Security Engineer
Principal Agentic AI Security Engineer

Epsilon Solutions Ltd. • Toronto

On-site
CAD 140,000 - 230,000
Chief Software Engineering Architect
Chief Software Engineering Architect

DataStealth Inc. • Mississauga

Hybrid
CAD 180,000 - 240,000
Hybrid schedule
Chief Software Engineering Architect
Chief Software Engineering Architect

DataStealth.io • Mississauga

Hybrid
CAD 180,000 - 240,000