Enable job alerts via email!

Offensive Security Specialist

Ubisoft Entertainment

Montreal

Hybrid

CAD 80,000 - 100,000

Full time

16 days ago

Job summary

A leading gaming company is looking for an Offensive Security Specialist to join their cybersecurity team in Montreal. This role involves validating vulnerabilities, collaborating on exploiting real-world attack scenarios, and enhancing security tools and workflows. Candidates should have a strong background in penetration testing and experience with vulnerability assessment tools. The position offers a hybrid work model and a focus on continual skill development.

Benefits

Hybrid work model

Qualifications

  • Demonstrated penetration testing experience in complex infrastructures.
  • Strong knowledge of vulnerability scoring and attack vectors.
  • Ability to build CVE exploitation proofs of concept.

Responsibilities

  • Validate third-party CVEs and conduct exploitation.
  • Collaborate with Red Team on exploit chains.
  • Document and communicate vulnerabilities and findings.

Skills

Penetration testing
Vulnerability assessment
Exploit development
Tool proficiency (Tenable, Qualys)
Knowledge of OWASP and MITRE ATT&CK

Education

Certifications such as OSCP

Tools

Wireshark
IDA Pro
Ghidra
Job description

Ubisoft is a global leader in gaming with teams across the world creating original and memorable gaming experiences, from Assassin’s Creed, Rainbow Six to Just Dance and more. We believe diverse perspectives help both players and teams thrive. If you’re passionate about innovation and pushing entertainment boundaries, join our journey and help us create the unknown!

JOB DESCRIPTION

Ubisoft is seeking a skilled and motivated Offensive Security Specialist to join our cybersecurity team and strengthen Ubisoft’s ability to identify, assess, and mitigate security vulnerabilities across its diverse environments, ranging from IT and corporate systems to games and online services.

You will contribute to our vulnerability management program by validating CVEs, developing exploit proofs-of-concept, collaborating with our Red Team, and supporting remediation and triage through actionable insights. Your expertise in offensive techniques will play a critical role in reducing risk exposure across the organization.

Responsibilities

  • Validate the exploitation of third-party CVEs identified by vulnerability scanners (e.g., Tenable.io).
  • Triage and validate first-party vulnerabilities discovered through responsible disclosure programs (e.g., Bug Bounty).
  • Collaborate with the Red Team to build exploit chains and simulate real-world attack scenarios.
  • Retest vulnerabilities identified by internal security teams to confirm remediation effectiveness.
  • Contribute to the development and deployment of internal security tools and workflows aligned with industry best practices.
  • Continuously research emerging offensive techniques and integrate findings into testing methodologies and tooling.
  • Document validated vulnerabilities, and communicate detailed findings and remediation recommendations to internal stakeholders.
  • Remediate vulnerabilities by following up with asset and application owners to ensure timely resolution.
QUALIFICATIONS
  • Practical Experience: Demonstrated track record in penetration testing or offensive security within large-scale, complex infrastructures, suited for an intermediate-level professional with a with a strong commitment to keeping skills current in offensive security with certifications such as OSCP.
  • Vulnerability Assessment Expertise: Strong knowledge of vulnerability scoring, attack vectors, triage, and assessments, including the ability to exploit common flaws such as: Web vulnerabilities (XSS, IDOR, CSRF), Server-side issues (SQLi, XXE, SSRF, RCE), Authentication and access control weaknesses
  • Exploit Development: Proven ability to build or adapt CVE exploitation proofs of concept (PoCs) tailored to organizational environments.
  • Tool Proficiency: Skilled in vulnerability assessment and penetration testing tools, including vulnerability scanners (Tenable, Qualys) and network analysis utilities (Wireshark, tcpdump, Scapy); Reverse engineering & debugging tools (IDA Pro, Ghidra, x64dbg, WinDbg) is a plus.
  • Security Frameworks & Practices: Familiarity with OWASP, MITRE ATT&CK, remediation techniques, and system hardening.
ADDITIONAL INFORMATION

We embrace a hybrid work model helping you stay connected with your team and aligned with business priorities, while giving you the opportunity to maintain your work-life balance. Note, that some roles are fully office-based and are not eligible for hybrid work.

Just a heads up: If you require a work permit, your eligibility may depend on your education and years of relevant work experience, as required by the government.

Skills and competencies show up in different forms and can be based on different experiences, that is why we strongly encourage you to apply even though you may not have all the requirements listed above.

At Ubisoft, we embrace diversity in all its forms. We’re committed to fostering an inclusive and respectful work environment for all.We know the importance of providing a pleasant interview experience, therefore if you need anyaccommodation, please let us know if there is anything we can do to facilitate the interview process.

LET OUR TEAM MEMBERS TELL YOU ABOUT THEIR JOB
Games Explained: Game Engines

Developers have many technologies and tools at their disposal to build games, and game engines are at their core. Timothy Dansie, technical associate producer, explains how game engines work and which ones we use at Ubisoft.

Alexandru's journey: from Game Tester to IT teams
Machine Learning, Physics Simulation, Kolmogorov Complexity, and Squishy Bunnies
FAQ
Can I submit an open application?

We do not accept open applications. You can find all our open positions by clicking on the ‘Search Jobs’ button. Check our careers page regularly if you don’t find the opportunity you are looking for this time.

How can I check my application status?

You can check the status of your application by logging into your SmartRecruiters candidate profile.

At Ubisoft, everyone is welcome! We know that by bringing together different perspectives and experiences, we create a more inclusive environment for our team members. You’ll get the chance to work with teams and projects that inspire and challenge you every single day.

How do I know if a Ubisoft email/offer is legit?

We were sorry to hear of some instances whereby scammers contacted candidates on Ubisoft’s “behalf” to gather personal data and/or money. We take this matter very seriously: not only do these actions put you at risk, they also jeopardize Ubisoft’s image.Click on the button below to read the detailed list of of things that Ubisoft, as a company, will never ask you for during your hiring process.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.