Penetration Tester

Stingrai Inc.

Toronto

Hybrid

CAD 90,000 - 120,000

Full time

13 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Potential for permanent role
Remote work supported

Job summary

Stingrai Inc. in Toronto is hiring a Penetration Tester for a 6-month contract with strong potential to convert to a permanent full-time position within 3–6 months.

The role focuses on hands-on testing of web apps, APIs, and networks, with use of the Snipe AI pentesting platform and direct client engagement through PTaaS. The candidate should have 2–3 years of experience, OSCP certification, and a solid understanding of OWASP Top 10.

Qualifications

  • 2–3 years of hands-on web app, API, and network pen testing.
  • Strong grasp of OWASP Top 10 and common attack techniques across web, API, and network.
  • Legally authorized to work in Canada without restrictions.

Responsibilities

  • Plan and execute penetration tests across web apps, APIs, and networks.
  • Document findings with prioritized remediation guidance.
  • Prepare reports and debrief findings to technical teams and executives.

Skills

Hands-on testing
OSINT & attacker mindset
Clear communication
OWASP Top 10

Education

OSCP certification

Tools

Snipe AI pentesting platform

Job description

Stingrai is a CREST-accredited premier offensive security firm specializing in expert-led penetration testing. Headquartered in Toronto, Canada, with a European hub in London, UK, we serve a global client base across Canada, the US, and Europe, from high-growth SaaS and fintech startups to large enterprises.

We are on a mission to transform offensive security. Alongside a team of experienced penetration testers, we operate an agentic penetration testing as a service (PTaaS) platform that delivers autonomous penetration testing, powered by Snipe, our AI pentesting agent, along with expert human pentesters. The result is world-class, real-world security validation that keeps pace with how fast modern environments change.

We are a team of security researchers, exploit developers and penetration testers. Our team holds the industry's most rigorous certifications, including OSCE³, OSCP, OSWE, and OSEP, has published dozens of CVEs, and presents research at conferences including DEF CON, BSides, and NATO Locked Shields.

THE ROLE

We are hiring a Penetration Tester on a 6 month contract, with potential to convert to a permanent full-time position within 3 to 6 months. This is a hands-on role for someone who already has experience in web application, API, and network penetration testing.

The role is based in Toronto and is currently fully remote, with roughly 5 to 10 percent of engagements requiring onsite presence at client sites in the Greater Toronto Area. We may transition to a hybrid arrangement in the future.

WHAT YOU'LL DO
  • Plan and execute penetration tests across web applications, APIs, and internal and external networks
  • Dig into every finding until you have proven real, exploitable impact, then document it with clear, prioritized remediation guidance
  • Validate and triage findings from Snipe, our AI pentesting agent, applying human judgment to separate real risk from noise
  • Where it matters, chain application flaws into adjacent areas such as cloud or Active Directory to demonstrate full impact
  • Write professional reports and debrief findings to both technical teams and executives
  • Work directly with clients through our PTaaS platform, including live support during active engagements
  • Keep current with new attack techniques, tooling, and disclosed vulnerabilities, and bring what you learn back to the team
  • Participate in our research and development (R&D) initiatives to further enhance our offensive security solutions, publish security blogs, and contribute back to the community
WHO YOU ARE
  • You think like an attacker. You are not satisfied flagging a vulnerability. You prove its impact.
  • You communicate clearly and on time, with clients, project leads, and teammates alike.
  • You take ownership of your work. Your name is on every report you deliver, and it shows.
  • You go toward hard problems, not around them, and you adapt fast in client environments.
  • You keep learning, because offensive security changes constantly.
  • You leave the ego at the door. The strongest finding wins, whoever surfaces it.
MINIMUM REQUIREMENTS
  • OSCP certification
  • 2 to 3 years of hands-on experience in web application, API, and network penetration testing
  • Strong grasp of OWASP Top 10 and common attack techniques across web, API, and network
  • Located in the Greater Toronto Area and available for occasional onsite presence at client sites
  • Legally authorized to work in Canada without restrictions

We do not offer sponsorship for this role.

PREFERRED QUALIFICATIONS

These are not required, but will strengthen your application:

  • Experience in a consulting or client-facing role
  • Red teaming and adversary simulation
  • Physical perimeter security
  • Wi-Fi security testing
  • Social engineering and phishing
  • Cloud security across AWS, Azure, or GCP
  • Secret clearance, or eligibility to obtain one
  • A bug bounty track record
  • Published security research, such as CVEs or conference talks
WHY STINGRAI
  • A clear path from contract to permanent, with real room to grow your craft
  • Work alongside an elite team of top bug bounty hunters, OSCE³ certified senior penetration testers, dozens of published CVEs, and talks at DEF CON, BSides, and NATO Locked Shields
  • Test real targets for a global client base across Canada, the US, and Europe, from high-growth startups to large enterprises
  • Use and help shape our agentic PTaaS platform and Snipe, our AI pentesting agent, instead of grinding through checklists
COMPENSATION
  • Conversion to a permanent full-time position with salary and benefits within 3 to 6 months, based on performance during the contract term
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Mississauga

On-site
CAD 105,000 - 165,000
Health, dental and vision plans
Wellness program
Tuition reimbursement
+1
Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Burnaby

On-site
CAD 105,000 - 165,000
Health plan
Dental plan
Vision plan
+4
Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Saskatoon

On-site
CAD 110,000 - 160,000
Health, dental, and vision plans
Wellness program
Employee stock purchase program
+1
Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Calgary

On-site
CAD 105,000 - 158,000
Health benefits
Wellness program
Employee stock purchase program
Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Southwestern Ontario

On-site
CAD 115,000 - 165,000
Health benefits
Dental coverage
Vision plans
+2
Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Markham

On-site
CAD 105,000 - 165,000
Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Regina

On-site
CAD 105,000 - 165,000
Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Vancouver

On-site
CAD 115,000 - 165,000
Health, dental and vision plans
Wellness program
RRSP / Employee stock purchase program
+1
Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Dartmouth

On-site
CAD 105,000 - 165,000
Health insurance
Tuition reimbursement
Stock purchase program
Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Toronto

On-site
CAD 105,000 - 158,000
Health insurance
Retirement plan
Paid time off