Enable job alerts via email!

Security Specialist (Penetration Tester) 8437-3112

Dheya

Toronto

Hybrid

CAD 70,000 - 110,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An innovative firm is seeking a Security Specialist with expertise in penetration testing and vulnerability assessments. This hybrid role involves conducting thorough security evaluations of web applications and IT systems, ensuring compliance with industry standards. You'll play a crucial role in identifying vulnerabilities and advising on security architecture, all while collaborating with diverse teams. If you're passionate about IT security and eager to tackle complex challenges, this position offers a fantastic opportunity to make a significant impact in a dynamic environment. Join a forward-thinking company where your skills will help shape the future of security in the digital landscape.

Qualifications

  • Current penetration test experience is mandatory.
  • Strong understanding of security architecture and methodologies.

Responsibilities

  • Conduct penetration tests and vulnerability assessments for various applications.
  • Define and evaluate security architecture requirements for IT projects.

Skills

Penetration Testing
Vulnerability Assessment
Security Architecture Analysis
Analytical and Problem-Solving Skills
Written and Verbal Communication
Network Security Technologies
Project Management
Multilingual
Programming Languages Knowledge
Emerging IT Security Trends Awareness

Tools

Automated Security Tools
Common Network Services and Protocols
Windows
Linux
.NET
Java

Job description

Security Specialist (Penetration Tester) 8437-3112

Skills Required:

  • Penetration Testing
  • Vulnerability Assessment
  • Security Architecture Analysis
  • Written and Verbal Communication
  • Network Security Technologies
  • Analytical and Problem-Solving Skills
  • Project Management
  • Multilingual
  • Programming Languages Knowledge
  • Emerging IT Security Trends Awareness

HM Note: This hybrid contract role is three (3) days in office. Candidates' resumes must include first and last name. The role commences April 1, 2025.

Description

Responsibilities:

  1. Conduct penetration tests, web application vulnerability assessments, code reviews, and network vulnerability assessments of all environments or applications related to the OPS province-wide I&IT infrastructure and information resources.
  2. Define, evaluate, and assess security architecture requirements for systems environments and IT projects.
  3. Ensure the incorporation of IT security and contingency measures in the development of systems.
  4. Advise on the identification, analysis, and resolution of specific security factors, risks, vulnerabilities; protection of personal privacy issues; and appropriate industry and international security standards.
  5. Carry out information and information technology (I&IT) security projects and tasks in the Ontario Public Service as assigned by Corporate Security or cluster I&IT management.

General Skills:

  • Experience in vulnerability assessment/penetration testing of web applications by identifying, analyzing, and exploiting common vulnerabilities contained in web applications using manual techniques and automated tools appropriate for enterprise use.
  • Experience performing penetration tests and red team assessments.
  • Experience with vulnerability assessment methodologies, tools, and techniques used to conduct network vulnerability assessments and penetration testing.
  • Knowledge of techniques to secure information assets and the planning, design, and implementation of security technologies.
  • Proven techniques to discover gaps or weaknesses in security architecture to identify and mitigate known security threats or inherent weaknesses.
  • Strong understanding and expertise in security architecture.
  • Knowledge and understanding of relevant legislation and corporate directives related to the security and confidentiality of information (e.g., Freedom of Information and Protection of Privacy Act) in order to identify and assess areas of concern and risk.
  • Solid knowledge of current security and contingency technology and techniques (e.g., digital signature, encryption, access controls, firewalls, authentication, virus protection, etc.); and a proven working knowledge of security audit procedures and protocols.
  • Experience in establishing secure environments at a network, operating system, or application level.
  • Experience with implementing security on complex and distributed systems.
  • Experience in writing reports to a large audience both at an executive/non-technical management level and technical resources.
  • Awareness of emerging IT trends and directions, especially as related to security.
  • Excellent analytical, problem-solving, and decision-making skills; written and verbal communication skills; interpersonal and negotiation skills.
  • A team player with a track record for meeting deadlines, managing competing priorities and client relationship management experience.
  • Experience with multiple operating systems such as Windows and Linux, multiple programming languages such as .NET and Java, and common network services and protocols.

Mandatory Requirement:

Current penetration test experience.

PENETRATION TEST EXPERIENCE: 35%

Demonstrated experience in identifying, analyzing, and exploiting common vulnerabilities using both manual techniques and automated tools for web and network pen testing and vulnerability assessments. Demonstrated experience in leading penetration tests, web application vulnerability assessments, code reviews, and network vulnerability assessments in a large environment with diverse systems; and in common attacks, common web application vulnerabilities, exploits, and best practices for remediation. Knowledge of IT security methodologies, tools, techniques, security design and architecture, threat/risk concepts and practices, and encryption technologies. Ability to acquire and interpret corporate I&IT security strategy, programs, the government’s trust model, and privacy legislation.

TECHNICAL EXPERTISE: 25%

Experience with multiple operating systems, programming and scripting languages, platforms, and network services and protocols. Understanding of emerging I&IT trends, best practices, and developments in common attacks, common web application vulnerabilities, exploits, and best practices for remediation.

ANALYTICAL AND PROBLEM SOLVING SKILLS: 20%

Demonstrated analytical and problem-solving skills to determine alternative and innovative solutions where guidelines or policies exist but may not address new and emerging I&IT trends. Ability to conceptualize, interpret, and evaluate security exposures across multiple domains.

COMMUNICATION AND RELATIONSHIP BUILDING SKILLS: 10%

Experience with writing reports aimed at both the executive/non-technical management level and technical analyst level. Oral and written communication, mediation, negotiation, consultative and advisory skills. Skills to provide training in the use of commercial security assessment tools and scanners. Stakeholder management, partnership, and relationship building skills to initiate and nurture strong working relationships with internal and external colleagues.

LEADERSHIP AND PROJECT MANAGEMENT SKILLS: 10%

Proven ability to provide leadership, advice, and direction on business risk planning and coordination. Demonstrated project methodology and management skills to provide project planning and technical leadership on concurrent projects.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Security Specialist (Penetration Tester) 8437-3112

Foilcon

Toronto

Hybrid

CAD 80,000 - 120,000

30+ days ago