Security Specialist (Penetration Tester) 8437-3112
Join to apply for the Security Specialist (Penetration Tester) 8437-3112 role at Foilcon.
HM Note: This hybrid contract role is three (3) days in office. Candidates' resumes must include first and last name. The role commences April 1, 2025.
Description
Responsibilities:
- Conduct penetration tests, web application vulnerability assessments, code reviews and network vulnerability assessments of all environments or applications related to the OPS province-wide I&IT infrastructure and information resources.
- Define, evaluate, and assess security architecture requirements for systems environments and IT projects.
- Ensure the incorporation of IT security and contingency measures in the development of systems.
- Advise on the identification, analysis, and resolution of specific security factors, risks, vulnerabilities; protection of personal privacy issues; and appropriate industry and international security standards.
- Carry out information and information technology (I&IT) security projects and tasks in the Ontario Public Service as assigned by Corporate Security or cluster I&IT management.
General Skills
- Experience in vulnerability assessment/penetration testing of web applications by identifying, analyzing and exploiting common vulnerabilities contained in web applications using manual techniques and automated tools appropriate for enterprise use.
- Experience performing penetration tests and red team assessments.
- Experience with vulnerability assessment methodologies, tools and techniques used to conduct network vulnerability assessments and penetration testing.
- Knowledge of techniques to secure information assets and the planning, design, and implementation of security technologies.
- Proven techniques to discover gaps or weaknesses in security architecture to identify and mitigate known security threats or inherent weaknesses.
- Strong understanding and expertise in security architecture.
- Knowledge and understanding of relevant legislation and corporate directives related to the security and confidentiality of information (e.g. Freedom of Information and Protection of Privacy Act).
- Solid knowledge of current security and contingency technology and techniques (e.g. digital signature, encryption, access controls, fire-walls, authentication, virus protection, etc.); and a proven working knowledge of security audit procedures and protocols.
- Experience in establishing secure environments at a network, operating system or application level.
- Experience with implementing security on complex and distributed systems.
- Experience in writing reports to a large audience both at an executive/non-technical management level and technical resources.
- Awareness of emerging IT trends and directions, especially as related to security.
- Excellent analytical, problem-solving, and decision-making skills; written and verbal communication skills; interpersonal and negotiation skills.
- A team player with a track record for meeting deadlines, managing competing priorities and client relationship management experience.
- Experience with multiple operating systems such as Windows and Linux, multiple programming languages such as .NET and Java, and common network services and protocols.
Skills
Experience and Skill Set Requirements
- Mandatory Requirement: Current penetration test experience.
- PENETRATION TEST EXPERIENCE: 35% Demonstrated experience in identifying, analyzing, and exploiting common vulnerabilities using both manual techniques and automated tools for web and network pen testing and vulnerability assessments.
- TECHNICAL EXPERTISE: 25% Experience with multiple operating systems, programming and scripting languages, platforms, and network services and protocols.
- ANALYTICAL AND PROBLEM SOLVING SKILLS: 20% Demonstrated analytical and problem-solving skills to determine alternative and innovative solutions.
- COMMUNICATION AND RELATIONSHIP BUILDING SKILLS: 10% Experience with writing reports aimed at both the executive/non-technical management level, and technical analyst level.
- LEADERSHIP AND PROJECT MANAGEMENT SKILLS: 10% Proven ability to provide leadership, advice, and direction on business risk planning and coordination.
Seniority level
Mid-Senior level
Employment type
Contract
Job function
Information Technology
Industries
IT Services and IT Consulting