Senior Cybersecurity Test Engineer (35651)

Myticas Consulting

Ottawa

On-site

CAD 110,000 - 140,000

Full time

4 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Myticas Consulting seeks a Senior Cybersecurity Test Engineer to lead security testing across apps, infrastructure, cloud, APIs, and integrations. You will design, implement, and perform comprehensive tests to identify vulnerabilities and validate controls within the SDLC and DevSecOps processes.

You will collaborate with cybersecurity, development, cloud and infrastructure teams, mentor junior testers, develop reusable test assets, and report findings with remediation guidance to stakeholders.

Qualifications

  • 8+ years in cybersecurity testing or related fields.
  • Hands-on security testing across applications, infrastructure, cloud and integrations.
  • Experience with threat modeling methodologies like STRIDE, MITRE ATT&CK, OWASP.
  • Cloud security testing in AWS/Azure/GCP environments.
  • Experience testing APIs, IAM, authentication and authorization controls.
  • Strong knowledge of security principles and risk management.

Responsibilities

  • Plan, design, and execute security testing across applications, infrastructure, cloud environments, APIs, and system integrations.
  • Develop and execute threat-based security test scenarios using STRIDE, MITRE ATT&CK, and OWASP testing approaches.
  • Perform security testing and validation for IAM, APIs, data flows, cloud, applications and infrastructure.
  • Conduct manual and automated security testing, including vulnerability assessments and security control validation.
  • Execute application security testing, API security testing, cloud security testing, and infrastructure security assessments.
  • Identify, document, and report vulnerabilities, security gaps, and control weaknesses, and provide remediation recommendations.
  • Validate remediation efforts through retesting and verification activities.
  • Develop and maintain reusable security test cases, scripts, automation frameworks, and testing procedures.
  • Support security risk assessments, investigations, incident reviews, and security-related escalations.
  • Collaborate with development, cloud, infrastructure, architecture, and cybersecurity teams to integrate security testing throughout the SDLC and DevSecOps processes.
  • Generate security testing reports, technical findings, risk assessments, and testing metrics for stakeholders.
  • Contribute to the development and continuous improvement of security testing standards, procedures, and best practices.
  • Mentor junior security testers and provide guidance on security testing methodologies and tools.

Skills

Cybersecurity testing
Threat modeling
API security testing
Cloud security testing
Vulnerability assessments
Remediation testing
Documentation & reporting
Mentoring

Tools

Burp Suite
OWASP ZAP
Nessus
Qualys
Fortify
Checkmarx
Veracode

Job description

Role Overview

We are seeking a Senior Cybersecurity Test Engineer to lead and execute security testing activities across applications, infrastructure, cloud environments, APIs, and system integrations. This role is responsible for designing, implementing, and performing comprehensive security testing to identify vulnerabilities, validate security controls, and ensure organizational security requirements are effectively met. The successful candidate will collaborate closely with cybersecurity, development, infrastructure, and cloud teams to integrate security testing throughout the system development lifecycle.

Key Responsibilities
  • Plan, design, and execute security testing activities across applications, infrastructure, cloud environments, APIs, and system integrations.
  • Develop and execute threat-based security test scenarios using methodologies such as STRIDE, MITRE ATT&CK, and OWASP testing approaches.
  • Perform security testing and validation for:
    • Identity and Access Management (IAM)
    • APIs and microservices
    • Data flows and system integrations
    • Cloud environments
    • Applications and infrastructure
  • Conduct manual and automated security testing, including vulnerability assessments and security control validation.
  • Execute application security testing, API security testing, cloud security testing, and infrastructure security assessments.
  • Identify, document, and report vulnerabilities, security gaps, and control weaknesses, and provide remediation recommendations.
  • Validate remediation efforts through retesting and verification activities.
  • Develop and maintain reusable security test cases, scripts, automation frameworks, and testing procedures.
  • Support security risk assessments, investigations, incident reviews, and security-related escalations.
  • Collaborate with development, cloud, infrastructure, architecture, and cybersecurity teams to integrate security testing throughout the SDLC and DevSecOps processes.
  • Generate security testing reports, technical findings, risk assessments, and testing metrics for stakeholders.
  • Contribute to the development and continuous improvement of security testing standards, procedures, and best practices.
  • Mentor junior security testers and provide guidance on security testing methodologies and tools.
Required Skills & Experience
  • 8+ years of experience in cybersecurity testing, security engineering, application security, penetration testing, or related disciplines.
  • Strong hands-on experience executing security testing across applications, infrastructure, cloud environments, and integrations.
  • Experience with threat modeling methodologies such as STRIDE, MITRE ATT&CK, OWASP Threat Modeling, or equivalent frameworks.
  • Strong knowledge of cloud security testing within AWS, Azure, and/or GCP environments.
  • Experience testing APIs, identity platforms, IAM solutions, authentication mechanisms, and authorization controls.
  • Strong understanding of application, infrastructure, network, and integration security principles.
  • Experience with security testing tools, vulnerability scanning, and automated testing frameworks.
  • Hands-on experience performing vulnerability assessments, security control validation, and remediation testing.
  • Knowledge of security requirements, controls, risk management principles, and compliance frameworks.
  • Strong analytical, troubleshooting, and investigative skills.
  • Excellent technical documentation, reporting, and communication skills.
  • Ability to work effectively with developers, architects, engineers, and cybersecurity stakeholders.
Preferred Qualifications
  • Experience integrating security testing into CI/CD pipelines and DevSecOps environments.
  • Experience with dynamic application security testing (DAST), static application security testing (SAST), software composition analysis (SCA), and container security testing.
  • Knowledge of security testing tools such as Burp Suite, OWASP ZAP, Nessus, Qualys, Fortify, Checkmarx, Veracode, or similar solutions.
  • Experience testing containerized and Kubernetes-based environments.
  • Familiarity with security frameworks and standards such as NIST, ISO 27001, CIS Controls, OWASP, and PCI-DSS.
  • Relevant certifications such as OSCP, CISSP, GIAC, CEH, GWAPT, GPEN, Security+, or cloud security certifications would be considered an asset.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Test Engineer
Senior Cybersecurity Test Engineer

Myticas Consulting • Ottawa

On-site
CAD 110,000 - 170,000
Senior Security Testing Engineer - Cloud, API & Apps
Senior Security Testing Engineer - Cloud, API & Apps

Myticas Consulting • Ottawa

On-site
CAD 110,000 - 140,000
Senior Cybersecurity Specialist
Senior Cybersecurity Specialist

STACK IT Recruitment • Burlington

On-site
CAD 154,000 - 181,000
Paid vacation and personal days
Annual bonus
Senior Offensive Security – Penetration Testing & Red Team Engineer
Senior Offensive Security – Penetration Testing & Red Team Engineer

Cognizant • Toronto

On-site
CAD 147,000 - 172,000
Medical/Dental/Vision/Life Insurance
Paid holidays and PTO
Long-term/Short-term Disability
+1
Cybersecurity Engineer Canada(Toronto, Vancouver)/Hybrid , India(Bangalore)/Hybrid, USA(Fremont -California)/Hybrid
Cybersecurity Engineer Canada(Toronto, Vancouver)/Hybrid , India(Bangalore)/Hybrid, USA(Fremont -California)/Hybrid

Initvalue • Toronto, Vancouver

Hybrid
CAD 90,000 - 140,000
Security Architect
Security Architect

Ateko, backed by Bell Canada • Montreal (administrative region)

On-site
CAD 120,000 - 160,000
Senior Cloud Penetration Tester
Senior Cloud Penetration Tester

Stantec • Regina

On-site
CAD 105,000 - 165,000
Senior Penetration Tester & Red Team Engineer
Senior Penetration Tester & Red Team Engineer

Cognizant • Toronto

On-site
CAD 106,000 - 124,000
Discretionary annual incentive
Disability benefits
Senior Software Security Engineer
Senior Software Security Engineer

TimePlay • Toronto

On-site
CAD 120,000 - 180,000
Senior Software Engineer (Security)
Senior Software Engineer (Security)

Super • Toronto

Hybrid
CAD 90,000 - 120,000
Competitive salary
Learning & development allowance
Generous equity options
+2