Senior Ethical Hacker

Stantec

Vancouver

On-site

CAD 115,000 - 165,000

Full time

9 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Health, dental and vision plans
Wellness program
RRSP / Employee stock purchase program
Paid time off

Job summary

Stantec is seeking a Senior Ethical Hacker to perform security assessments on web applications and cloud services, emulating real-world attacks per the MITRE ATT&CK framework. You will uncover vulnerabilities, misconfigurations and risks to prevent breaches and strengthen security posture.

Responsibilities include cross-functional collaboration, comprehensive reporting, remediation process design, and presenting results to executives.

Qualifications

  • Minimum 5 years of cybersecurity experience with offensive security or red team work.
  • Proficient in manual web and cloud penetration testing without automated tools.
  • Proven ability to write custom attack tools in Python, PHP, Golang and Bash.
  • Experience with Burp Suite Enterprise and building attack automation pipelines.
  • Strong reporting skills and comfortable presenting findings to leadership.

Responsibilities

  • Collaborate with security, engineering, cloud and network teams.
  • Create reports and communicate findings to technical teams and executives.
  • Develop processes to help remediation goals and test debriefs with sponsors.
  • Conduct penetration tests on cloud systems, apps and APIs.
  • Assess configurations, access controls and encryption in cloud environments.
  • Engineer Python, Terraform and Ansible extensions for security use cases.
  • Lead internal Red/ Purple team engagements and live hacking webinars.

Skills

Offensive security
Manual web penetration testing
Cloud penetration testing
Python scripting
PHP/Golang scripting
Bash scripting
Windows/Linux CLI
XSS/SQL injection
Cloud security (Azure/AWS/GCP/Oracle)

Education

OffSec Web Expert (OSWE)
OffSec (OSAI)
GIAC Web Application Penetration Tester (GWAPT)
Burp Suite Certified Practitioner (BSCP)
Pentester Academy Cloud Security Professional (PACSP)
Certified Kubernetes Security Specialist (CKS)
Terraform Associate (003)

Tools

Burp Suite Enterprise
Python
Terraform
Ansible
Kubernetes
Bash
PowerShell

Job description

  • OffSec Web Expert (OSWE) - Preferred
  • OffSec (OSAI) - Preferred

At Stantec, we have some of the world’s leading professionals passionate about enabling our business to be its best. Our business teams include finance, procurement, human resources, information technology, marketing, corporate development, HSSE, real estate, legal, and practice services. We bring diverse backgrounds, skills, and expertise and create a caring culture where everyone can thrive. Through teamwork and collaboration, we’re building a stronger, more resilient Stantec every day.

Your Opportunity

The Senior Ethical Hacker will conduct security assessments on web applications and cloud services by emulating real-world attacks using the Mitre Attack Framework. Their goal is to identify security weaknesses, help prevent data breaches and enhance the security posture by uncovering vulnerabilities, misconfigurations, and risks proactively before they are discovered by threat actors.

Your Key Responsibilities
Communication
  • Collaborate with cross-functional teams (security, engineering, cloud and network operations).
  • Create reports and communicate findings to various technical teams, architects and engineers.
  • Create and communicate processes that could help engineering teams meet remediation goals.
  • Create and verbally present your test findings in debrief meetings with the C-Suite or sponsors.
Cloud Application
  • Conduct penetration tests on cloud systems, applications and APIs to identify vulnerabilities.
  • Assess cloud/application specific configurations, access controls, and encryption mechanisms.
  • Validate and exploit security findings within web/thick client apps and cloud environments.
  • Validate various app services, databases, Kubernetes, serverless functions, container instances, images and cloud storage blob/buckets for security issues.
Project work/Knowledge Share
  • Assist/Create rules of engagement for new pen test projects.
  • Architect automated workflows for independent security evaluation and assurance processes
  • Establish and enforce security baseline controls through Policy-as-Code implementations
  • Engineer custom Python, Terraform, and Ansible extensions to enable specialized security and infrastructure use cases
  • Create or populate content in the internal training lab so developers and security champions can stay current in offensive security with practical CTF's when time permits.
  • Provide live hacking webinars for teams interested in learning by example.
  • Conduct internal Red Team engagements.
  • Participate in purple team engagements.
Your Capabilities and Credentials
  • Minimum 5-7+ years working in some aspect of cybersecurity (Offensive Security, Red Team experience preferred).
  • Proficient with manual web/cloud penetration testing without using any tools.
  • Proficient writing custom attack tools in Python, PHP, Golang and Bash Scripting.
  • Proficient with interception proxies and attacking manually via Burp Suite Enterprise tool.
  • Proficient building/maintaining attack automation systems (Commercial or Open-Source).
  • Proficient building containers and automation pipelines for attacking purposes.
  • Experience combining multiple low/medium findings to weaponize and achieve a higher level.
  • Comfortable working exclusively from Windows or Linux command line.
  • Comfortable 'living off the land' using VIM/VI/Bash/SH/Perl/VBScript/WMI/PowerShell for post exploitation and lateral movement.
  • Comfortable with writing XSS attacks, System/SQL injection payloads or weaponizing binaries.
  • Comfortable attacking various popular public cloud services in (Azure/AWS/GCP/Oracle).
  • Comfortable presenting audit findings to a small group or C-Suite during debrief meetings.
  • Comfortable taking ownership for testing actions and performing blameless post-mortems.
Preference For The Following Additional Skills/Certifications
  • OffSec Web Expert (OSWE) - Preferred
  • OffSec (OSAI) - Preferred
  • GIAC Web Application Penetration Tester (GWAPT)
  • Burp Suite Certified Practitioner (BSCP)
  • Pentester Academy Cloud Security Professional (PACSP)
  • AI/LLM Penetration testing experience
  • Acknowledged findings in a responsible disclosure or public, private Bug Bounty program.
  • Certified Kubernetes Security Specialist (CKS)
  • Terraform Associate (003)
  • DevSecOps experience
Education and Experience
  • Minimum 5 years relevant experience.
  • Related Degree or Certificate, preferably in areas of Offensive Security, AI Red Teaming or Application
  • Security
Pay Range
  • Locations Outside of Lower Mainland - BC & Various locations in Ontario-$105,400.00 - $158,100.00 Annually
  • Locations in Lower Mainland -- BC, GTA & Ottawa Ontario-$114,600.00 - $164,600.00 Annually
Pay Transparency

In compliance with pay transparency laws, pay ranges are provided for positions in locations where required. Please note, the final agreed upon compensation is based on individual education, qualifications, experience, and work location. At Stantec certain roles are bonus eligible. Actual compensation for part-time roles will be pro-rated based on the agreed number of working hours per week.

Benefits Summary

Regular full-time and part-time employees (working at least 20 hours per week) will have access to health, dental, and vision plans, a wellness program, health care spending account, wellness spending account, group registered retirement savings plan, employee stock purchase program, group tax-free savings account, life and accidental death & dismemberment (AD&D) insurance, short-term/long-term disability plans, emergency travel benefits, tuition reimbursement, professional membership fee coverage, and paid time off.

Temporary/casual employees will have access to group registered retirement savings plan, employee stock purchase program, and group tax-free savings account.

The benefits information listed above may not apply to union positions because benefits for such positions are governed by applicable collective bargaining agreements.

Primary Location

Canada | ON | Toronto

Other Locations

Canada | BC | Vancouver

Organization

BC-1374 IT Services-CA Corporate

Employee Status

Regular

Business Justification

Replacement

Travel

No

Schedule

Full time

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Winnipeg

On-site
CAD 105,000 - 165,000
Health, dental, and vision plans
Wellness program
Employee stock purchase plan
+1
Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Edmonton

On-site
CAD 105,000 - 165,000
Health and dental plans
Vision care
Wellness program
Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Montreal (administrative region)

On-site
CAD 105,000 - 165,000
Health, dental, vision plans
Wellness program
Tuition reimbursement
+1
Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Southwestern Ontario

On-site
CAD 115,000 - 165,000
Health benefits
Dental coverage
Vision plans
+2
Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Toronto

On-site
CAD 105,000 - 158,000
Health insurance
Retirement plan
Paid time off
Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Regina

On-site
CAD 105,000 - 165,000
Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Saskatoon

On-site
CAD 110,000 - 160,000
Health, dental, and vision plans
Wellness program
Employee stock purchase program
+1
Senior Ethical Hacker
Senior Ethical Hacker

Stantec Consulting International Ltd. • Toronto

On-site
CAD 115,000 - 165,000
Health, dental, vision plans
Wellness program
Employee stock purchase program
+1
Senior Ethical Hacker
Senior Ethical Hacker

Stantec • Burnaby

On-site
CAD 105,000 - 165,000
Health plan
Dental plan
Vision plan
+4
Senior Ethical Hacker
Senior Ethical Hacker

Stantec Consulting International Ltd. • Edmonton

On-site
CAD 105,000 - 165,000