Senior Offensive Security Engineer -SAST, DAST, SCA, IAST

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision!

Toronto

On-site

CAD 120,000 - 160,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Astra-North Infoteck Inc. is seeking a Certified Senior Offensive Security Engineer to enhance their AI vulnerability program. This role involves assessing vulnerabilities that affect AI, developing prompts for AI agents, and ensuring AI-driven fixes effectively resolve underlying issues. The ideal candidate should have over 10 years of experience in offensive security with a solid background in exploit development and red teaming. Responsibilities also include translating analysis into reusable prompts and executing in-depth assessments across various security findings. Collaborate with the vulnerability management team to fortify defenses against evolving threats.

Qualifications

  • 10+ years in offensive security with hands-on exploit development and red teaming.
  • Ability to identify and validate exploit chains across vulnerability classes.
  • Deep understanding of various vulnerability types including memory safety and injection.

Responsibilities

  • Lead exploitability assessment and false positive analysis across security findings.
  • Develop offensive prompts, attack scenarios, and evaluation criteria for AI agents.
  • Translate analysis into reusable AI agent prompts and skills.

Skills

Offensive security
Hands-on exploit development
Red teaming
Penetration testing
Experience in SAST
Experience in DAST
Experience in SCA
Experience in IAST
Coding in Java
Coding in Python
Coding in C#
Coding in Go

Education

Relevant certifications (OSCP, OSCE, OSEP, OSWE, GXPN, GWAPT)

Tools

Application security testing tools

Job description

Certified Senior Offensive Security Engineer - SAST, DAST, SCA, IAST

Role Overview: You will bring deep offensive security expertise to the agentic AI vulnerability program. You will determine what is truly exploitable, identify how vulnerabilities chain into real attacks, and validate that AI-generated fixes close the actual root cause—not just suppress scanner alerts.

Your offensive analysis, exploit chain reasoning, and false positive judgment will be channeled into AI agents through prompts, evaluation criteria, and workflows that scale your expertise across the bank.

You will work alongside the vulnerability management team and AI capability suppliers, contributing the deep offensive perspective the program needs.

What You Will Do
  • Lead exploitability assessment and false positive analysis across SAST, DAST, SCA, IAST, container, and infrastructure findings
  • Translate analysis into reusable AI agent prompts and skills
  • Identify exploit chains across vulnerability classes and encode reasoning into agent workflows
  • Validate AI-generated fixes and ensure they close exploitable conditions
  • Develop offensive prompts, attack scenarios, and evaluation criteria for AI agents
  • Translate offensive insights into prioritization signals and remediation guidance via AI-driven workflows
Top 3 Required Skills
  • Offensive security, hands-on exploit development, red teaming, penetration testing
  • Hands-on experience in SAST / DAST / SCA / IAST
  • Coding in Java, Python, C#, or Go
Must-Have Requirements
  • 10+ years in offensive security with hands-on exploit development and red teaming
  • One or more certifications: OSCP, OSCE, OSEP, OSWE, GXPN, GWAPT
  • Ability to identify and validate exploit chains across vulnerability classes
  • Deep understanding of vulnerability types (memory safety, injection, auth flaws, deserialization, race conditions, supply chain attacks)
  • Strong code reading ability in at least three programming languages
  • Hands-on experience with application security testing tools (SAST, DAST, SCA, IAST) and false positive analysis
Nice-to-Have
  • CVEs, conference talks (DEF CON, Black Hat, OffensiveCon, Recon)
  • CTF achievements or bug bounty experience
  • Software engineering experience in production systems
  • Defensive security engineering exposure
  • Familiarity with LLMs / agentic AI in security
  • CI/CD & container security (Docker, Kubernetes, GitHub Actions, Jenkins)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Oakville

On-site
CAD 120,000 - 180,000
Information Security Specialist – Attack Surface Reduction
Information Security Specialist – Attack Surface Reduction

Jobtailor • Toronto

On-site
CAD 120,000 - 160,000
Application Security Engineer
Application Security Engineer

Segment (Twilio) • Toronto

On-site
CAD 100,000 - 130,000
Offensive Security Lead - Penetration Testing
Offensive Security Lead - Penetration Testing

RSM Canada • Canada

On-site
CAD 80,000 - 100,000
Offensive Security Engineer- Principal Consultant
Offensive Security Engineer- Principal Consultant

Synechron • Toronto

Hybrid
CAD 130,000 - 140,000
Global offices
Paid annual leave + personal leave
Comprehensive insurance plan
+6
AI Security Architect
AI Security Architect

Jobtailor • Calgary

On-site
CAD 150,000 - 190,000
Senior Red Team Operator
Senior Red Team Operator

Sun Life Financial • Toronto

On-site
CAD 90,000 - 120,000
Senior Red Team Engineer
Senior Red Team Engineer

OffSeq • North Glengarry

Hybrid
CAD 40,983 - 49,089
Senior AI Platform Engineer
Senior AI Platform Engineer

Luxoft • Toronto

On-site
CAD 120,000 - 180,000
Forward Deployed AI Engineer
Forward Deployed AI Engineer

Kinvie • Toronto

On-site
CAD 90,000 - 120,000