Enable job alerts via email!

Senior Penetration Tester

Alquemy Search & Consulting

Toronto

On-site

CAD 100,000 - 140,000

Full time

29 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading Canadian financial institution seeks a Senior Penetration Tester / Red Team Operator in Toronto to enhance their cybersecurity measures. This senior-level role involves executing advanced penetration tests and red team operations while contributing to the organization's strategic security framework. The ideal candidate possesses extensive experience, strong analytical skills, and effective communication abilities to present findings to diverse stakeholders.

Qualifications

  • Minimum 5 years in penetration testing/red team operations.
  • At least one CREST certification required.
  • Strong knowledge of Windows/Linux, networking, and cloud platforms.

Responsibilities

  • Lead penetration testing across various environments.
  • Design red team operations to evaluate response capabilities.
  • Prepare detailed reports on findings with actionable recommendations.

Skills

Analytical
Problem-solving
Communication

Education

Bachelor’s degree in Computer Science, Information Security, or related discipline

Tools

Metasploit
Burp Suite
Kali Linux
Python
Bash
PowerShell

Job description

Location : Toronto, Ontario, Canada (On-site presence may be required)

Industry : Financial Services

About the Client :

We are engaged on behalf of a leading Canadian financial institution to identify a highly qualified Senior Penetration Tester / Red Team Operator . This position plays a critical role in safeguarding enterprise infrastructure through the execution of advanced security assessments, including red team operations and OSFI-regulated penetration testing. The successful candidate will contribute directly to strengthening the organization’s cybersecurity posture in alignment with regulatory and business requirements.

Position Overview :

This is a senior-level opportunity suited for an individual with extensive experience in offensive security. The successful candidate will lead and execute comprehensive penetration testing and red teaming engagements, simulating sophisticated attack scenarios to assess and enhance the effectiveness of defensive security controls. A high level of technical proficiency, strategic thinking, and the ability to communicate complex findings to a variety of stakeholders are essential for this role.

Key Responsibilities :

  • Lead and execute comprehensive penetration testing engagements across network, web application, mobile, and cloud environments.
  • Design and conduct red team operations to evaluate detection and response capabilities.
  • Perform penetration testing in accordance with OSFI (Office of the Superintendent of Financial Institutions) regulatory requirements.
  • Identify and exploit vulnerabilities using a combination of manual techniques and automated tools.
  • Prepare detailed reports outlining technical findings and provide actionable recommendations.
  • Present findings to both technical teams and senior leadership in a clear and professional manner.
  • Maintain current knowledge of emerging threats, attack techniques, and relevant industry trends.
  • Collaborate with internal teams to continuously improve security practices and protocols.
  • Support the development and mentorship of junior security professionals, as applicable.

Qualifications and Experience :

  • A minimum of 5 years of relevant experience in penetration testing and / or red team operations.
  • Mandatory : At least one current CREST certification (e.g., CCT INF, CCT APP, CCSAS). Additional CREST certifications are strongly preferred.
  • Proficiency in using industry-standard tools (e.g., Metasploit, Burp Suite, Kali Linux) and scripting languages such as Python, Bash, or PowerShell.
  • In-depth understanding of vulnerabilities (e.g., OWASP Top 10), common attack vectors, and exploitation techniques.
  • Strong knowledge of operating systems (Windows and Linux), networking concepts, and cloud platforms (AWS, Azure, GCP).
  • Exceptional analytical, problem-solving, and communication skills, both written and verbal.
  • Proven ability to document findings clearly and communicate effectively with technical and non-technical stakeholders.

Preferred Qualifications :

  • Additional certifications such as CISSP, CISA, CRISC, GPEN, PFI, or QSA.
  • Experience within the financial services sector and familiarity with OSFI cybersecurity requirements.
  • Exposure to adversary emulation and threat intelligence methodologies.
  • Familiarity with SIEM solutions and other security monitoring tools.
  • Bachelor’s degree in Computer Science, Information Security, or a related discipline.
Create a job alert for this search
Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Penetration Tester

Scotiabank

Toronto null

On-site

On-site

CAD 100,000 - 130,000

Full time

11 days ago

Senior Penetration Tester

Scotiabank

Toronto null

On-site

On-site

CAD 90,000 - 130,000

Full time

8 days ago

Principal Penetration Tester, Canada

Aon Hewitt

Quebec null

Remote

Remote

CAD 80,000 - 120,000

Full time

30+ days ago

Security Specialist (Penetration Tester) 8435-3112

Foilcon

Toronto null

On-site

On-site

CAD 80,000 - 120,000

Full time

30+ days ago

Security Specialist (Penetration Tester) 8437-3112

Foilcon

Toronto null

Hybrid

Hybrid

CAD 80,000 - 120,000

Full time

30+ days ago

Security Specialist (Penetration Tester) 8437-3112

Dheya

Toronto null

Hybrid

Hybrid

CAD 70,000 - 110,000

Full time

30+ days ago

Security Specialist (Penetration Tester) 8435-3112

Dheya

Toronto null

Hybrid

Hybrid

CAD 70,000 - 110,000

Full time

30+ days ago