Senior Security Consultant (Web Application Penetration Tester)

NetSPI

Toronto

On-site

CAD 100,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

NetSPI seeks a Senior Security Consultant to lead penetration testing engagements on web applications and underlying APIs, delivering clear, actionable reports and strengthening client security posture.

You will mentor junior testers, stay current with attack techniques, and collaborate with client teams to tailor testing approaches while adhering to NetSPI standards.

Qualifications

  • Bachelor’s degree or higher in IT, CS, Engineering, Math or equivalent.
  • 3–5+ years of Penetration Testing experience.
  • Familiarity with offensive security tools and frameworks.
  • Understanding of OWASP Top 10 and MITRE ATT&CK.
  • Strong written and verbal communication; travel up to 5–10%.

Responsibilities

  • Lead web application and API penetration testing engagements.
  • Review and mentor junior testers; provide QA oversight.
  • Create and deliver penetration testing reports in client environments.
  • Develop innovative testing techniques and contribute to NetSPI products.

Skills

Penetration Testing
Communication skills
Team mentorship

Education

Bachelor’s degree or higher (IT/CS/Engineering/Math)

Tools

Kali Linux
Burp Suite
Metasploit
Nessus

Job description

About NetSPI

NetSPI® is an award-winning pioneer of Penetration Testing as a Service (PTaaS) with its AI-powered platform supported by more than 350 in‑house cybersecurity experts. Specializing in 50+ pentest types, attack surface visibility, vulnerability prioritization, and attack simulation, NetSPI delivers security testing with unprecedented clarity, speed, and scale.

Mission

Join the mission as a Senior Security Consultant. We are seeking a skilled and detail‑oriented Penetration Tester to conduct thorough security assessments, identify vulnerabilities, and provide expert recommendations to strengthen our clients' security posture. As a Penetration Tester supporting web applications, you will work closely with clients to deliver clear, actionable reports and contribute to the development of security best practices.

Responsibilities
  • Conduct engagements on web applications and underlying APIs independently and provide technical oversight.
  • Review reports for accuracy in technical oversight, perform weekly QA oversight, and provide mentoring support to others.
  • Create, deliver, and collaborate on penetration testing reports in diverse client environments, maintaining client‑specific processes, reporting standards, and access protocols to help improve their security posture.
  • Research and develop innovative techniques, tools, and methodologies for penetration testing services, alongside commitment to improvement and execution on NetSPI specific products and processes.
  • Participate in development, implementation, and oversight of testing, delivery, and management strategies for key client accounts.
  • Perform administrative tasks related to day‑to‑day consulting activities to ensure smooth business and engagement operations.
Minimum Qualifications
  • Bachelor’s degree or higher, with a focus on IT, Computer Science, Engineering or Math or equivalent experience.
  • Minimum of 3‑5 years of work experience in Penetration Testing.
  • Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Metasploit, Nessus).
  • Familiarity with offensive and defensive IT concepts and protocols.
  • Extensive understanding of the OWASP Top 10, MITRE ATT&CK framework, and various security frameworks.
  • Working knowledge of Windows, Linux and MacOS operating systems internals.
  • Experience mentoring or coaching to growing team members, while sharing knowledge externally through blogs, hosting webinars, or presenting at conferences.
  • Ability to work independently and as part of a team.
  • Proficient communication skills, both written and verbal.
  • Willingness to travel up to 5‑10%.
  • This position requires an 8‑hour workday, with occasional evenings or weekends necessary to meet project deadlines or critical needs.
Preferred Qualifications
  • Ability to provide technical and QA oversight on web applications and underlying APIs.
  • Experience in one or more of the following programming or scripting languages (e.g., Ruby, Python, Perl, C, C++, Java, and C#).
  • Offensive cybersecurity certifications (e.g., GXPN, GPEN, OSCP, GWAPT).

We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Offensive Security Lead - Penetration Testing
Offensive Security Lead - Penetration Testing

RSM Canada • Canada

On-site
CAD 80,000 - 100,000
Senior Penetration Tester
Senior Penetration Tester

OffSeq • North Glengarry

Hybrid
CAD 36,000 - 43,000
Source-code review
OT/ICS testing
Mobile/thick-client testing
+2
Junior Penetration Tester
Junior Penetration Tester

Software Secured • Ottawa

Hybrid
CAD 55,000 - 85,000
UberEats budget
Home office stipend
3 weeks vacation
+3
Penetration Testing Engineer - Web and Cloud Security
Penetration Testing Engineer - Web and Cloud Security

RSM Canada • Toronto

On-site
CAD 62,000 - 100,000
Junior Project Manager
Junior Project Manager

Jobless • Canada

Hybrid
CAD 85,000 - 125,000
Comprehensive benefits and GRSPu
Immediate and continual offensive sec.
Amazing team and working environment
+3
Penetration Tester
Penetration Tester

Akkodis • Toronto

Hybrid
CAD 100,000 - 140,000
Senior Cybersecurity Test Architect
Senior Cybersecurity Test Architect

Myticas Consulting • Ottawa

On-site
CAD 120,000 - 160,000
Senior Penetration Tester — Remote/Hybrid (Baltics)
Senior Penetration Tester — Remote/Hybrid (Baltics)

OffSeq • North Glengarry

Hybrid
CAD 36,000 - 43,000
Source-code review
OT/ICS testing
Mobile/thick-client testing
+2
Senior Penetration Testing Lead - Web & Network Security
Senior Penetration Testing Lead - Web & Network Security

Rubicon Path • Toronto

On-site
CAD 90,000 - 120,000
Senior Penetration Tester — Cloud & Web Apps
Senior Penetration Tester — Cloud & Web Apps

Stantec Consulting International Ltd. • Mississauga

On-site
CAD 115,000 - 165,000
Health, dental, vision plans
Wellness program
Employee stock purchase program