Pen test platform

NEPSE Trading

Northern (KY)

Hybrid

USD 120,000 - 210,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Fraser Health is seeking an Expert-level Information Security Consultant to advance the organization’s penetration testing program. This remote role conducts grey-box tests across a broad Web/API portfolio, manages assessments through a secure management platform, and drives remediation lifecycles with emphasis on patient data safety.

Responsibilities include scoping, executing tests, generating detailed reports, and coordinating with owners for validated remediation, while adhering to

Qualifications

  • Active penetration testing certifications such as OSCP or CEH.
  • Minimum 10 years of directly related consulting experience.
  • Healthcare and production experience in sensitive environments with zero impact.
  • Permanent employee of the service provider (no subcontracting).
  • Familiarity with OWASP, NIST SP 800-53A, PCI DSS 11.3 and related standards.

Responsibilities

  • Perform end-to-end grey-box penetration tests across Web/API applications.
  • Chain vulnerabilities into realistic attack paths and validate in clinical environments.
  • Manage testing lifecycles from kickoff to final sign-off within tight SLAs.
  • Author comprehensive reports with methodologies, findings, and remediation guidance.
  • Coordinate remediation tracking and retests with application owners.

Skills

Expert-level
Penetration testing
Threat modeling
OWASP
NIST SP 800-53A

Education

Relevant Degree
Relevant Diploma
Relevant Certificate

Tools

PAM platform
RBAC
MFA
GRC tools

Job description

This is a remote position. We are seeking an Expert-level Information Security Consultant to drive the ongoing maturity of Fraser Health's penetration testing program. In this role, you will perform end-to-end grey-box penetration tests across a large portfolio of web and API applications while utilizing a secure, browser-based management platform to schedule assessments, track vulnerabilities, and manage remediation lifecycles

Requirements Scoping & Sizing

Conduct T-shirt sizing (Small, Medium, Large) and scoping for onboarded applications based on dynamic web pages and user roles.

Penetration Testing Execution

Execute manual and tool-assisted grey-box penetration tests across approximately 123 Web/API applications (30 Large, 51 Medium, 42 Small), completing testing within 5–10 days per application.

Engagement Lifecycles

Manage the end-to-end testing lifecycle for each application from kickoff meeting to final sign-off within 20–25 days.

In-Depth Vulnerability Assessment

Conduct expert manual assessments covering authentication, session management, MFA bypass, horizontal/vertical privilege escalation, IDOR/BOLA, API vulnerabilities, and business logic workflow abuses.

Attack-Path Validation

Chain vulnerabilities into realistic attack paths and perform controlled, non-destructive validation within live healthcare environments without disrupting operational or clinical systems.

Platform Management

Deploy and operate a browser-based, RBAC/MFA-enabled pen test platform supporting 6–12 month forward scheduling, metric dashboards, report retention, automated notifications, and GRC tool integration.

Tooling & Environment Setup

Install, configure, and maintain all necessary licensed testing tools inside the client-provided penetration testing machines accessed via the Privileged Access Management (PAM) platform.

Reporting & Debriefs

Author comprehensive reports with testing methodologies, scorecards, reproducible steps, root-cause analyses, and prioritized remediation guidance, followed by stakeholder presentations.

Remediation Tracking & Retesting

Follow up with application owners on vulnerability mitigations and perform targeted retests on resolved findings.

Required Qualifications & Experience
  • Certifications: Active penetration testing certification such as OSCP (Offensive Security Certified Professional), CEH (Certified Ethical Hacker), or an equivalent credential.
  • Seniority Threshold (Expert Level): Relevant Degree + minimum 6 years of consulting experience.
  • Seniority Threshold (Expert Level): Relevant Diploma + minimum 7 years of consulting experience.
  • Seniority Threshold (Expert Level): Relevant Certificate + minimum 8 years of consulting experience.
  • Minimum 10 years of directly related consulting experience.
  • Healthcare & Production Experience: Demonstrated experience performing penetration testing safely in Canadian healthcare or sensitive enterprise environments with zero clinical/operational impact.
  • Employment Status: Must be a permanent employee of the service provider (subcontracting is prohibited).
  • Framework Alignment: Practical working knowledge of OWASP, NIST SP 800-53A, PCI DSS 11.3, and IDART standards.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Remote Senior Penetration Tester - Web & API Platforms
Remote Senior Penetration Tester - Web & API Platforms

NEPSE Trading • Northern (KY)

Hybrid
USD 120,000 - 210,000
Penetration Tester
Penetration Tester

CGVantage • United States

On-site
USD 110,000 - 170,000
Remote Penetration Tester
Remote Penetration Tester

Philadelphia Comapny • Atlanta (GA)

Remote
USD 80,000 - 120,000
Penetration Tester
Penetration Tester

TalentFish • Illinois

On-site
USD 100,000 - 160,000
Penetration Tester
Penetration Tester

BrothersTech • United States

On-site
USD 95,000 - 150,000
Penetration Tester / Ethical Hacker (Offensive Security)
Penetration Tester / Ethical Hacker (Offensive Security)

Zoho • United States

On-site
USD 83,000 - 165,000
Penetration Tester
Penetration Tester

Akaasa Technologies • Falls Church (VA)

On-site
USD 120,000 - 180,000
Penetration Tester
Penetration Tester

Cybersecurity Jobs • Nashville (TN)

On-site
USD 90,000 - 140,000
Limited immigration sponsorship may be
Penetration Tester
Penetration Tester

NikSoft Systems Corporation • United States

On-site
USD 120,000 - 170,000
Penetration Tester - Infrastructure & Red Team
Penetration Tester - Infrastructure & Red Team

Cybersecurity Jobs • Miami (FL)

Hybrid
USD 90,000 - 130,000
Education reimbursement
Volunteer day
Birthday day off
+2