Turn this role into an interview — a resume and cover letter built around what this employer wants.
Fraser Health is seeking an Expert-level Information Security Consultant to advance the organization’s penetration testing program. This remote role conducts grey-box tests across a broad Web/API portfolio, manages assessments through a secure management platform, and drives remediation lifecycles with emphasis on patient data safety.
Responsibilities include scoping, executing tests, generating detailed reports, and coordinating with owners for validated remediation, while adhering to
This is a remote position. We are seeking an Expert-level Information Security Consultant to drive the ongoing maturity of Fraser Health's penetration testing program. In this role, you will perform end-to-end grey-box penetration tests across a large portfolio of web and API applications while utilizing a secure, browser-based management platform to schedule assessments, track vulnerabilities, and manage remediation lifecycles
Conduct T-shirt sizing (Small, Medium, Large) and scoping for onboarded applications based on dynamic web pages and user roles.
Execute manual and tool-assisted grey-box penetration tests across approximately 123 Web/API applications (30 Large, 51 Medium, 42 Small), completing testing within 5–10 days per application.
Manage the end-to-end testing lifecycle for each application from kickoff meeting to final sign-off within 20–25 days.
Conduct expert manual assessments covering authentication, session management, MFA bypass, horizontal/vertical privilege escalation, IDOR/BOLA, API vulnerabilities, and business logic workflow abuses.
Chain vulnerabilities into realistic attack paths and perform controlled, non-destructive validation within live healthcare environments without disrupting operational or clinical systems.
Deploy and operate a browser-based, RBAC/MFA-enabled pen test platform supporting 6–12 month forward scheduling, metric dashboards, report retention, automated notifications, and GRC tool integration.
Install, configure, and maintain all necessary licensed testing tools inside the client-provided penetration testing machines accessed via the Privileged Access Management (PAM) platform.
Author comprehensive reports with testing methodologies, scorecards, reproducible steps, root-cause analyses, and prioritized remediation guidance, followed by stakeholder presentations.
Follow up with application owners on vulnerability mitigations and perform targeted retests on resolved findings.