Current jobs related to Penetration Tester - Ottawa, Ontario - Malleum

  • Penetration Tester

    2 days ago


    Ottawa, Ontario, Canada Malleum Full time

    About UsWe are a premier cybersecurity consultancy, blending advanced offensive and defensive strategies to safeguard our customers.With a team known for its contributions to cybersecurity research at platforms like Black Hat and DEF CON, we excel at identifying and mitigating sophisticated threats. Large enterprises from a range of industries trust us for...

  • Penetration Tester

    3 days ago


    Ottawa, Ontario, Canada Software Secured Full time

    Penetrate to Secure: Join Our Team!Software Secured is a leading Penetration Testing as a Service company, dedicated to helping software development teams identify and address security vulnerabilities in their applications. We are seeking an experienced Intermediate Pentester to join our team and contribute to delivering high-quality security services to our...


  • Ottawa, Ontario, Canada ipss inc. Full time

    About the RoleIPSS Inc. is seeking a highly skilled and experienced Senior Specialist Offensive Security to join our Threat Management unit's offensive security section. As a key member of our team, you will be responsible for conducting penetration tests and red team exercises, providing recommendations and direction in remediating identified security...


  • Ottawa, Ontario, Canada Pager Full time

    Senior Security Engineer 3, Product & Application SecurityTorontoPagerDuty empowers teams of all kinds to do the critical work that moves business forward through the PagerDuty Operations Cloud.PagerDuty is seeking a Senior Security Engineer to join our diverse, customer-focused team As a Senior Security Engineer, you will be a key contributor in leading,...

  • Penetration Tester

    2 weeks ago


    Ottawa, Canada Nova Networks Inc. Full time

    The Penetration Tester will provide broad and in depth knowledge to conduct offensive cyber operations across the organization globally. In this role, you will conduct offensive security operations to emulate adversary tactics and procedures to test preventative, detective and response controls across the global technology landscape. You will use your...

  • Penetration Tester

    4 weeks ago


    Ottawa, Canada Malleum Full time

    About UsWe are a premier cybersecurity consultancy, blending advanced offensive and defensive strategies to safeguard our customers.With a team known for its contributions to cybersecurity research at platforms like Black Hat and DEF CON, we excel at identifying and mitigating sophisticated threats. Large enterprises from a range of industries trust us for...

  • Penetration Tester

    2 weeks ago


    Ottawa, Canada MSi Corp (Bell Canada) Full time

    **Key Responsibilities and Job Duties**: - Run and explore new Hacking Tools and Frameworks against our landscape. - Continuously improve our offensive and defensive capabilities. - Create, organize, document, and run red teaming exercises. - Drive lessons learned with Security Architect and follow up on activities after red teaming exercises. - Help...


  • Ottawa, Canada Lightship Security Full time

    Lightship Security is a market leader in IT security standards-based conformance testing and test automation. We work with leading-edge security technology vendors from around the world to perform conformance testing to various IT security standards such as Common Criteria and FIPS 140. We are committed to creating real-world value through continued...


  • Ottawa, Canada Cyberclan Full time

    **Summary/Objective** **Essential Functions** - Performing sophisticated adversary simulation operations against CyberClan and customers systems to identify gaps in prevention, detection, and/or response. - Leveraging threat intelligence to hunt for indicators of compromise and vulnerabilities. - Managing and improving breach and attack simulation tools. -...


  • Ottawa, Canada Lightship Security Full time

    Highlights of the Job **Introduction** Lightship Security is a market leader in IT security standards-based conformance testing and test automation. We work with leading edge security technology vendors from around the world to perform conformance testing to various IT security standards such as Common Criteria and FIPS 140. We are committed to creating...


  • Ottawa, Canada Convergence Networks Full time

    SERVICE DESK ADMINISTRATOR SECURITY CONSULTING AND ASSESSMENT OTTAWA - Full time on client site Convergence Networks is one of North America’s leading managed service and managed security providers. We are a service company focused on helping clients leverage technology as a strategic tool and proactively protecting their business. We are fueled by...


  • Ottawa, Canada Software Secured Full time

    Software Secured is a leading Penetration Testing as a Service company, with a head office in beautiful Ottawa, Canada. We help software development teams get ahead of hackers using a suite of services and products. Our marketing team is looking for multiple freelance technical content writers who can help us scale our content production operations. What...

Penetration Tester

2 weeks ago


Ottawa, Ontario, Canada Malleum Full time
About Us
We are a premier cybersecurity consultancy, blending advanced offensive and defensive strategies to safeguard our customers.

With a team known for its contributions to cybersecurity research at platforms like Black Hat and DEF CON, we excel at identifying and mitigating sophisticated threats. Large enterprises from a range of industries trust us for advanced adversarial emulation and for critical support in managing their cyber frameworks. Governments trust us with classified projects, relying on our precision and discretion to handle sensitive information securely.

We're a small group that makes a big impact. Our deep technical expertise and our commitment to clients continues to fuel our success, and with success comes growth – we're currently searching for an intermediate Pen Tester…

Role Profile
Working remotely, in this position your mandate will be to assess the security posture of our clients by identifying and exploiting vulnerabilities in networks, applications, and systems. You will conduct controlled security assessments, execute attack simulations, and analyze security weaknesses. You'll document findings and collaborate with colleagues and client teams to support remediation efforts. You will also contribute to analysis and reporting that provides actionable insights for improving defenses.

This is an outstanding opportunity to join an accelerating startup, work with cutting-edge tech, and tackle critical problems on high-stakes engagements.

Key Responsibilities
  • Conduct web, network, mobile, and API penetration tests to identify vulnerabilities. 
  • Support team assessments, simulating real-world attack scenarios. 
  • Develop and execute custom exploits, scripts, and attack chains. 
  • Conduct source code reviews for security weaknesses in applications. 
  • Assess cloud security in AWS, Azure, and GCP, as well as containerized environments like Docker and Kubernetes. 
  • Collaborate with blue teams, SOC analysts, and developers to remediate findings. 
  • Write detailed technical reports and present findings to technical and non-technical stakeholders. 
  • Stay updated on zero-day vulnerabilities, APT tactics, and emerging threats. 
  • Participate in CTFs, security research, and bug bounty programs to refine skills. 
Candidate Profile
As an ideal candidate, you're skilled in pen testing and have exposure to adversarial emulation and custom exploit development. You're a natural hacker with a founder's mindset, eager to learn and collaborate, and prone to thrive in a startup environment.   

Key Qualifications
  • 3-5 years of hands-on penetration testing experience. 
  • Proficiency in manual testing techniques beyond automated scanning. 
  • Strong knowledge of OWASP Top 10, MITRE ATT&CK, and CVSS scoring.
  • Experience with Active Directory attacks, privilege escalation, and lateral movement. 
  • Skilled in the use of some or all of: Burp Suite, Nessus, Metasploit, Kali Linux.
  • Familiarity with scripting in Python, PowerShell, Bash, or Ruby.
  • Understanding of secure coding practices and DevSecOps principles. 
  • Excellent communication and interpersonal skills.
Nice-to-Haves
  • Experience in cloud security testing.
  • Knowledge of hardware hacking, IoT security, or reverse engineering. 
  • Familiarity with SOC operations, threat hunting, and incident response. 
  • Previous experience in bug bounty programs or published security research. 

Powered by JazzHR