Offensive Security specialist

1 week ago


Toronto, Ontario, Canada Hays Full time

WORK ILLUSTRATION:

We are seeking a highly skilled and motivated Contractor, Offensive Security Specialist to join our security team. This is a highly technical role which involves simulating real-world cyberattacks to identify vulnerabilities in our systems, networks, and applications, and providing recommendations to strengthen our security posture. The ideal candidate will have hands-on experience in penetration testing, red team operations, and adversary emulation, along with a passion for staying on the cutting edge.

KEY RESPONSIBILITIES:

Penetration Testing:

  • Conduct ethical hacking assessments on web applications, networks, systems, and wireless environments to identify vulnerabilities.
  • Perform vulnerability assessments using novel, and industry-standard tools and techniques.
  • Develop and execute manual and automated penetration testing procedures, including black-box and white-box testing.
  • Perform risk assessments to evaluate the severity of discovered weaknesses.
  • Provide detailed written reports on vulnerabilities, exploitation techniques, and recommendations for remediation.
  • Collaborate with development teams and system administrators to implement security best practices across the technology stack, as applicable.

Red/Purple Team Operations:

  • Conduct red teaming exercises to simulate advanced persistent threats (APTs) likely to target the organization's environment, focusing on evading detection and bypassing security controls.
  • Simulate attacks to test incident response and security operations team responses to realistic threat scenarios.
  • Perform social engineering assessments, including phishing campaigns, to evaluate human vulnerabilities.
  • Develop and execute advanced adversary tactics to test the organization's defenses, including exploitation, lateral movement, privilege escalation, data exfiltration and encryption.
  • Lead or support tabletop exercises and training sessions to improve awareness and response protocols.

Collaboration and Reporting:

  • Work closely with other IT teams to ensure comprehensive coverage of security controls.
  • Provide actionable recommendations to reduce risk and improve the organization's security posture.
  • Communicate findings to both technical and non-technical stakeholders in clear and concise reports.
  • Mentor and train junior team members and other security staff on offensive security techniques.

REQUIRED SKILLS & QUALIFICATIONS:

  • Proven experience in offensive security, or ethical hacking in an enterprise environment.
  • Strong understanding of networking protocols, operating systems (Windows, Linux), web application architectures, and cloud security.
  • Expertise in commonly used offensive security tools.
  • Familiarity with scripting and automation tools.
  • Experience with exploiting common vulnerabilities (e.g., OWASP Top 10) and the latest attack vectors (e.g., Ransomware, Supply Chain Attacks).
  • In-depth knowledge of penetration testing techniques and methodologies (e.g., OSCP, PTES, NIST SP , etc.).
  • Experience in simulating attacks against cloud infrastructure and OT/ICS systems are a big plus.
  • Familiarity with security frameworks and compliance standards (NIST, PCI-DSS, GDPR, etc.).

DESIRABLE CERTIFICATIONS:

While certifications are not mandatory, the following certifications are highly valued for this position:

  • Offensive Security Certified Professional (OSCP)
  • Certified Red Team Professional (CRTP) - Focuses on adversary simulation and red teaming skills.
  • GIAC Penetration Tester (GPEN) - Demonstrates expertise in penetration testing methodologies.
  • Certified Expert Penetration Tester (CEPT) - Advanced penetration testing certification.
  • Certified Incident Handler (GCIH) - Strong knowledge of incident response and handling breaches.

DESIRABLE SOFT SKILLS

  • Problem-solving skills: Ability to think like an attacker and work through complex problems creatively.
  • Attention to detail: Ensuring thorough testing and identification of all in-scope vulnerabilities.


  • Toronto, Ontario, Canada Intact Full time

    Our employees are at the heart of everything we do. Together, we help people, businesses, and society prosper in good times and be resilient in bad times.Our employee promise represents Intact's commitment to you in exchange for living our Values, striving to do your best work, being open to change and investing in your career. In return, we promise to...


  • Toronto, Ontario, Canada Robinhood Full time

    Join us in building the future of finance.Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you're ready to be at the epicenter of this historic cultural and financial shift, keep reading.About the team +...


  • Toronto, Ontario, Canada Autodesk Full time US$138,100 - US$223,300

    Job Requisition ID # 25WD91774English translation will follow/La traduction en anglais suivra25WD91774, Développeur principal en sécurité offensiveAperçu du PosteVous êtes passionné par les ordinateurs, les logiciels et l'art de démonter des codes, des appareils, voire des voitures ? Vous aimez protéger les gens contre les menaces numériques,...


  • Toronto, Ontario, Canada Robinhood Full time

    Join us in building the future of finance.Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you're ready to be at the epicenter of this historic cultural and financial shift, keep reading. About the team +...


  • Toronto, Ontario, Canada Robinhood Full time

    Join us in building the future of finance. Our mission is to democratize finance for all. An estimated $124 trillion of assets will be inherited by younger generations in the next two decades. The largest transfer of wealth in human history. If you're ready to be at the epicenter of this historic cultural and financial shift, keep reading. About the team...


  • Toronto, Ontario, Canada CAAT Pension Plan Full time

    At CAAT, we're passionate about what we do. And it showsHere, you'll find a cultural spark in everything we do – from the way we partner with members and employers, to the way we work, collaborate, and grow. It doesn't just feel different at CAAT. Itisdifferent. We're one of the fastest-growing pensions in the country for a reason. We challenge the status...


  • Toronto, Ontario, Canada StafinGo Full time

    Senior Security Specialist – Governance, Risk & Compliance (GRC) / Cyber DefenceLocation:Toronto, ON (Hybrid – up to 3 days onsite)Contract Length: 2-3 months to start(with potential extension)Sector:Public Sector / HealthcareA leadingpublic-sector organization in Ontariois seeking a highly experiencedSenior Security Specialistto support multiple...


  • Toronto, Ontario, Canada RBC Full time

    Job DescriptionWhat Will You Do?Execute Red Team operations, Purple Team exercises, and hypothesis-led engagements in mature production environmentsDevelop offensive capabilities: exploit development, novel C2 channels, automation, and moreActively participate in the full lifecycle of projects — from idea development and proposal writing to execution and...


  • Toronto, Ontario, Canada RBC Full time

    Job DescriptionWhat Will You Do?Execute Red Team operations, Purple Team exercises, and hypothesis-led engagements in mature production environmentsDevelop offensive capabilities: exploit development, novel C2 channels, automation, and moreActively participate in the full lifecycle of projects — from idea development and proposal writing to execution and...


  • Toronto, Ontario, Canada Royal Bank of Canada Full time

    Job DescriptionWhat Will You Do?Execute Red Team operations, Purple Team exercises, and hypothesis-led engagements in mature production environmentsDevelop offensive capabilities: exploit development, novel C2 channels, automation, and moreActively participate in the full lifecycle of projects — from idea development and proposal writing to execution and...