Senior Offensive Security Advisor
1 week ago
As a Senior Offensive Security Advisor, you help identify, analyze, eradicate and mitigate threats to Desjardins Group's external systems. You plan for threats based on the continuous development of offensive techniques and threat actors. You design, develop and implement offensive methods and tools, while mitigating the risks associated with their use. You follow rigorous processes and develop new ones to protect the organization from cyberattacks. You'll have access to a diverse range of cutting-edge offensive tools and the opportunity to continuously test to identify, analyze and exploit vulnerabilities. More specifically, you will be required to:
- Discover and map out exposed assets and services: configure and develop discovery tools to maintain a complete and up-to-date inventory.
- Identify and analyze major issues. Create diagnostics and make recommendations based on different constraints. Analyze, map and explain threats to guide test activities.
- Analyze, map and explain REALISTIC threats identified on the external perimeter.
- Identify exploitable vulnerabilities: Combine manual and automated approaches to identify vulnerabilities.
- Continuously monitor the external perimeter: Perform non-regression tests to prevent the vulnerabilities from returning.
- Work with experts to strengthen the overall security posture.
- Facilitate technical workshops to generate detailed analyses and feed risk assessments.
- Conduct research and develop innovative methodologies to improve asset recognition and vulnerability exploitation.
- Independently manage assigned files: organizing meetings, managing schedules and priorities, and gathering the required information.
What we offer*
- Competitive salary and annual bonus
- 4 weeks of flexible vacation starting in the first year
- Defined benefit pension plan that provides predictable, stable income throughout retirement
- Group insurance including telemedicine
- Reimbursement of health and wellness expenses and telework equipment
- Benefits apply based on eligibility criteria.
Curious about Desjardins ? Click here
LI-HybridWhat you bring to the table
- Bachelor's degree in IT or a related field
- A minimum of six years of relevant information security experience, including 3 years of penetration testing (Pentest or Red Team)
- Please note that other combinations of qualifications and relevant experience may be considered
- Experience using threat modeling methodologies such as STRIDE and OWASP or comparable experience visually representing data and process flows in a corporate environment
- Experience in vulnerability detection through bug bounty initiatives
- Experience making recommendations and putting people into action
- Experience analyzing source codes and identifying vulnerabilities
- Advanced proficiency in French, both spoken and written
- Proficiency in application security and infrastructure operations
- Knowledge of defence mechanisms and business controls
- Familiarity with the MITRE ATT&CK framework
Action oriented, Customer Focus, Differences, Interpersonal Savvy, Nimble learning, Strategic mindset
Trade Union (If applicable)
At Desjardins, we believe in equity, diversity and inclusion. We're committed to welcoming, respecting and valuing people for who they are as individuals, learning from their differences, embracing their uniqueness, and providing a positive workplace for all. At Desjardins, we have zero tolerance for discrimination of any kind. We believe our teams should reflect the diversity of the members, clients and communities we serve.
If there's something we can do to help make the recruitment process or the job you're applying for more accessible, let us know. We can provide accommodations at any stage in the recruitment process. Just ask
Job Family
Security (FG)
Unposting Date
-
Offensive Security Advisor
5 days ago
Montréal, QC HB N, Canada Desjardins Full timeDo technical challenges keep you awake at night? Do you want to constantly learn, analyze, understand things and leverage your experience, knowledge and expertise? Our Red Team needs an operator to perform adversary simulation and threat monitoring activities at Desjardins. In this role, you work with high caliber cyber-defence and insider-threat teams...
-
Offensive Security Advisor
2 days ago
Montréal, Canada Desjardins Full timeAt Desjardins, we believe in equity, diversity and inclusion. We're committed to welcoming, respecting and valuing people for who they are as individuals, learning from their differences, embracing their uniqueness, and providing a positive workplace for all. At Desjardins, we have zero tolerance for discrimination of any kind. We believe our teams should...
-
Senior offensive and defensive security advisor
16 minutes ago
Montréal, QC, Canada Desjardins Full timeAs a senior defensive security advisor, you help identify, analyze, eradicate and mitigate threats to Desjardins's systems, networks and applications. You analyze security incidents and determine their scope, impact and origin. You collect data from a variety of defence tools. You perform ongoing monitoring and interpret, analyze and report all events and...
-
Senior security advisor
1 week ago
Montréal, QC HB N, Canada Desjardins Full timeAs a senior security advisor, you help develop and optimize security measures to align with corporate objectives by planning, implementing and overseeing best practices to strengthen Desjardins's security posture. You help develop the Desjardins Group Security Office's priorities and governance, and work on different aspects of our security practices. You're...
-
Senior security advisor
10 minutes ago
Montréal, QC, Canada Desjardins Group Full timeAs a senior security advisor, you help develop and optimize security measures to align with corporate objectives by planning, implementing and overseeing best practices to strengthen Desjardins's security posture. You help develop the Desjardins Group Security Office's priorities and governance, and work on different aspects of our security practices. You're...
-
Security Advisor
1 week ago
Montréal, QC HB N, Canada Desjardins Full timeAs a security advisor, you help develop and optimize security measures to align with corporate objectives by planning, implementing and overseeing best practices to strengthen Desjardins's security posture. You help develop the Desjardins Group Security Office's priorities and governance, and work on different aspects of our security practices. You're...
-
Senior Advisor, Data governance
5 days ago
Montréal, QC HB N, Canada Desjardins Full timeAs a data governance senior advisor, you help define and implement data management processes, allowing optimal and secure use of data for the benefit of members and clients, with compliance rules, privacy, privacy policies and security in mind. You assist teams by helping them recognize and manage data as a strategic asset. You lead and influence...
-
Senior Data Quality Advisor
2 weeks ago
Montréal, QC HB N, Canada Desjardins Full timeThe Data Office is aiming to accelerate data quality improvement efforts to help Desjardins Group further ground its business practices in data and analytics. The Data Quality Practice Department is looking for talented people to guide Desjardins as it grows in this area. As a senior data quality advisor, you help define and implement data quality management...
-
Security Data Governance Advisor
2 weeks ago
Montréal, QC HB N, Canada Desjardins Full timeTemporary position for 12 monthsThe Cybersecurity Monitoring Ecosystem Department is looking for a security data governance advisor to join its team of experts in handling large volumes of sensitive and confidential data essential to cybersecurity activities. This role is key to ensuring rigorous data governance and respect for lifecycles in a multi-petabyte...
-
Senior Advisor, Operational risks
2 weeks ago
Montréal, QC HB N, Canada Desjardins Full timeTemporary position for 12 monthsAs a senior operational risk advisor, you help prevent, analyze and develop guidelines for suspicious and fraudulent transactions. You also assist with compliance, internal controls, crisis management and the security of personal information and property. You lead development projects and strategic initiatives that are complex...