Senior Offensive Security Advisor

1 week ago


Montréal QC HB N, Canada Desjardins Full time

As a Senior Offensive Security Advisor, you help identify, analyze, eradicate and mitigate threats to Desjardins Group's external systems. You plan for threats based on the continuous development of offensive techniques and threat actors. You design, develop and implement offensive methods and tools, while mitigating the risks associated with their use. You follow rigorous processes and develop new ones to protect the organization from cyberattacks. You'll have access to a diverse range of cutting-edge offensive tools and the opportunity to continuously test to identify, analyze and exploit vulnerabilities. More specifically, you will be required to:

  • Discover and map out exposed assets and services: configure and develop discovery tools to maintain a complete and up-to-date inventory.
  • Identify and analyze major issues. Create diagnostics and make recommendations based on different constraints. Analyze, map and explain threats to guide test activities.
  • Analyze, map and explain REALISTIC threats identified on the external perimeter.
  • Identify exploitable vulnerabilities: Combine manual and automated approaches to identify vulnerabilities.
  • Continuously monitor the external perimeter: Perform non-regression tests to prevent the vulnerabilities from returning.
  • Work with experts to strengthen the overall security posture.
  • Facilitate technical workshops to generate detailed analyses and feed risk assessments.
  • Conduct research and develop innovative methodologies to improve asset recognition and vulnerability exploitation.
  • Independently manage assigned files: organizing meetings, managing schedules and priorities, and gathering the required information.

What we offer*

  • Competitive salary and annual bonus
  • 4 weeks of flexible vacation starting in the first year
  • Defined benefit pension plan that provides predictable, stable income throughout retirement
  • Group insurance including telemedicine
  • Reimbursement of health and wellness expenses and telework equipment
  • Benefits apply based on eligibility criteria.

Curious about Desjardins ? Click here

LI-Hybrid

What you bring to the table

  • Bachelor's degree in IT or a related field
  • A minimum of six years of relevant information security experience, including 3 years of penetration testing (Pentest or Red Team)
  • Please note that other combinations of qualifications and relevant experience may be considered
  • Experience using threat modeling methodologies such as STRIDE and OWASP or comparable experience visually representing data and process flows in a corporate environment
  • Experience in vulnerability detection through bug bounty initiatives
  • Experience making recommendations and putting people into action
  • Experience analyzing source codes and identifying vulnerabilities
  • Advanced proficiency in French, both spoken and written
  • Proficiency in application security and infrastructure operations
  • Knowledge of defence mechanisms and business controls
  • Familiarity with the MITRE ATT&CK framework

Action oriented, Customer Focus, Differences, Interpersonal Savvy, Nimble learning, Strategic mindset

Trade Union (If applicable)

At Desjardins, we believe in equity, diversity and inclusion. We're committed to welcoming, respecting and valuing people for who they are as individuals, learning from their differences, embracing their uniqueness, and providing a positive workplace for all. At Desjardins, we have zero tolerance for discrimination of any kind. We believe our teams should reflect the diversity of the members, clients and communities we serve.

If there's something we can do to help make the recruitment process or the job you're applying for more accessible, let us know. We can provide accommodations at any stage in the recruitment process. Just ask

Job Family

Security (FG)

Unposting Date



  • Montréal, QC, Canada Desjardins Full time

    As a senior defensive security advisor, you help identify, analyze, eradicate and mitigate threats to Desjardins's systems, networks and applications. You analyze security incidents and determine their scope, impact and origin. You collect data from a variety of defence tools. You perform ongoing monitoring and interpret, analyze and report all events and...


  • Montréal, QC, Canada Desjardins Group Full time

    As a senior defensive security advisor, you help identify, analyze, eradicate and mitigate threats to Desjardins's systems, networks and applications. You analyze security incidents and determine their scope, impact and origin. You collect data from a variety of defence tools. You perform ongoing monitoring and interpret, analyze and report all events and...


  • Montréal, QC HB N, Canada Desjardins Full time

    As a senior IT security advisor, you help protect IT hardware, software and data against modification, destruction, and accidental or unauthorized disclosure. You also assist in authentication and access control by designing, administering and controlling proven security systems. You analyze IT system vulnerabilities and implement protective measures to back...

  • Pentester Expert

    7 days ago


    Montréal, QC HB N, Canada Desjardins Full time

    As a senior offensive security advisor, you help identify, analyze, eradicate and mitigate threats to Desjardins's systems, networks and applications. You arre brought to simulater threats based on the evolution of offensive techniques and threat actors. You design, develop and implement offensive methodologies and tools, while mitigating the risks...


  • Montréal, QC, Canada Desjardins Group Full time

    As a senior security advisor, you help develop and optimize security measures to align with corporate objectives by planning, implementing and overseeing best practices to strengthen Desjardins's security posture. You help develop the Desjardins Group Security Office's priorities and governance, and work on different aspects of our security practices. You're...


  • Montréal, QC, Canada Desjardins Group Full time

    As a senior security advisor, you help develop and optimize security measures to align with corporate objectives by planning, implementing and overseeing best practices to strengthen Desjardins's security posture. You help develop the Desjardins Group Security Office's priorities and governance, and work on different aspects of our security practices. You're...


  • Montréal, QC HB N, Canada Desjardins Full time

    As a Senior Advisor IT Architecture, you design IT solutions to meet the business needs of large-scale projects or programs using Desjardins Group's architecture targets and shared platforms. You ensure consistency with the organization's structure, as well as current and future needs, and ensure that new elements are compatible with existing architecture....

  • Security Advisor

    1 week ago


    Montréal, QC HB N, Canada Desjardins Full time

    As a security advisor, you help develop and optimize security measures to align with corporate objectives by planning, implementing and overseeing best practices to strengthen Desjardins's security posture. You help develop the Desjardins Group Security Office's priorities and governance, and work on different aspects of our security practices. You're...


  • Montréal, QC HB N, Canada Desjardins Full time

    As a data governance senior advisor, you help define and implement data management processes, allowing optimal and secure use of data for the benefit of members and clients, with compliance rules, privacy, privacy policies and security in mind. You assist teams by helping them recognize and manage data as a strategic asset. You lead and influence...


  • Montréal, QC HB N, Canada Desjardins Full time

    As a data governance senior advisor, you help define and implement data management processes, allowing optimal and secure use of data for the benefit of members and clients, with compliance rules, privacy, privacy policies and security in mind. You assist teams by helping them recognize and manage data as a strategic asset. You lead stakeholders in...