Remote Penetration Tester
4 days ago
New Glasgow, Nova Scotia, Canada
Malleum
Full-time
Free with email or Google
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
Free with email or Google
Location: Hybrid / On-site at client locations as required
Department: Offensive Security & Adversary Simulation
About Malleum
Malleum is at the forefront of next-generation cyber defense, partnering with marquee clients across space, aerospace, defense, government, financial services, and critical infrastructure. We're experiencing exceptional growth as demand accelerates for trusted advisors capable of delivering at the intersection of national security, allied intelligence cooperation, and enterprise resilience. Our offensive security consultants test the systems behind cutting-edge defensive technologies, sovereign space capabilities, and allied programs - finding the gaps before adversaries do, on networks that protect missions of genuine national consequence.If you take pride in breaking things ethically - and helping the most consequential organizations build back stronger - Malleum is where your craft meets purpose.
The Opportunity
We're seeking a Penetration Tester to deliver hands-on offensive security engagements across client networks, applications, cloud environments, and operational technology. You'll work directly within client environments - including sovereign, regulated, and cleared settings - emulating real-world adversaries, documenting findings, and partnering with clients to drive meaningful remediation.
This is a hands-on consulting role for a practitioner who blends deep technical tradecraft with strong client presence and the discipline to deliver findings clearly, safely, and on schedule.
What You'll Do
- Plan, scope, and execute penetration tests across external, internal, web application, API, mobile, cloud (Azure / AWS / GCP), wireless, and Active Directory targets
- Conduct red team and adversary emulation engagements aligned to MITRE ATT&CK, executing realistic TTPs against client environments
- Perform assumed-breach assessments, internal pivoting, privilege escalation, and lateral movement exercises
- Support purple team exercises in partnership with client SOC and Malleum's IR practice to improve detection and response
- Execute social engineering campaigns (phishing, vishing, physical) where contracted, with rigorous rules of engagement
- Conduct cloud configuration reviews against CIS Benchmarks, CSA CCM, and provider-specific baselines
- Support OT / ICS / SCADA security testing for defense and critical-infrastructure clients (with appropriate safety controls)
- Develop custom tooling, scripts, and payloads (PowerShell, Python, C#, Go) to evade modern EDR and ZTNA controls during sanctioned engagements
- Produce high-quality client deliverables: executive summaries, technical findings, reproduction steps, evidence, CVSS-scored risk ratings, and pragmatic remediation guidance
- Deliver findings briefings to client stakeholders — from engineers to executive leadership and boards - with clarity and professionalism
- Contribute to scopin