Senior Security Engineer (Pen Tester, Cybersecurity)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Senior Security Engineer (Pen Tester) (Cybersecurity): Conducting penetration testing of product features and cloud architecture in multi-cloud environments (AWS & GCP) with an accent on offensive security, infrastructure reviews, and vulnerability triaging. Focus on collaborative pentests, AI-augmented assessments, control plane audits, and rapid reporting to maintain release velocity.
Salary: 120,000–210,000 CAD
Company
enables secure connections for enterprises including Fortune 500 companies, global banks, and the Department of Defense.
What you will do
- Collaborate on deep-dive penetration tests across AWS & GCP multi-cloud environments.
- Review control plane configurations including IAM policies and cloud-native permissions.
- Perform dynamic testing on data plane, web UI, and API endpoints.
- Assess security posture of hybrid infrastructure with containers and VMs.
- Triage vulnerabilities, create PoCs, and advise product teams on risks.
- Leverage AI/LLMs for reconnaissance, attack vector generation, and report drafting.
- Monitor bug bounty programs and manage external researcher communications.
Requirements
- Deep architectural knowledge of AWS and GCP, including IAM reviews and CSPM tools.
- Experience auditing managed/unmanaged container services (GKE, EKS, ECS, Kubernetes).
- Proficiency integrating AI/LLM tools like Gemini or Claude into pentesting.
- Expert web app security: OWASP Top 10, Burp Suite/ZAP, auth patterns (OAuth, JWT).
- Scripting in Python, Go, or Bash for automation; Terraform for IaC audits.
- Strong technical reporting for product teams.
Culture & Benefits
- Collaborative, inclusive culture with core values: Stay Aligned, Get It Done, Customer Empathy, Think Creatively, Help Each Other Out.
- Competitive total compensation including base salary, stock grants based on performance.
- Open communication, support for new ideas, opportunities for initiative and growth.
- Well-funded with top investors like Vista Equity Partners and General Catalyst.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →