Senior Security Engineer – Pentester

🕒 August 4

🇨🇦 Canada – Remote

💵 $158k - $237k / year

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

👻 Ghost score 0%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Menlo Security Inc.

Menlo Security Inc.

201 - 500 employees

🔒 Cybersecurity

🏢 Enterprise

💰 $100M Series E on 2020-11

Cybersecurity • Enterprise

Menlo Security Inc. is a cybersecurity company focused on providing advanced internet security solutions for enterprises. They specialize in securing browsers across hybrid enterprise environments to prevent phishing and malware attacks. Menlo Security offers a cloud-based browser security solution that transforms any browser into a secure enterprise browser, helping organizations protect against highly evasive adaptive threats, zero-hour phishing, and ransomware. Their zero-trust access architecture enables safe internet use and secure application access, supporting over 800 customers globally, including financial institutions and government agencies.

📋 Description

• Conduct deep-dive penetration tests of products across AWS and GCP environments, working with a peer pentester • Review IAM policies, service configurations, and cloud-native permission structures across the Control Plane against security baselines • Execute dynamic testing against web interfaces and API endpoints across the Data Plane and Web UI • Assess the security posture of hybrid infrastructure spanning containers and virtual machines • Triage findings and create clear, reproducible proofs of concept • Partner with product teams to explain risk and drive remediation • Use AI and large language models to automate reconnaissance, generate attack vectors, analyze configurations, and draft vulnerability reports • Monitor bug bounty pipelines and external reports, validate findings, and manage researcher communication • Ensure product features and multi-cloud infrastructure are rigorously security-tested before release • Track assessment coverage, triage speed, vulnerability escape rates, AI-assisted time savings, and report quality

🎯 Requirements

• Deep architectural understanding of GCP and AWS • Ability to perform manual reviews of complex IAM and resource hierarchies • Experience with native cloud APIs or CSPM frameworks • Proven experience auditing and hardening GKE Autopilot/Standard, EKS, ECS, Kubernetes, k3s, and OCI-runc workloads • Demonstrated ability to integrate AI/LLM tools such as Gemini and Claude into the pentesting lifecycle • Expert knowledge of web application security and offensive testing methodologies • Deep proficiency in OWASP Top 10 vulnerabilities, modern web framework exploitation, and REST/WebSocket API security • Extensive hands-on experience with Burp Suite Professional, OWASP ZAP, or similar tools • Understanding of CSP, CORS, SameSite cookies, Subresource Integrity, OAuth 2.0, OIDC, JWT, HSTS, X-Frame-Options, and Permissions-Policy • Ability to identify complex flaws beyond automated scanners and validate them with proofs of concept • Proficiency in Python, Go, or Bash • Solid grasp of Terraform, cloud-native deployment patterns, and HCL auditing • Ability to write high-quality technical reports for product teams • Experience with Gatekeeper policies and Binary Authorization is preferred

🏖️ Benefits

• Base salary range of 158,000 CAD - 237,000 CAD • Eligibility for stock-based compensation grants based on company and individual performance • Collaborative, inclusive, and fun culture • Opportunities to take initiative and implement new ideas • Open communication and support for new ideas

Apply Now

Similar Jobs

🕒 August 3

NMI

201 - 500

💼 Consulting

📦 Logistics

📣 Marketing

Senior Staff Information Security Engineer helping shape security across AWS and on-premises infrastructure. Leading initiatives as a trusted technical authority for complex security architecture and engineering decisions.

🕒 July 28

Akamai Technologies

5001 - 10000

🔒 Cybersecurity

Acting as the security contact ensuring integration and support for Akamai customers. Leading technical services and fostering customer engagement and success teams.

🇨🇦 Canada – Remote

💵 $109.9k - $197.7k / year

💰 Post-IPO Equity on 2001-07

⏰ Full Time

🟠 Senior

👮‍♂️ Cybersecurity / Security Engineer

🕒 July 27

TEHORA inc.

11 - 50

Conseiller en sécurité informatique – Senior pour contribuer à la protection des actifs informationnels chez TEHORA. Participer à l’amélioration de la posture de sécurité et à la mise en œuvre de pratiques de cybersécurité.

🗣️🇫🇷 French Required

🕒 July 27

TEHORA inc.

11 - 50

Spécialiste en gestion des vulnérabilités et sécurité à distance chez TEHORA. Analyser et prioriser les vulnérabilités en cybersécurité pour assurer la sécurité des infrastructures technologiques.

🗣️🇫🇷 French Required

🕒 July 24

Black Duck

5001 - 10000

🔒 Cybersecurity

☁️ SaaS

📋 Compliance

Lead Incident Security Responder for Black Duck, driving applied product security across the portfolio. Partnering with engineering teams to ensure product security and compliance.