Security Penetration Tester     

Who We Are…
We are Bulletproof Solutions and like our name suggests, IT security is in the fabric of who we are.   We know the risks are simply too great to ignore and we use our expertise to equip our clients with solutions that help protect their businesses.

Why You Should Work With Us…
This is your opportunity to join a growing, fast-paced, successful business which values our employees above all else. Our employees are at the heart of everything that we do and that is why they are our biggest investment. We offer top notch health insurance, 401k/RRSP and career advancement/enhancement opportunities to all employees.

What the Role Does…
This position conducts security assessments by probing for and exploiting security vulnerabilities in web-based applications, networks and systems and finding ways to ensure that any risk to our client is mitigated.


Position Summary

This position conducts security assessments by probing for and exploiting security vulnerabilities in web-based applications, networks and systems and finding ways to ensure that any risk to our client is mitigated.


Responsibilities

  • Conducts security assessments that can be multi-faceted for a wide variety of assigned clients
  • Defines the scope for security testing assignments
  • Creates quality assurance security test reports and other documentation as needed
  • Works with clients to develop appropriate remediation plans
  • Provides clients with exceptional service in a professional, courteous and timely manner
  • Provides technical support as a subject matter expert in the sale of security testing assignments on an as needed basis
  • Provides thought leadership and direction for the Information Security practice on malware, attack vectors and methods to protect against threats
  • Teams up with colleagues in other lines of services in support of client needs for Information Security services
  • Stays up-to-date on current tools, technologies and vulnerabilities to incorporate into testing practices
  • Other related duties as assigned

Required Education/Credentials:

  • Degree in Computer Science, Information Systems, Engineering or related major from an accredited University or equivalent
  • At least two (2) years working on vulnerability assessment and/or penetration test
  • Application and/or infrastructure penetration testing experience above and beyond running automated tools
  • A good understanding of Linux, Windows and network security skills
  • Excellent written and oral communication skills in English
  • Ability to meet deadlines and deliver a high-quality product (reports)
  • Strong attention to detail
  • Ability to work both independently and perform as a leader in a team environment
  • Familiar with (if not qualified in) test suites such as:
    • Nessus
    • MetaSploit
    • Burp Suite
    • Kali
    • NMap
    • Fortify
    • Acunetix

Qualifications:

  • EC-Council Certified Ethical Hacker (CEH)
  • EC-Council Licensed Penetration Tester (LPT)
  • GIAC Certified Penetration Tester (CPEN)
  • IACRB Certified Penetration Tester (CPT)
  • Offensive Security Certified Professional (OSCP)
  • CREST Registered Tester (CRT)
  • CREST Infrastructure Certification
  • CESG CHECK Team Leader
  • CESG CHECK Team Member
  • Tiger Scheme Senior Security Tester
  • Tiger Scheme Qualified Security Tester
  • Any other recognized penetration testing certification/accreditation

The following skills are preferred but not required:

  • ISO27001 Lead Auditor
  • CISSP, CISA, CISM Certifications
  • PCI ASV
  • CREST recognized penetration testing certification/accreditation (CREST Certified Tester (CCT) or CHECK Team Leader (CTL)
  • Experience developing custom scripts or tools used for vulnerability scanning and identification
  • Familiarity with threat modelling and security design review methodologies
  • Support team technical development (e.g. through service development or research) and contribute to company technical processes overall
  • Development and/or source code review experience in C/C++, C#, VB.NET, ASP, PHP, or Java and/or Fortify, Veracode, Brakeman and/or IDA Pro
  • Experience with physical security testing, phishing and social engineering techniques.
  • Experience with mobile applications such as Android DeBug Bridge (ADS), OWASP ZAP, Drozer, Mobile Security Framework (MobSF), Smartphone Pentest Framework (SPF), Burp Suite, Android SDK, Friday, Cydia and/or IDB

Travel Expectations:

  • Must be able to travel 70% or more.
  • Must hold a valid Canadian passport and be eligible to apply for a US Work Visa

 Sound like a fit for you? 

Apply Now