Job Description
Client: Government of Nova Scotia – Service Nova Scotia (GeoNOVA)
Project: Infrastructure Registry for Municipal Assets (IRMA) Application Penetration Testing
Location: Halifax, Nova Scotia
Work Arrangement: Remote; office space in Halifax or Amherst may be available if required and mutually agreed upon
Contract: November 2, 2026 – November 27, 2026
Duration: 20 business days
Openings: 1
Engagement Type: Competitive-Sourced
Payment Structure: Milestone
Project Overview
The Government of Nova Scotia is seeking an Intermediate Penetration Testing Specialist to conduct security testing of the Infrastructure Registry for Municipal Assets (IRMA), a provincially supported, web-based GIS application hosted within the Nova Scotia Geospatial Infrastructure (NSGI).
The successful resource will perform penetration testing using Grey Box and Black Box methodologies, identify and analyze vulnerabilities, validate security controls, document findings, provide remediation recommendations, and re-test identified vulnerabilities following remediation.
Key Responsibilities
- Conduct penetration testing of the IRMA web application using the required testing methodologies.
- Perform Grey Box and Black Box penetration testing based on the approved scope and testing plan.
- Assess the security of the web application and applicable APIs within the defined scope.
- Identify, analyze, evaluate, and document security vulnerabilities using industry best practices.
- Review and analyze relevant penetration testing results and security scan results from the IRMA application and related systems.
- Assess vulnerabilities, severity, affected systems, potential business/technical impacts, and recommended remediation actions.
- Immediately report Critical vulnerabilities, as identified using the Common Vulnerability Scoring System (CVSS), to the Cyber and Risk team and Service Nova Scotia (GeoNOVA).
- Participate in project kickoff, progress/status meetings, and security risk assessment activities as required.
- Work collaboratively with IT, cybersecurity, application owners, and business stakeholders.
- Identify appropriate business owners and risk treatment owners for penetration testing recommendations.
- Provide weekly status updates throughout the engagement.
- Prepare a comprehensive Final Penetration Testing Report.
- Prepare and deliver an Executive Presentation summarizing key findings, vulnerabilities, impacts, and recommended mitigations.
- Re-test and verify remediation of findings identified during the penetration testing engagement.
- Ensure all testing tools and toolkits are used in accordance with Government of Nova Scotia requirements.
- Obtain prior written approval before installing any testing toolkit on the Government of Nova Scotia network.
- Thoroughly remove all testing-related files, binaries, scripts, backdoors, malware, and other related items following testing.
Requirements
Mandatory Qualifications & Experience
Candidates must meet the following requirements:
1. Penetration Testing Experience
- Minimum 3 years of professional experience in penetration testing.
- Demonstrated experience conducting penetration testing on digital systems.
- Experience with application security testing and vulnerability identification.
2. Tier 1 Certification – Mandatory at Team Level
At least one proposed resource must hold a recognized Tier 1 certification:
- Offensive Security Certified Penetration Tester (OSCP), OR
- CREST Registered Penetration Tester (CRT).
3. Tier 2 Certification – Mandatory at Team Level
At least one proposed resource must hold a recognized Tier 2 certification:
- Certified Ethical Hacker Master (CEH-Master), OR
- GIAC Penetration Tester (GPEN), OR
- CompTIA PenTest+.
4. Public Sector Penetration Testing Experience
- Proven experience conducting penetration testing for the Canadian public sector, including federal, provincial, territorial, and/or municipal government organizations.
5. Government of Nova Scotia Experience
- Experience conducting penetration testing for the Government of Nova Scotia is required as part of the stated experience requirements.
6. Recent Penetration Testing Experience
- At least one proposed resource must have conducted two (2) or more penetration tests within the last 12 months.
7. Cross-Functional Collaboration
- Demonstrated ability to work effectively with IT, cybersecurity, application teams, and business stakeholders.
8. Criminal Record Check
- A clear criminal record check processed within the last six (6) months must be provided for each proposed resource.
Required Technical Testing Scope
Experience should align with the SOW's defined penetration-testing scope, including:
- Web Application Penetration Testing
- API Security / API Penetration Testing
- Grey Box Testing
- Black Box Testing
- Vulnerability identification and analysis
- Security assessment and risk analysis
- CVSS-based vulnerability severity assessment
- Penetration testing reporting
- Remediation validation and re-testing
Testing Methodologies
Grey Box Testing
Testing with partial knowledge of the target environment, such as credentials or system documentation, simulating an attacker with some level of access.
Black Box Testing
Testing with no prior knowledge of the target environment, simulating an external attacker using reconnaissance and trial-and-error techniques.
Key Deliverables
The successful resource will contribute to:
- Final Penetration Testing Report
- Scope and objectives
- Testing methodologies and tools
- Detailed vulnerabilities and findings
- Severity ratings
- Affected systems
- Potential impacts
- Recommended treatment/remediation plans
- Remediation timelines
- Executive Presentation
- Major findings
- Vulnerabilities
- Potential impacts
- Recommended mitigations
- Business-level summary for non-technical stakeholders
- Remediation Validation
- Re-test identified vulnerabilities
- Verify remediation effectiveness
- Document validation results
Proposal / Submission Requirements
For each proposed resource, suppliers should be prepared to provide:
- Resume/CV
- Years and types of penetration testing experience
- Relevant penetration testing project examples from the past five years
- Tier 1 certification details, where applicable
- Tier 2 certification details, where applicable
- Public-sector penetration testing experience in Canada
- Government of Nova Scotia experience
- Evidence of at least two penetration tests completed within the past 12 months for at least one proposed resource
- Clear criminal record check completed within the last six months
Requirements
Mandatory Qualifications & Experience Candidates must meet the following requirements: 1. Penetration Testing Experience Minimum 3 years of professional experience in penetration testing. Demonstrated experience conducting penetration testing on digital systems. Experience with application security testing and vulnerability identification. 2. Tier 1 Certification – Mandatory at Team Level At least one proposed resource must hold a recognized Tier 1 certification: Offensive Security Certified Penetration Tester (OSCP), OR CREST Registered Penetration Tester (CRT). 3. Tier 2 Certification – Mandatory at Team Level At least one proposed resource must hold a recognized Tier 2 certification: Certified Ethical Hacker Master (CEH-Master), OR GIAC Penetration Tester (GPEN), OR CompTIA PenTest+. 4. Public Sector Penetration Testing Experience Proven experience conducting penetration testing for the Canadian public sector, including federal, provincial, territorial, and/or municipal government organizations. 5. Government of Nova Scotia Experience Experience conducting penetration testing for the Government of Nova Scotia is required as part of the stated experience requirements. 6. Recent Penetration Testing Experience At least one proposed resource must have conducted two (2) or more penetration tests within the last 12 months. 7. Cross-Functional Collaboration Demonstrated ability to work effectively with IT, cybersecurity, application teams, and business stakeholders. 8. Criminal Record Check A clear criminal record check processed within the last six (6) months must be provided for each proposed resource. Required Technical Testing Scope Experience should align with the SOW's defined penetration-testing scope, including: Web Application Penetration Testing API Security / API Penetration Testing Grey Box Testing Black Box Testing Vulnerability identification and analysis Security assessment and risk analysis CVSS-based vulnerability severity assessment Penetration testing reporting Remediation validation and re-testing Testing Methodologies Grey Box Testing Testing with partial knowledge of the target environment, such as credentials or system documentation, simulating an attacker with some level of access. Black Box Testing Testing with no prior knowledge of the target environment, simulating an external attacker using reconnaissance and trial-and-error techniques. Key Deliverables The successful resource will contribute to: Final Penetration Testing Report Scope and objectives Testing methodologies and tools Detailed vulnerabilities and findings Severity ratings Affected systems Potential impacts Recommended treatment/remediation plans Remediation timelines Executive Presentation Major findings Vulnerabilities Potential impacts Recommended mitigations Business-level summary for non-technical stakeholders Remediation Validation Re-test identified vulnerabilities Verify remediation effectiveness Document validation results Proposal / Submission Requirements For each proposed resource, suppliers should be prepared to provide: Resume/CV Years and types of penetration testing experience Relevant penetration testing project examples from the past five years Tier 1 certification details, where applicable Tier 2 certification details, where applicable Public-sector penetration testing experience in Canada Government of Nova Scotia experience Evidence of at least two penetration tests completed within the past 12 months for at least one proposed resource Clear criminal record check completed within the last six months