Talent.com
Senior Penetration Tester, Application Security
Senior Penetration Tester, Application SecurityQueer Tech • Toronto, Canada
Senior Penetration Tester, Application Security

Senior Penetration Tester, Application Security

Queer Tech • Toronto, Canada
Il y a 16 jours
Type de contrat
  • Temps plein
Description de poste

Build something people love

Wealthsimple is on a mission to help everyone achieve financial freedom by reimagining what it means to manage your money. Using smart technology, we take financial services that are often confusing and expensive and make them transparent and low-cost for everyone. We’re the largest fintech company in Canada, with 3+ million users who trust us with more than $100 billion in assets. And we’re just getting started.

We’re looking for someone who thinks big, sweats the small stuff and keeps things simple. You’ll join a high-bar, fast-paced team where people are trusted to own their work, communicate openly, and ship things that improve our clients’ lives. Collaboration, humility, and an obsession over quality are how we get stuff done.

About the Role

As a Senior Penetration Tester you will plan engagements, find security vulnerabilities, and help us fix them. Your role also involves establishing rapport with leadership, as well as internal, consultant, and third-party teams to communicate and support the improvement of our company’s cybersecurity posture and resiliency. You will report to the Senior Manager, Application Security and have a mandate to plan and execute secure code reviews, penetration tests, and other offensive security activities to improve Wealthsimple’s security.

This role requires a unique blend of offensive security expertise and collaborative problem-solving. You won't just be finding vulnerabilities and handing off reports - you'll be working shoulder-to-shoulder with engineering teams to understand root causes, suggest practical remediations, and sometimes implement fixes yourself. If you see your job ending when the report is submitted, this role isn't for you. We're looking for someone who sees vulnerability discovery as the beginning of the conversation, not the end.

Responsibilities

Perform security assessments : discover flaws in our systems by conducting detailed penetration tests, code reviews, or threat models on our internal systems, web applications, and other software.

Analyze vulnerabilities : determine the real-world severity of discovered issues and suggest actionable recommendations to address security threats, improve application security, and strengthen our cloud environments.

Write findings : create comprehensive write-ups of the findings, risk analysis, recommendations, and actionable insights for our engineers and other stakeholders.

Help fix problems : work closely with our application security, vulnerability management, infrastructure and platform engineers to implement solutions, enhance our security posture, and develop guardrails, regression tests, and out-of-the-box solutions to prevent future vulnerabilities or design flaws.

What You Bring

Courageously Ambitious - enthusiastically tackle big audacious goals.

Deeply Human - take responsibility for bringing the best out of themselves and others.

Problem Solvers - have the ability and resilience to tackle complex issues and see them through.

Skills and Experience

Experience (5+ years preferred) in a mix of network, application, and native mobile penetration testing with a proven history of working cross-functionally with high-functioning teams.

Experience performing boundary testing for PCI-DSS card holder environments or equivalent.

Experience performing mobile testing for Android / iOS applications.

Technical understanding of networks, endpoint, identity, cloud, encryption, data protection and application deployment stacks.

Knowledge of standard penetration testing methodologies, including NIST SP 800-115.

Familiarity with Ruby, React, and GraphQL testing is preferred.

Development and / or scripting competence is preferred.

AWS testing experience is preferred.

Previous industry experience in Financial Services is preferred.

Experience using automation and AI to supplement and scale manual testing is preferred.

Education and Certifications

Offensive Security Certified Professional (OSCP) / Experienced Penetration Tester (OSEP)

CREST Registered Tester

AWS Certified Security - Specialty

Bachelor’s or higher degree in cybersecurity, software engineering, or a related field

Compensation & Equity

Base salary range : For this role, candidates located in Canada can expect a base salary range of CAD $151,200 - $189,000. Actual compensation is determined based on skills, experience, and role level. Exceptional candidates may be considered above the top of the range, and pay can increase quickly for those who make a big impact in the role.

Total compensation : In addition to base salary, this role includes equity compensation. We use clear job levels and market-based salary bands to ensure compensation is fair and consistent across the company.

Why Wealthsimple?

Top-tier health benefits and life insurance

Long-term group savings with employer match using our Wealthsimple for Business platform

20 vacation days + 4 wellness days per year, and unlimited sick and mental health days

✈️ 90 days away program : Employees can work outside of Canada for up to 90 days per calendar year

A wide variety of peer and company-led Employee Resources Groups (e.g., Rainbow, Women of Wealthsimple, Black @ WS)

We’re a remote first team with over 1,500 employees across North America - and one of the best things about working here is the people. You’ll be collaborating with incredibly talented, curious, and driven teammates who care deeply about doing great work.

Be a part of our Canadian success story and help shape the financial future of millions.

Technology & Innovation at Wealthsimple

We believe the future belongs to those who innovate boldly. At Wealthsimple, every team member is expected to lean into new technologies, including AI, and tooling to rethink how we work, solve problems faster, and create even greater value. We're looking for people who are not just comfortable with change but energized by it. Our commitment is to build a company that evolves at the pace of the world around us, and we want you to help lead that future.

DEI Statement

At Wealthsimple, we are building products for a diverse world and we need a diverse team to do that successfully. We strongly encourage applications from everyone regardless of race, religion, colour, national origin, gender, sexual orientation, age, marital status, or disability status.

Accessibility Statement

Wealthsimple provides an accessible candidate experience. If you need any accommodations or adjustments throughout the interview process and beyond, please let us know, and we will work with you to provide the necessary support and make reasonable accommodations to facilitate your participation. We are continuously working to improve our accessibility practices and welcome any feedback or suggestions on how we can better accommodate candidates with accessibility needs.

#J-18808-Ljbffr

Créer une alerte emploi pour cette recherche

Senior Penetration Tester Application Security • Toronto, Canada

Offres similaires
RQ08437 - Security Specialist - Penetration Testing - Senior

RQ08437 - Security Specialist - Penetration Testing - Senior

Rubicon Path • Toronto
Temps plein
RQ08437 - Security Specialist - Penetration Testing - Senior.Conducts penetration tests, web application vulnerability assessments, code reviews and network vulnerability assessments of all environ...Voir plus
Dernière mise à jour : il y a 20 jours • Offre sponsorisée
Senior Security Analyst : Threat Hunting & IR Automation

Senior Security Analyst : Threat Hunting & IR Automation

Sagard Holdings Inc. • Toronto
Temps plein
A leading asset management firm in Toronto is looking for a Senior Security Analyst to enhance security operations.The role involves leading advanced incident investigations, conducting threat hunt...Voir plus
Dernière mise à jour : il y a 20 jours • Offre sponsorisée
RG Analyst

RG Analyst

BET99 • markham, on, ca
Temps plein
BET99 is Canada's Premiere Online Sportsbook and Casino.Launched in 2020, we have consistently innovated the online gaming landscape every step of the way, exponentially growing our customer base a...Voir plus
Dernière mise à jour : il y a 1 jour • Offre sponsorisée
Senior Application Security Specialist

Senior Application Security Specialist

AIR MILES Reward Program • Toronto
Temps plein
The AIR MILES Reward Program is one of Canada’s most recognized loyalty programs, with over 10 million active collector accounts, representing more than half of all Canadian households.AIR MILES co...Voir plus
Dernière mise à jour : il y a 20 jours • Offre sponsorisée
Security Implementation SME - Azure and Palo Alto

Security Implementation SME - Azure and Palo Alto

Software International • Toronto
Temps plein
Security Implementation SME - Azure and Palo Alto.Job Openings Security Implementation SME - Azure and Palo Alto.About the job Security Implementation SME - Azure and Palo Alto.Fortune 100 / 500 / 1000...Voir plus
Dernière mise à jour : il y a 20 jours • Offre sponsorisée
Security Specialist - Senior_10+yrs

Security Specialist - Senior_10+yrs

Maarut Inc • Toronto
Temps plein
The Cyber Security Centre of Excellence (COE) is seeking one (1) Senior Cyber Security Specialist to support in strengthening Ontario’s cyber security infrastructure as the province collectively mo...Voir plus
Dernière mise à jour : il y a 20 jours • Offre sponsorisée
Senior App Security Engineer - Hybrid & Flexible PTO

Senior App Security Engineer - Hybrid & Flexible PTO

Clio • Toronto
Temps plein
A leading legal tech company in Toronto is seeking a Senior Application Security Developer to enhance its security practices. This role will involve developing security tools, providing remediation ...Voir plus
Dernière mise à jour : il y a 20 jours • Offre sponsorisée
Senior DevOps with Infrastructure (Security Clearance) - newmarket

Senior DevOps with Infrastructure (Security Clearance) - newmarket

Orion Innovation • newmarket, on, ca
Temps plein
Senior DevOps with Infrastructure.Senior DevOps with Infrastructure.Must be eligible for up to a Top-Secret Security Clearance. The Senior DevOps Engineer is a critical hands-on role responsible for...Voir plus
Dernière mise à jour : il y a 1 jour • Offre sponsorisée
Saviynt SME - TechDemocracy

Saviynt SME - TechDemocracy

TechDemocracy • markham, on, ca
Temps plein
Lead design and implementation of Saviynt IGA solutions (Lifecycle, Access Requests, Certifications).Integrate Saviynt with HR, AD, Azure AD, and cloud / on-prem applications.Configure workflows, pol...Voir plus
Dernière mise à jour : il y a 10 jours • Offre sponsorisée
Senior Application Security Engineer — Defensive Security

Senior Application Security Engineer — Defensive Security

Themis Solutions Inc. • Toronto
Temps plein
A leading technology firm seeks a Senior Software Developer in Defensive Security to join its team in Toronto.The role involves developing innovative solutions to enhance application security while...Voir plus
Dernière mise à jour : il y a 2 jours • Offre sponsorisée
AI / LLM Security Penetration Tester

AI / LLM Security Penetration Tester

TD Securities • Toronto
Temps plein
A leading financial institution in Toronto is seeking an Information Security Specialist specializing in AI Penetration Testing. This role involves conducting advanced security testing across AI / ML ...Voir plus
Dernière mise à jour : il y a 10 jours • Offre sponsorisée
Senior Physical Security Integration Analyst

Senior Physical Security Integration Analyst

Equinix • Toronto
Temps plein
A global digital infrastructure company is seeking a Physical Security Enablement Senior Analyst in Toronto.This role is crucial for safeguarding Data Centers with top-tier security solutions.It in...Voir plus
Dernière mise à jour : il y a 8 jours • Offre sponsorisée
Mobile Manual Tester (Android and iOS)

Mobile Manual Tester (Android and iOS)

Pacer Group • newmarket, on, ca
Temps plein
Mobile Manual Tester with extensive experience in mobile (iOS, Android), Skilled in functional, regression, UI / UX, and exploratory testing, with hands-on experience using Jira, SQL, and Postman.Fam...Voir plus
Dernière mise à jour : il y a 1 jour • Offre sponsorisée
Cyber Security Manager - Penetration Tester

Cyber Security Manager - Penetration Tester

RSM Canada • Toronto
Temps plein
Cyber Security Manager - Penetration Tester.Be among the first 25 applicants.We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence...Voir plus
Dernière mise à jour : il y a 20 jours • Offre sponsorisée
Application Security Lead

Application Security Lead

Compunnel, Inc. • Toronto
Temps plein
The Application Security Lead is responsible for integrating, optimizing, and managing security tools within the DevSecOps pipeline. The role will triage application security findings, drive remedia...Voir plus
Dernière mise à jour : il y a 20 jours • Offre sponsorisée
Senior DevOps with Infrastructure (Security Clearance) - markham

Senior DevOps with Infrastructure (Security Clearance) - markham

Orion Innovation • markham, on, ca
Temps plein
Senior DevOps with Infrastructure.Senior DevOps with Infrastructure.Must be eligible for up to a Top-Secret Security Clearance. The Senior DevOps Engineer is a critical hands-on role responsible for...Voir plus
Dernière mise à jour : il y a 1 jour • Offre sponsorisée
Senior Network Security Engineer – HPE Aruba SSE - Ateko, backed by Bell Canada

Senior Network Security Engineer – HPE Aruba SSE - Ateko, backed by Bell Canada

Ateko, backed by Bell Canada • newmarket, on, ca
Temporaire
Job Title : Senior Network Security Engineer – HPE Aruba SSE.We are looking for a Senior Network Security Engineer with strong hands-on expertise in HPE Aruba Secure Service Edge (SSE) deployments.T...Voir plus
Dernière mise à jour : il y a 10 jours • Offre sponsorisée
Epicor Kinetic Implementation Specialist - Tenth Revolution Group

Epicor Kinetic Implementation Specialist - Tenth Revolution Group

Tenth Revolution Group • markham, on, ca
Temps plein
Job Description : Epicor Kinetic Implementation Consultant.Epicor Kinetic Implementation Consultant.ERP implementations for manufacturing and distribution clients. This role requires strong expertise...Voir plus
Dernière mise à jour : il y a 9 jours • Offre sponsorisée