Talent.com
Malleum
Remote Penetration Tester - Offensive SecurityMalleum • Winnipeg, Manitoba
Remote Penetration Tester - Offensive Security

Remote Penetration Tester - Offensive Security

Malleum • Winnipeg, Manitoba
Il y a 8 jours
Type de contrat
  • Temps plein
  • Télétravail
Description de poste

Location: Hybrid / On-site at client locations as required
Department: Offensive Security & Adversary Simulation

About Malleum

Malleum is at the forefront of next-generation cyber defense, partnering with marquee clients across space, aerospace, defense, government, financial services, and critical infrastructure. We're experiencing exceptional growth as demand accelerates for trusted advisors capable of delivering at the intersection of national security, allied intelligence cooperation, and enterprise resilience. Our offensive security consultants test the systems behind cutting-edge defensive technologies, sovereign space capabilities, and allied programs - finding the gaps before adversaries do, on networks that protect missions of genuine national consequence.

If you take pride in breaking things ethically - and helping the most consequential organizations build back stronger - Malleum is where your craft meets purpose.

The Opportunity

We're seeking a Penetration Tester to deliver hands-on offensive security engagements across client networks, applications, cloud environments, and operational technology. You'll work directly within client environments - including sovereign, regulated, and cleared settings - emulating real-world adversaries, documenting findings, and partnering with clients to drive meaningful remediation.

This is a hands-on consulting role for a practitioner who blends deep technical tradecraft with strong client presence and the discipline to deliver findings clearly, safely, and on schedule.

What You'll Do

  • Plan, scope, and execute penetration tests across external, internal, web application, API, mobile, cloud (Azure / AWS / GCP), wireless, and Active Directory targets
  • Conduct red team and adversary emulation engagements aligned to MITRE ATT&CK, executing realistic TTPs against client environments
  • Perform assumed-breach assessments, internal pivoting, privilege escalation, and lateral movement exercises
  • Support purple team exercises in partnership with client SOC and Malleum's IR practice to improve detection and response
  • Execute social engineering campaigns (phishing, vishing, physical) where contracted, with rigorous rules of engagement
  • Conduct cloud configuration reviews against CIS Benchmarks, CSA CCM, and provider-specific baselines
  • Support OT / ICS / SCADA security testing for defense and critical-infrastructure clients (with appropriate safety controls)
  • Develop custom tooling, scripts, and payloads (PowerShell, Python, C#, Go) to evade modern EDR and ZTNA controls during sanctioned engagements
  • Produce high-quality client deliverables: executive summaries, technical findings, reproduction steps, evidence, CVSS-scored risk ratings, and pragmatic remediation guidance
  • Deliver findings briefings to client stakeholders — from engineers to executive leadership and boards - with clarity and professionalism
  • Contribute to scoping, estimation, statements of work, and continuous improvement of Malleum's offensive security service offerings
  • Maintain meticulous engagement hygiene: rules of engagement, scope control, evidence handling, and safe-listing coordination
  • Participate in research, internal tooling development, CTFs, and conference contributions to grow Malleum's offensive capability and brand

What You Bring

  • 4+ years of professional penetration testing or red team experience, ideally in a consulting, MSSP, or in-house offensive security team
  • Demonstrated success working directly with clients - strong communication, professionalism, and stakeholder management skills
  • Deep working knowledge of network, web application, and Active Directory attack paths (Kerberoasting, AS-REP roasting, NTLM relay, ADCS abuse, BloodHound-driven pathing)
  • Hands-on proficiency with offensive tooling: Burp Suite Pro, Nmap, Nessus / Nuclei, Metasploit, Cobalt Strike, Sliver, Mythic, Impacket, BloodHound, CrackMapExec / NetExec, Responder, Mimikatz, and modern C2 frameworks
  • Strong scripting skills in Python, PowerShell, and Bash; comfort reading and modifying C#, Go, or Rust tooling
  • Experience evading or bypassing EDR (Defender, CrowdStrike, SentinelOne), AMSI, and modern Windows defenses
  • Familiarity with cloud attack paths in Azure / Entra ID (Pass-the-PRT, illicit consent grants, managed identity abuse) and AWS (IAM privilege escalation, metadata service abuse)
  • Solid grasp of ZTNA and identity-aware perimeters (e.g., Cloudflare Access, Zscaler, Entra Conditional Access) and how they reshape attacker tradecraft
  • Comfort emulating adversary TTPs mapped to MITRE ATT&CK and known threat-actor playbooks
  • Familiarity with testing standards: PTES, OWASP WSTG / MASTG / ASVS, NIST SP 800-115, OSSTMM
  • Awareness of compliance contexts that frame client expectations: PCI DSS, SOC 2, NIST 800-171 / CMMC, CPCSC, ITSG-33, ISO 27001:2022
  • Certifications such as OSCP, OSEP, OSWE, OSCE3, CRTO, CRTL, GPEN, GXPN, GWAPT, GMOB, GCSA / GPCS / GCLD (cloud), AWS Certified Security – Specialty, Microsoft SC-100 / AZ-500 strongly preferred; OSCP or equivalent practical certification (e.g., CRTO, HTB CPTS, PNPT) is a baseline expectation
  • Demonstrated ability to perform under pressure - calm, methodical, and ethical when engagements surface sensitive findings
  • Willingness and availability to work odd hours and extended shifts when supporting time-boxed red team windows, after-hours testing, or rapid-response offensive support during active IR matters
  • Comfort working across multiple client environments, tooling stacks, and rules-of-engagement simultaneously
  • Eligibility for Government of Canada security clearance (Secret or higher); existing clearance highly valued; or controlled-goods registration considered an asset
  • Bilingualism (English/French) considered a strong asset

Why Malleum

  • Test the systems behind programs with genuine national and allied security impact - across aerospace, defense, and critical infrastructure
  • Join a rapidly scaling firm with a flat, high-trust culture and direct access to senior offensive, IR, and engineering leaders
  • Exposure to a wide variety of advanced targets, sectors, and cleared environments
  • Dedicated research time, lab budget, and support for conference talks, CVE research, and open-source contributions
  • Competitive compensation, performance incentives, and comprehensive benefits
  • Continuous learning budget, certification sponsorship (OSCP, OSEP, OSWE, CRTL, SANS), and clear paths into senior red team, exploit development, or offensive research specializations


Malleum is an equal opportunity employer. We welcome applications from all qualified candidates and are committed to building a team that reflects the communities and missions we serve.

We are proud to accommodate individuals with disabilities throughout the recruitment and selection process. Please indicate your need for accommodations in your application.

Créer une alerte emploi pour cette recherche

Remote Penetration Tester - Offensive Security • Winnipeg, Manitoba

Offres similaires

Remote Security Software Engineer (Go) - App & Privacy

TailscaleWinnipeg, Manitoba, Canada
Télétravail
Temps plein

A cutting-edge tech company in Canada is seeking a skilled Software Engineer specializing in security and privacy.The role involves improving security properties by implementing features, auditing ... Voir plus

 • Offre sponsorisée

Cyber Security Engineer

Manitoba Liquor & Lotteries CorporationWinnipeg, Manitoba, Canada
Temps plein

The Cyber Security Engineer is responsible for the planning, development, design, execution, and support of the operation and integration of cyber security tools and processes to protect Manitoba L... Voir plus

 • Offre sponsorisée

Remote Sales Manager – AI-Driven Security Solutions

Birdseye Solutions IncWinnipeg, MB, CA
Télétravail
Temps plein

An established industry player is on the lookout for a dynamic Sales Manager to lead their sales team.This role is pivotal in driving revenue growth and fostering strong client relationships.The id... Voir plus

 • Offre sponsorisée

Senior Application Security Engineer (Remote)

BrexWinnipeg, Manitoba, Canada
Télétravail
Temps plein

Brex is the intelligent finance platform that enables companies to spend smarter and move faster in more than 200 markets.By combining global corporate cards and banking with intuitive spend manage... Voir plus

 • Offre sponsorisée

Senior Malware Protection Specialist (Trellix) – Remote

act digitalWinnipeg, MB, CA
Télétravail
Temps plein

A consulting and technology expertise company is seeking an experienced Senior IT and Security Administrator specializing in Malware Protection technologies.The ideal candidate will have a strong b... Voir plus

 • Offre sponsorisée

Remote Technical Marketing Lead for Security & Dev

Internetwork ExpertWinnipeg, MB, CA
Télétravail
Temps plein

A technology firm is seeking a Technical Marketing Leader to create compelling product narratives and technical content.This remote role requires a strong engineering background and experience in t... Voir plus

 • Offre sponsorisée

Remote Quality Assurance Role for Innovative Oncology Software

RadformationWinnipeg, MB, CA
Télétravail
Temps plein

Shape the future of cancer treatment as a Quality Assurance Manager, ensuring that AutoContour meets high-quality standards.Work remotely while executing tests and validation processes for product ... Voir plus

 • Offre sponsorisée

Senior Analyst, Security Compliance

P2PWinnipeg, Manitoba, Canada
Temps plein

Building the Future of Crypto Our Krakenites are a world-class team with crypto conviction, united by our desire to discover and unlock the potential of crypto and blockchain technology.Kraken is a... Voir plus

 • Offre sponsorisée

Air Cargo Screener — Aviation Security & Compliance Expert

CNSCWinnipeg, MB, CA
Temps plein +1

Join a forward-thinking company as an Air Cargo Screener and contribute to aviation security in a dynamic environment.This permanent full-time role involves meticulous adherence to safety protocols... Voir plus

 • Offre sponsorisée

Loss Prevention Store Security Agent - C$37,590 - C$52,626 A Year

TJX CanadaWinnipeg, Canada
Temps plein

TJX CanadaAt TJX Canada, every day brings new opportunities for growth, exploration, and achievement.You’ll be part of our vibrant team that embraces diversity, fosters collaboration, and prioritiz... Voir plus

 • Offre sponsorisée

REMOTE Protection & Controls Substation Engineer

JobotWinnipeg, MB, CA
Télétravail
Temps plein

REMOTE Protection & Controls Substation Engineer.Be among the first 25 applicants.This range is provided by Jobot.Your actual pay will be based on your skills and experience — talk with your recrui... Voir plus

 • Offre sponsorisée

Remote Product Tester

OCPAWinnipeg, Manitoba, CA
25,00 $CA par heure
Télétravail
Temps partiel +1

Product Testers are wanted to work from home nationwide in the US to fulfill upcoming contracts with national and international companies.We guarantee 15-25 hours per week with an hourly pay of bet... Voir plus

 • Offre sponsorisée

Remote Domain Security Consultant - SASE & Zero Trust

Palo Alto NetworksWinnipeg, MB, CA
Télétravail
Temps plein

A leading cybersecurity company is seeking a Domain Consultant in Vancouver to provide expertise in network security transformation.This role involves collaborating with sales teams and leading cus... Voir plus

 • Offre sponsorisée

Remote Presales Engineer for Global Network Security

StealthWatchWinnipeg, MB, CA
Télétravail
Temps plein

A leading technology firm is seeking a Presales Engineer to join their team.This role offers the chance to work remotely from anywhere in Canada and requires expertise in network and security techn... Voir plus

 • Offre sponsorisée

Remote Domain Security Consultant - SASE

Palo Alto NetworksWinnipeg, MB, CA
Télétravail
Temps plein

A cybersecurity company is seeking a remote Domain Consultant specializing in network security transformation.This role requires over 6 years in pre-sales within Zero Trust and Networking, excellen... Voir plus

 • Offre sponsorisée

Principal Security Analyst - Remote

CyderesWinnipeg, MB, CA
Télétravail
Temps plein

Be among the first 25 applicants.Cyderes (Cyber Defense and Response) is a pure-play, full life-cycle cybersecurity services provider with award-winning managed security services, identity and acce... Voir plus

 • Offre sponsorisée

Senior Penetration Tester - Android (Contract)

SamsungresearchamericaWinnipeg, Manitoba, Canada
Temps plein

The Development Quality Innovation (DQI) lab in Mountain View has a dual role that is first to research new automation tools as well as take current tools and refine them to our needs.Second, act a... Voir plus

 • Offre sponsorisée

Survey Taker: Earn up to $25 per survey (Remote)

Earn HausSt. Andrews, MB, CA
Télétravail
Temps plein +1

Looking for people to participate in taking online surveys for Fortune 500 brands.All you need to do is complete online surveys by sharing your opinion.You will help influence brand decisions on se... Voir plus

 • Offre sponsorisée

Cyber Security Advisor At Hitachi Rail - $114,000 - $147,000 A Year

Hitachi RailWinnipeg, Canada
Temps plein

About UsA career at Hitachi Rail will help create a legacy.With operations in every corner of the world, our work goes to the cutting-edge of digital transformation and technology.From the multi-cu... Voir plus

 • Offre sponsorisée

Senior Product Security Engineer – Remote Canada - Equity - $150,000 - $200,000 A Year - Remote

Financial Technology FirmWinnipeg, Canada
Télétravail
Temps plein

A financial technology firm is seeking a Senior Product Security Engineer to ensure security in the product development lifecycle and mitigate vulnerabilities.The ideal candidate should have a stro... Voir plus