Talent.com
Senior Penetration Tester, Application Security
Senior Penetration Tester, Application SecurityQueer Tech • Toronto, Canada
Senior Penetration Tester, Application Security

Senior Penetration Tester, Application Security

Queer Tech • Toronto, Canada
16 days ago
Job type
  • Full-time
Job description

Build something people love

Wealthsimple is on a mission to help everyone achieve financial freedom by reimagining what it means to manage your money. Using smart technology, we take financial services that are often confusing and expensive and make them transparent and low-cost for everyone. We’re the largest fintech company in Canada, with 3+ million users who trust us with more than $100 billion in assets. And we’re just getting started.

We’re looking for someone who thinks big, sweats the small stuff and keeps things simple. You’ll join a high-bar, fast-paced team where people are trusted to own their work, communicate openly, and ship things that improve our clients’ lives. Collaboration, humility, and an obsession over quality are how we get stuff done.

About the Role

As a Senior Penetration Tester you will plan engagements, find security vulnerabilities, and help us fix them. Your role also involves establishing rapport with leadership, as well as internal, consultant, and third-party teams to communicate and support the improvement of our company’s cybersecurity posture and resiliency. You will report to the Senior Manager, Application Security and have a mandate to plan and execute secure code reviews, penetration tests, and other offensive security activities to improve Wealthsimple’s security.

This role requires a unique blend of offensive security expertise and collaborative problem-solving. You won't just be finding vulnerabilities and handing off reports - you'll be working shoulder-to-shoulder with engineering teams to understand root causes, suggest practical remediations, and sometimes implement fixes yourself. If you see your job ending when the report is submitted, this role isn't for you. We're looking for someone who sees vulnerability discovery as the beginning of the conversation, not the end.

Responsibilities

Perform security assessments : discover flaws in our systems by conducting detailed penetration tests, code reviews, or threat models on our internal systems, web applications, and other software.

Analyze vulnerabilities : determine the real-world severity of discovered issues and suggest actionable recommendations to address security threats, improve application security, and strengthen our cloud environments.

Write findings : create comprehensive write-ups of the findings, risk analysis, recommendations, and actionable insights for our engineers and other stakeholders.

Help fix problems : work closely with our application security, vulnerability management, infrastructure and platform engineers to implement solutions, enhance our security posture, and develop guardrails, regression tests, and out-of-the-box solutions to prevent future vulnerabilities or design flaws.

What You Bring

Courageously Ambitious - enthusiastically tackle big audacious goals.

Deeply Human - take responsibility for bringing the best out of themselves and others.

Problem Solvers - have the ability and resilience to tackle complex issues and see them through.

Skills and Experience

Experience (5+ years preferred) in a mix of network, application, and native mobile penetration testing with a proven history of working cross-functionally with high-functioning teams.

Experience performing boundary testing for PCI-DSS card holder environments or equivalent.

Experience performing mobile testing for Android / iOS applications.

Technical understanding of networks, endpoint, identity, cloud, encryption, data protection and application deployment stacks.

Knowledge of standard penetration testing methodologies, including NIST SP 800-115.

Familiarity with Ruby, React, and GraphQL testing is preferred.

Development and / or scripting competence is preferred.

AWS testing experience is preferred.

Previous industry experience in Financial Services is preferred.

Experience using automation and AI to supplement and scale manual testing is preferred.

Education and Certifications

Offensive Security Certified Professional (OSCP) / Experienced Penetration Tester (OSEP)

CREST Registered Tester

AWS Certified Security - Specialty

Bachelor’s or higher degree in cybersecurity, software engineering, or a related field

Compensation & Equity

Base salary range : For this role, candidates located in Canada can expect a base salary range of CAD $151,200 - $189,000. Actual compensation is determined based on skills, experience, and role level. Exceptional candidates may be considered above the top of the range, and pay can increase quickly for those who make a big impact in the role.

Total compensation : In addition to base salary, this role includes equity compensation. We use clear job levels and market-based salary bands to ensure compensation is fair and consistent across the company.

Why Wealthsimple?

Top-tier health benefits and life insurance

Long-term group savings with employer match using our Wealthsimple for Business platform

20 vacation days + 4 wellness days per year, and unlimited sick and mental health days

✈️ 90 days away program : Employees can work outside of Canada for up to 90 days per calendar year

A wide variety of peer and company-led Employee Resources Groups (e.g., Rainbow, Women of Wealthsimple, Black @ WS)

We’re a remote first team with over 1,500 employees across North America - and one of the best things about working here is the people. You’ll be collaborating with incredibly talented, curious, and driven teammates who care deeply about doing great work.

Be a part of our Canadian success story and help shape the financial future of millions.

Technology & Innovation at Wealthsimple

We believe the future belongs to those who innovate boldly. At Wealthsimple, every team member is expected to lean into new technologies, including AI, and tooling to rethink how we work, solve problems faster, and create even greater value. We're looking for people who are not just comfortable with change but energized by it. Our commitment is to build a company that evolves at the pace of the world around us, and we want you to help lead that future.

DEI Statement

At Wealthsimple, we are building products for a diverse world and we need a diverse team to do that successfully. We strongly encourage applications from everyone regardless of race, religion, colour, national origin, gender, sexual orientation, age, marital status, or disability status.

Accessibility Statement

Wealthsimple provides an accessible candidate experience. If you need any accommodations or adjustments throughout the interview process and beyond, please let us know, and we will work with you to provide the necessary support and make reasonable accommodations to facilitate your participation. We are continuously working to improve our accessibility practices and welcome any feedback or suggestions on how we can better accommodate candidates with accessibility needs.

#J-18808-Ljbffr

Create a job alert for this search

Senior Penetration Tester Application Security • Toronto, Canada

Similar jobs
RQ08437 - Security Specialist - Penetration Testing - Senior

RQ08437 - Security Specialist - Penetration Testing - Senior

Rubicon Path • Toronto
Full-time
RQ08437 - Security Specialist - Penetration Testing - Senior.Conducts penetration tests, web application vulnerability assessments, code reviews and network vulnerability assessments of all environ...Show more
Last updated: 20 days ago • Promoted
Signaling Tester in Charge

Signaling Tester in Charge

Alstom • Toronto
Full-time
At Alstom, we understand transport networks and what moves people.From high‑speed trains, metros, monorails, and trams, to turnkey systems, services, infrastructure, signalling and digital mobility...Show more
Last updated: 20 days ago • Promoted
Mobile Manual Tester (Android and iOS)

Mobile Manual Tester (Android and iOS)

Pacer Group • richmond hill, ON, ca
Full-time
Mobile Manual Tester with extensive experience in mobile (iOS, Android), Skilled in functional, regression, UI / UX, and exploratory testing, with hands-on experience using Jira, SQL, and Postman.Fam...Show more
Last updated: 1 day ago • Promoted
Senior Security Analyst : Threat Hunting & IR Automation

Senior Security Analyst : Threat Hunting & IR Automation

Sagard Holdings Inc. • Toronto
Full-time
A leading asset management firm in Toronto is looking for a Senior Security Analyst to enhance security operations.The role involves leading advanced incident investigations, conducting threat hunt...Show more
Last updated: 20 days ago • Promoted
Cyber Security Analyst | Apple

Cyber Security Analyst | Apple

Sky States • Toronto
Full-time
We are seeking a skilled and motivated.The ideal candidate will be responsible for protecting the organization’s systems, networks, and data from cyber threats while ensuring compliance with securi...Show more
Last updated: 15 days ago • Promoted
Senior Application Security Specialist

Senior Application Security Specialist

AIR MILES Reward Program • Toronto
Full-time
The AIR MILES Reward Program is one of Canada’s most recognized loyalty programs, with over 10 million active collector accounts, representing more than half of all Canadian households.AIR MILES co...Show more
Last updated: 20 days ago • Promoted
Senior App Security Engineer - Hybrid & Flexible PTO

Senior App Security Engineer - Hybrid & Flexible PTO

Clio • Toronto
Full-time
A leading legal tech company in Toronto is seeking a Senior Application Security Developer to enhance its security practices. This role will involve developing security tools, providing remediation ...Show more
Last updated: 20 days ago • Promoted
LabVIEW Test Engineer

LabVIEW Test Engineer

Global Connect Technologies • newmarket, on, ca
Full-time
Job Title : LabVIEW Test Engineer.We are seeking LabVIEW Test Engineer will be responsible for validating automotive cluster software through automated test scripts to ensure functional compliance w...Show more
Last updated: 13 days ago • Promoted
Senior DevOps with Infrastructure (Security Clearance) - newmarket

Senior DevOps with Infrastructure (Security Clearance) - newmarket

Orion Innovation • newmarket, on, ca
Full-time
Senior DevOps with Infrastructure.Senior DevOps with Infrastructure.Must be eligible for up to a Top-Secret Security Clearance. The Senior DevOps Engineer is a critical hands-on role responsible for...Show more
Last updated: 1 day ago • Promoted
Saviynt SME - TechDemocracy

Saviynt SME - TechDemocracy

TechDemocracy • markham, on, ca
Full-time
Lead design and implementation of Saviynt IGA solutions (Lifecycle, Access Requests, Certifications).Integrate Saviynt with HR, AD, Azure AD, and cloud / on-prem applications.Configure workflows, pol...Show more
Last updated: 10 days ago • Promoted
Senior Application Security Engineer — Defensive Security

Senior Application Security Engineer — Defensive Security

Themis Solutions Inc. • Toronto
Full-time
A leading technology firm seeks a Senior Software Developer in Defensive Security to join its team in Toronto.The role involves developing innovative solutions to enhance application security while...Show more
Last updated: 2 days ago • Promoted
Senior Physical Security Integration Analyst

Senior Physical Security Integration Analyst

Equinix • Toronto
Full-time
A global digital infrastructure company is seeking a Physical Security Enablement Senior Analyst in Toronto.This role is crucial for safeguarding Data Centers with top-tier security solutions.It in...Show more
Last updated: 7 days ago • Promoted
Senior Compliance Testing Analyst (3925)

Senior Compliance Testing Analyst (3925)

TD Securities • Markham
Full-time
Work Location : Markham, Ontario, Canada.Pay Details : $81,600 - $115,200 CAD.TD is committed to providing fair and equitable compensation opportunities to all colleagues. Growth opportunities and ski...Show more
Last updated: 9 days ago • Promoted
Cyber Security Manager - Penetration Tester

Cyber Security Manager - Penetration Tester

RSM Canada • Toronto
Full-time
Cyber Security Manager - Penetration Tester.Be among the first 25 applicants.We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence...Show more
Last updated: 20 days ago • Promoted
Senior Penetration Testing & Risk Consultant (Hybrid)

Senior Penetration Testing & Risk Consultant (Hybrid)

CIBC • Toronto
Full-time
A leading financial institution in Toronto is seeking a Senior Information Security Consultant to assess and communicate the risks associated with penetration testing findings.You will translate te...Show more
Last updated: 14 days ago • Promoted
Application Security Lead

Application Security Lead

Compunnel, Inc. • Toronto
Full-time
The Application Security Lead is responsible for integrating, optimizing, and managing security tools within the DevSecOps pipeline. The role will triage application security findings, drive remedia...Show more
Last updated: 20 days ago • Promoted
Senior DevOps with Infrastructure (Security Clearance) - markham

Senior DevOps with Infrastructure (Security Clearance) - markham

Orion Innovation • markham, on, ca
Full-time
Senior DevOps with Infrastructure.Senior DevOps with Infrastructure.Must be eligible for up to a Top-Secret Security Clearance. The Senior DevOps Engineer is a critical hands-on role responsible for...Show more
Last updated: 1 day ago • Promoted
Senior Network Security Engineer – HPE Aruba SSE - Ateko, backed by Bell Canada

Senior Network Security Engineer – HPE Aruba SSE - Ateko, backed by Bell Canada

Ateko, backed by Bell Canada • newmarket, on, ca
Temporary
Job Title : Senior Network Security Engineer – HPE Aruba SSE.We are looking for a Senior Network Security Engineer with strong hands-on expertise in HPE Aruba Secure Service Edge (SSE) deployments.T...Show more
Last updated: 10 days ago • Promoted