Talent.com
Malleum
Penetration Tester - Offensive SecurityMalleum • Ahuntsic North, ca
No longer accepting applications
Penetration Tester - Offensive Security

Penetration Tester - Offensive Security

Malleum • Ahuntsic North, ca
5 days ago
Job type
  • Full-time
Job description
Location: Hybrid / On-site at client locations as required

Department: Offensive Security & Adversary Simulation

About Malleum

Malleum is at the forefront of next‑generation cyber defense, partnering with marquee clients across space, aerospace, defense, government, financial services, and critical infrastructure. We're experiencing exceptional growth as demand accelerates for trusted advisors capable of delivering at the intersection of national security, allied intelligence cooperation, and enterprise resilience. Our offensive security consultants test the systems behind cutting‑edge defensive technologies, sovereign space capabilities, and allied programs - finding the gaps before adversaries do, on networks that protect missions of genuine national consequence. If you take pride in breaking things ethically - and helping the most consequential organizations build back stronger - Malleum is where your craft meets purpose. The Opportunity

We're seeking a Penetration Tester to deliver hands‑on offensive security engagements across client networks, applications, cloud environments, and operational technology. You'll work directly within client environments - including sovereign, regulated, and cleared settings - emulating real‑world adversaries, documenting findings, and partnering with clients to drive meaningful remediation.

This is a hands‑on consulting role for a practitioner who blends deep technical tradecraft with strong client presence and the discipline to deliver findings clearly, safely, and on schedule.

What You'll Do

Plan, scope, and execute penetration tests across external, internal, web application, API, mobile, cloud (Azure / AWS / GCP), wireless, and Active Directory targets Conduct red team and adversary emulation engagements aligned to MITRE ATT&CK, executing realistic TTPs against client environments Perform assumed‑breach assessments, internal pivoting, privilege escalation, and lateral movement exercises Support purple team exercises in partnership with client SOC and Malleum's IR practice to improve detection and response Execute social engineering campaigns (phishing, vishing, physical) where contracted, with rigorous rules of engagement Conduct cloud configuration reviews against CIS Benchmarks, CSA CCM, and provider‑specific baselines Support OT / ICС / SCADA security testing for defense and critical‑infrastructure clients (with appropriate safety controls) Develop custom tooling, scripts, and payloads (PowerShell, Python, C#, Go) to evade modern EDR and ZTNA controls during sanctioned engagements Produce high‑quality client deliverables: executive summaries, technical findings, reproduction steps, evidence, CVSS‑scored risk ratings, and pragmatic remediation guidance Deliver findings briefings to client stakeholders — from engineers to executive leadership and boards -with clarity and professionalism Contribute to scoping, estimation, statements of work, and continuous improvement of Malleum's offensive security service offerings Maintain meticulous engagement hygiene: rules of engagement, scope control, evidence handling, and safe‑listing coordination Participate in research, internal tooling development, CTFs, and conference contributions to grow Malleum's offensive capability and brand What You Bring

4+ years of professional penetration testing or red team experience, ideally in a consulting, MSSP, or in‑house offensive security team Demonstrated success working directly with clients — strong communication, professionalism, and stakeholder management skills Deep working knowledge of network, web application, and Active Directory attack paths (Kerberoasting, AS‑REP roasting, NTLM relay, ADCS abuse, BloodHound‑driven pathing) Hands‑on proficiency with offensive tooling: Burp Suite Pro, Nmap, Nessus / Nuclei, Metasploit, Cobalt Strike, Sliver, Mythic, Impacket, BloodHound, CrackMapExec / NetExec, Responder, Mimikatz, and modern C2 frameworks Strong scripting skills in Python, PowerShell, and Bash; comfort reading and modifying C#, Go, or Rust tooling Experience evading or bypassing EDR (Defender, CrowdStrike, SentinelOne), AMSI, and modern Windows defenses Familiarity with cloud attack paths in Azure / Entra ID (Pass‑the‑PRT, illicit consent grants, managed identity abuse) and AWS (IAM privilege escalation, metadata service abuse) Solid grasp of ZTNA and identity‑aware perimeters (e.g., Cloudflare Access, Zscaler, Entra Conditional Access) and how they reshape attacker tradecraft Comfort emulating adversary TTPs mapped to MITRE ATT&CK and known threat‑actor playbooks Familiarity with testing standards: PTES, OWASP WSTG / MASTG / ASVS, NIST SP 800‑115, OSSTMM Awareness of compliance contexts that frame client expectations: PCI DSS, SOC 2, NIST 800‑171 / CMMC, CPCSC, ITSG‑33, ISO 27001:2022 Certifications such as OSCP, OSEP, OSWE, OSCE3, CRTO, CRTL, GPEN, GXPN, GWAPT, GMOB, GCSA / GPCS / GCLD (cloud), AWS Certified Security – Specialty, Microsoft SC‑100 / AZ‑500 strongly preferred; OSCP or equivalent practical certification (e.g., CRTO, HTB CPTS, PNPT) is a baseline expectation Demonstrated ability to perform under pressure — calm, methodical, and ethical when engagements surface sensitive findings Willingness and availability to work odd hours and extended shifts when supporting time‑boxed red team windows, after‑hours testing, or rapid‑response offensive support during active IR matters Comfort working across multiple client environments, tooling stacks, and rules‑of‑engagement simultaneously Eligibility for Government of Canada security clearance (Secret or higher); existing clearance highly valued; or controlled‑goods registration considered an asset Bilingualism (English/French) considered a strong asset Why Malleum

Test the systems behind programs with genuine national and allied security impact – across aerospace, defense, and critical infrastructure Join a rapidly scaling firm with a flat, high‑trust culture and direct access to senior offensive, IR, and engineering leaders Exposure to a wide variety of advanced targets, sectors, and cleared environments Dedicated research time, lab budget, and support for conference talks, CVE research, and open‑source contributions Competitive compensation, performance incentives, and comprehensive benefits Continuous learning budget, certification sponsorship (OSCP, OSEP, OSWE, CRTL, SANS), and clear paths into senior red team, exploit development, or offensive research specializations Malleum is an equal opportunity employer. We welcome applications from all qualified candidates and are committed to building a team that reflects the communities and missions we serve. We are proud to accommodate individuals with disabilities throughout the recruitment and selection process. Please indicate your need for accommodations in your application.

#J-18808-Ljbffr
Create a job alert for this search

Penetration Tester - Offensive Security • Ahuntsic North, ca

Similar jobs

Senior Oracle Application Developer - PwC Canada

PwC Canadasaint-esprit, qc, ca
Full-time

Please review this posting in detail and self-assess your eligibility, before applying.PwC Canada is sourcing for two (x2) Secret (Level II) security cleared, Senior Oracle Application Developer, C... Show more

 • Promoted

Sap Finance Control Consultant - saint-esprit

Pacer Groupsaint-esprit, qc, ca
Full-time

Job Title: Sap Finance Control Consultant.Pay Rate: CAD 75-80/hour Incorporated.Application Deadline: May 18th, 2026.Minimum 8 years of experience in SAP Controlling.At least one end to end impleme... Show more

 • Promoted

Senior Cloud Penetration Tester (AWS) — Remote

NetSPI Inc.Montreal (administrative region), QC, CA
Remote
Full-time

A leading cybersecurity company is seeking a Senior Security Consultant specializing in Cloud Penetration Testing for AWS.This role requires a Bachelor’s degree and 3-5 years of penetration testing... Show more

 • Promoted

MONTREAL [Hybrid] - CSIRT Security Analyst Level 2 - QUANTEAM (Groupe RAINBOW PARTNERS)

QUANTEAM (Groupe RAINBOW PARTNERS)laval, qc, ca
Full-time

As the founding entity of RAINBOW PARTNERS, Quanteam is a consulting firm specializing in Banking, Finance, and Financial Services.Guided by our core values of closeness, teamwork, diversity, and e... Show more

 • Promoted

Penetration Tester - Offensive Security

MalleumRivière-Des-Prairies-Pointe-Aux-Trembles, Canada
Full-time

Location: Hybrid / On-site at client locations as requiredDepartment: Offensive Security & Adversary SimulationAbout MalleumMalleum is at the forefront of next‑generation cyber defense, partner... Show more

 • Promoted

Quality Assurance Specialist

IFG - International Financial Groupsaint-esprit, qc, ca
Temporary

Job Title: Software Test Engineer 2.Location: Hybrid: 3 days per week: Vancouver.The Development Support team member works with development teams to provide early testing, documentation creation (e... Show more

 • Promoted

Azure local SME - Ascendion

Ascendionsaint-esprit, qc, ca
Full-time

Ascendion est une entreprise offrant une gamme complète de solutions en ingénierie numérique.Nous concevons et gérons des plateformes et des produits logiciels qui stimulent la croissance et offren... Show more

 • Promoted

Guidewire Developer/Tech Lead

Delta System & Software, Inc.saint-esprit, qc, ca
Full-time

Job Title: Guidewire Tech Lead.Must have: Guidewire ACE Certification.Strong hands-on experience in PolicyCenter, BillingCenter, or ClaimCenter (v10.Lead and mentor a team of developers, driving de... Show more

 • Promoted

Survey Taker: Earn up to $25 per survey (Remote)

Earn HausRawdon, QC, CA
Remote
Full-time +1

Looking for people to participate in taking online surveys for Fortune 500 brands.All you need to do is complete online surveys by sharing your opinion.You will help influence brand decisions on se... Show more

 • Promoted

Public Safety & Fire Prevention Technician - saint-esprit

Kativik Regional Governmentsaint-esprit, qc, ca
Permanent

The Kativik Regional Government (KRG) is a supra-municipal organization with jurisdiction over the Quebec territory located north of the 55th parallel.The role of the KRG Civil Security Department ... Show more

 • Promoted

Data Security Services Compliance Manager - Entrust

Entrustsaint-esprit, qc, ca
Full-time

At Entrust, we’re shaping the future of identity centric security solutions.From our comprehensive portfolio of solutions to our flexible, global workplace, we empower careers, foster collaboration... Show more

 • Promoted

Software Quality Assurance Analyst - saint-esprit

Helic & Co.saint-esprit, qc, ca
Full-time

Location: Remote (Canada-based).Occasional on-site presence may be required in Edmonton, Alberta.Engagement Type: Contract – Full-Time Allocation (Initial 12 months with possible extensions up to 3... Show more

 • Promoted

Expert Penetration Tester - Remote Role

New Value SolutionsMontreal (administrative region), QC, CA
Remote
Full-time

New Value Solutions invites you to apply for the role of Senior Penetration Tester, working remotely within Canada.Contribute to cybersecurity efforts in a structured, public-sector justice framewo... Show more

 • Promoted

Quality Inspector

BombarbierDorval, QC, Canada
Full-time

Bombardier is a global leader in aviation, focused on designing, manufacturing and servicing the worlds most exceptional business jets and specialized mission platforms.Bombardier has been successf... Show more

 • Promoted • New!

Senior Guidewire PolicyCenter Developer - Axiom Global Technologies

Axiom Global Technologiessaint-esprit, qc, ca
Full-time

We are seeking a highly experienced Senior Guidewire PolicyCenter Developer to lead the design, configuration, customization, and support of PolicyCenter solutions.This is a hands-on engineering ro... Show more

 • Promoted

Armour Soldier

Calian Groupsaint-esprit, qc, ca
Full-time

Calian / Deloitte is a third‑party service provider contracted by the Canadian Armed Forces Recruiting Group (CFRG) to provide information and candidate sourcing support for CAF career opportunitie... Show more

 • Promoted

Senior Security Engineer (Pen Tester)

Menlo SecurityMontreal (administrative region), QC, CA
Full-time

Menlo Security's mission is enabling the world to connect, communicate and collaborate securely without compromise.COVID-19 has made our mission all the more real.We support customers across variou... Show more

 • Promoted

Penetration Tester

Software SecuredRivière-Des-Prairies-Pointe-Aux-Trembles, Canada
Full-time +1

Software Secured is a leading Penetration Testing as a Service (PTaaS) company, with a head office in beautiful Ottawa, Canada.We help software development teams get ahead of hackers, using a suite... Show more

 • Promoted

Product Security Specialist - montréal

Haivisionmontréal, qc, ca
Full-time

The Product Security Specialist is responsible for ensuring products are secure before release by embedding security into the development lifecycle.This role focuses on automated security testing, ... Show more

 • Promoted

Safety Engineer

IKOS GROUPsaint-esprit, qc, ca
Full-time

European consulting firm specializing in.We are committed to participating in the ecological transition and to developing the means of transportation of the future that are.To continue IKOS’s growt... Show more