Talent.com
Malleum
Remote Penetration Tester - Offensive SecurityMalleum • Halifax, Nova Scotia
Remote Penetration Tester - Offensive Security

Remote Penetration Tester - Offensive Security

Malleum • Halifax, Nova Scotia
30+ days ago
Job type
  • Full-time
  • Remote
Job description

Location: Hybrid / On-site at client locations as required
Department: Offensive Security & Adversary Simulation

About MalleumMalleum is at the forefront of next-generation cyber defense, partnering with marquee clients across space, aerospace, defense, government, financial services, and critical infrastructure. We're experiencing exceptional growth as demand accelerates for trusted advisors capable of delivering at the intersection of national security, allied intelligence cooperation, and enterprise resilience. Our offensive security consultants test the systems behind cutting-edge defensive technologies, sovereign space capabilities, and allied programs - finding the gaps before adversaries do, on networks that protect missions of genuine national consequence.

If you take pride in breaking things ethically - and helping the most consequential organizations build back stronger - Malleum is where your craft meets purpose.

The Opportunity

We're seeking a Penetration Tester to deliver hands-on offensive security engagements across client networks, applications, cloud environments, and operational technology. You'll work directly within client environments - including sovereign, regulated, and cleared settings - emulating real-world adversaries, documenting findings, and partnering with clients to drive meaningful remediation.

This is a hands-on consulting role for a practitioner who blends deep technical tradecraft with strong client presence and the discipline to deliver findings clearly, safely, and on schedule.

What You'll Do

  • Plan, scope, and execute penetration tests across external, internal, web application, API, mobile, cloud (Azure / AWS / GCP), wireless, and Active Directory targets
  • Conduct red team and adversary emulation engagements aligned to MITRE ATT&CK, executing realistic TTPs against client environments
  • Perform assumed-breach assessments, internal pivoting, privilege escalation, and lateral movement exercises
  • Support purple team exercises in partnership with client SOC and Malleum's IR practice to improve detection and response
  • Execute social engineering campaigns (phishing, vishing, physical) where contracted, with rigorous rules of engagement
  • Conduct cloud configuration reviews against CIS Benchmarks, CSA CCM, and provider-specific baselines
  • Support OT / ICS / SCADA security testing for defense and critical-infrastructure clients (with appropriate safety controls)
  • Develop custom tooling, scripts, and payloads (PowerShell, Python, C#, Go) to evade modern EDR and ZTNA controls during sanctioned engagements
  • Produce high-quality client deliverables: executive summaries, technical findings, reproduction steps, evidence, CVSS-scored risk ratings, and pragmatic remediation guidance
  • Deliver findings briefings to client stakeholders — from engineers to executive leadership and boards - with clarity and professionalism
  • Contribute to scoping, estimation, statements of work, and continuous improvement of Malleum's offensive security service offerings
  • Maintain meticulous engagement hygiene: rules of engagement, scope control, evidence handling, and safe-listing coordination
  • Participate in research, internal tooling development, CTFs, and conference contributions to grow Malleum's offensive capability and brand
What You Bring
  • 4+ years of professional penetration testing or red team experience, ideally in a consulting, MSSP, or in-house offensive security team
  • Demonstrated success working directly with clients - strong communication, professionalism, and stakeholder management skills
  • Deep working knowledge of network, web application, and Active Directory attack paths (Kerberoasting, AS-REP roasting, NTLM relay, ADCS abuse, BloodHound-driven pathing)
  • Hands-on proficiency with offensive tooling: Burp Suite Pro, Nmap, Nessus / Nuclei, Metasploit, Cobalt Strike, Sliver, Mythic, Impacket, BloodHound, CrackMapExec / NetExec, Responder, Mimikatz, and modern C2 frameworks
  • Strong scripting skills in Python, PowerShell, and Bash; comfort reading and modifying C#, Go, or Rust tooling
  • Experience evading or bypassing EDR (Defender, CrowdStrike, SentinelOne), AMSI, and modern Windows defenses
  • Familiarity with cloud attack paths in Azure / Entra ID (Pass-the-PRT, illicit consent grants, managed identity abuse) and AWS (IAM privilege escalation, metadata service abuse)
  • Solid grasp of ZTNA and identity-aware perimeters (e.g., Cloudflare Access, Zscaler, Entra Conditional Access) and how they reshape attacker tradecraft
  • Comfort emulating adversary TTPs mapped to MITRE ATT&CK and known threat-actor playbooks
  • Familiarity with testing standards: PTES, OWASP WSTG / MASTG / ASVS, NIST SP 800-115, OSSTMM
  • Awareness of compliance contexts that frame client expectations: PCI DSS, SOC 2, NIST 800-171 / CMMC, CPCSC, ITSG-33, ISO 27001:2022
  • Certifications such as OSCP, OSEP, OSWE, OSCE3, CRTO, CRTL, GPEN, GXPN, GWAPT, GMOB, GCSA / GPCS / GCLD (cloud), AWS Certified Security – Specialty, Microsoft SC-100 / AZ-500 strongly preferred; OSCP or equivalent practical certification (e.g., CRTO, HTB CPTS, PNPT) is a baseline expectation
  • Demonstrated ability to perform under pressure - calm, methodical, and ethical when engagements surface sensitive findings
  • Willingness and availability to work odd hours and extended shifts when supporting time-boxed red team windows, after-hours testing, or rapid-response offensive support during active IR matters
  • Comfort working across multiple client environments, tooling stacks, and rules-of-engagement simultaneously
  • Eligibility for Government of Canada security clearance (Secret or higher); existing clearance highly valued; or controlled-goods registration considered an asset
  • Bilingualism (English/French) considered a strong asset

Why Malleum

  • Test the systems behind programs with genuine national and allied security impact - across aerospace, defense, and critical infrastructure
  • Join a rapidly scaling firm with a flat, high-trust culture and direct access to senior offensive, IR, and engineering leaders
  • Exposure to a wide variety of advanced targets, sectors, and cleared environments
  • Dedicated research time, lab budget, and support for conference talks, CVE research, and open-source contributions
  • Competitive compensation, performance incentives, and comprehensive benefits
  • Continuous learning budget, certification sponsorship (OSCP, OSEP, OSWE, CRTL, SANS), and clear paths into senior red team, exploit development, or offensive research specializations

Malleum is an equal opportunity employer. We welcome applications from all qualified candidates and are committed to building a team that reflects the communities and missions we serve.

We are proud to accommodate individuals with disabilities throughout the recruitment and selection process. Please indicate your need for accommodations in your application.

Create a job alert for this search

Remote Penetration Tester - Offensive Security • Halifax, Nova Scotia

Similar jobs

Senior Test Specialist

Babcock Mission Critical Services España SA.Halifax, Halifax County, Canada
Permanent

Location: Halifax, Nova Scotia, CA, B3B 1E6.Onsite or Hybrid: Senior Test Specialist, Mechanical or Electrical (Permanent) – Halifax, NS.Expected Salary: $80,458 to $98,337.To determine final salar... Show more

 • Promoted

Automation Tester

Aarorn Technologies IncHalifax, Halifax County, Canada
Full-time

Halifax, NS (4x onsite a week).Contract – CAD$45–50 per hour, inclusive.Interview: Face‑to‑face onsite only.Develop and maintain automation test scripts using Python and Robot Framework.Execute aut... Show more

 • Promoted

Security Systems Design Consultant - Buildings

WSP in CanadaDartmouth, Nova Scotia, Canada
Full-time

What if you could redefine what’s possible? With us, you can.We are the home of ambitious, passionate, and innovative world shapers.With an unmatched breadth and depth of engineering, advisory and ... Show more

 • Promoted

Cyber Security Analyst - Halifax

DaviesHalifax, Halifax County, Canada
Full-time

Cyber Security Analyst - Halifax.Application Deadline: 28 November 2025.Department: Risk and Compliance.Reporting to: Lead Cyber Security Engineer.Managing alerts within the group’s security toolin... Show more

 • Promoted

Security Operations Engineer For Breakthrough Research - £60,000 - £70,000 A Year

Leading Educational InstituteHalifax, Canada
Full-time

A leading educational institute in Nova Scotia, Canada is looking for a Security Operations Engineer to join their team.This hands-on role involves enhancing security monitoring and incident respon... Show more

 • Promoted

Fire Protection Systems Designer

StantecDartmouth, NS, CA
Full-time

A leading design firm is looking for an Intermediate Fire Protection Designer in Dartmouth, Nova Scotia.This role involves designing sprinkler, suppression, and fire alarm systems, conducting fire ... Show more

 • Promoted

Survey Taker: Earn up to $25 per survey (Remote)

Earn HausHalifax, NS, CA
Remote
Full-time +1

Looking for people to participate in taking online surveys for Fortune 500 brands.All you need to do is complete online surveys by sharing your opinion.You will help influence brand decisions on se... Show more

 • Promoted

Senior Product Security Engineer – Remote Canada - Equity - $150,000 - $200,000 A Year - Remote

Financial technology companyHalifax, Canada
Remote
Full-time

A financial technology company is looking for a Senior Product Security Engineer to ensure security during product development.This remote position requires a deep understanding of web application ... Show more

 • Promoted

IVVQ Test Specialist - Dartmouth

Aversan IncDartmouth, NS, CA
Full-time

We are currently seeking a qualified IVVQ Test Specialist to join our specialized team.This role is responsible for designing, conducting, and reporting on IVVQ (Integration, Verification, Validati... Show more

 • Promoted

Security Systems Design Consultant - Buildings

WSPHalifax, Halifax County, Canada
Full-time

Security Systems Design Consultant - Buildings.What if you could redefine what’s possible?.We are the home of ambitious, passionate, and innovative world shapers.With an unmatched breadth and depth... Show more

 • Promoted

Geoint Security Engineer - Systems & Devops (Secret) - $70,000 - $93,000 A Year

MDA SpaceHalifax, Canada
Full-time

A technology firm in the space industry seeks an Intermediate Systems Security Engineer to join their Halifax team.The ideal candidate will develop security artefacts, conduct risk assessments, and... Show more

 • Promoted

Automation Tester

Lorven Technologies Inc.Halifax, Halifax County, Canada
Full-time

Location: Halifax (4 days a week on site).Develop and maintain automation test scripts using Python and Robot Framework.Execute automated and manual test cases as required.Identify logs and track d... Show more

 • Promoted

Game Tester - Remote

AlmediaHalifax, Canada
Remote
Full-time

Get paid for testing apps, games and surveys.Almedia runs a dynamic platform where users earn money online by completing tasks, playing games, and filling out surveys.Since our launch 5 years ago, ... Show more

 • Promoted

Security Software Engineer, Infrastructure Security (Staff Or Senior) - C$144,000 - C$200,000 A Year

MongoDBHalifax, Canada
Full-time

We are hiring an experienced Security Software Engineer (Staff or Senior) for our Infrastructure Security team to design and build scalable security controls and services within MongoDB Atlas multi... Show more

 • Promoted

Senior Product Security Engineer – Remote Canada - Equity - $150,000 - $200,000 A Year - Remote

AffirmHalifax, Canada
Remote
Full-time

A financial technology company is looking for a Senior Product Security Engineer to ensure security during product development.This remote position requires a deep understanding of web application ... Show more

 • Promoted

Senior Security Engineer, Cloud Infra - Multi-Cloud - C$144,000 - C$200,000 A Year - Remote

Cloud Database CompanyHalifax, Canada
Remote
Full-time

A leading cloud database company is seeking a Security Software Engineer to enhance security for its multi-cloud infrastructure.This role involves designing scalable security controls, developing a... Show more

 • Promoted

Senior Product Manager, Data Security (Remote) - C$112,000 - C$155,000 A Year - Remote

Database Platform ProviderHalifax, Canada
Remote
Full-time

Drive data security initiatives for a leading database platform provider, partnering with teams to deliver innovative features.Requires 5+ years experience in data security and strong communication... Show more

 • Promoted

Security Operations Engineer - £60,000 - £70,000 A Year

Ellison Institute of TechnologyHalifax, Canada
Full-time

OverviewJoin us at EIT:At the Ellison Institute of Technology (EIT), we’re on a mission to translate scientific discovery into real world impact.We bring together visionary scientists, technologist... Show more

 • Promoted

Security Site Manager

J.D. Irving, LimitedHalifax, Nova Scotia, Canada
Full-time

Job Description Reporting to the Operations Manager of Industrial Security Limited (ISL), the Security Site Manager will lead and oversee 24/7 security operations at the Irving Shipyard Inc (ISI) i... Show more

 • Promoted

Remote Appointment Setter - 60k / Year

Spade RecruitingEast Hants, Nova Scotia
Remote
Full-time
Quick Apply

We’re looking for enthusiastic, self-driven, individuals to assist existing and prospective clients within our organization.This position will work with multiple clients throughout the day pr... Show more