Talent.com
Malleum
Remote Penetration Tester - Offensive SecurityMalleum • Stouffville, Ontario
Remote Penetration Tester - Offensive Security

Remote Penetration Tester - Offensive Security

Malleum • Stouffville, Ontario
30+ days ago
Job type
  • Full-time
  • Remote
Job description

Location: Hybrid / On-site at client locations as required
Department: Offensive Security & Adversary Simulation

About MalleumMalleum is at the forefront of next-generation cyber defense, partnering with marquee clients across space, aerospace, defense, government, financial services, and critical infrastructure. We're experiencing exceptional growth as demand accelerates for trusted advisors capable of delivering at the intersection of national security, allied intelligence cooperation, and enterprise resilience. Our offensive security consultants test the systems behind cutting-edge defensive technologies, sovereign space capabilities, and allied programs - finding the gaps before adversaries do, on networks that protect missions of genuine national consequence.

If you take pride in breaking things ethically - and helping the most consequential organizations build back stronger - Malleum is where your craft meets purpose.

The Opportunity

We're seeking a Penetration Tester to deliver hands-on offensive security engagements across client networks, applications, cloud environments, and operational technology. You'll work directly within client environments - including sovereign, regulated, and cleared settings - emulating real-world adversaries, documenting findings, and partnering with clients to drive meaningful remediation.

This is a hands-on consulting role for a practitioner who blends deep technical tradecraft with strong client presence and the discipline to deliver findings clearly, safely, and on schedule.

What You'll Do

  • Plan, scope, and execute penetration tests across external, internal, web application, API, mobile, cloud (Azure / AWS / GCP), wireless, and Active Directory targets
  • Conduct red team and adversary emulation engagements aligned to MITRE ATT&CK, executing realistic TTPs against client environments
  • Perform assumed-breach assessments, internal pivoting, privilege escalation, and lateral movement exercises
  • Support purple team exercises in partnership with client SOC and Malleum's IR practice to improve detection and response
  • Execute social engineering campaigns (phishing, vishing, physical) where contracted, with rigorous rules of engagement
  • Conduct cloud configuration reviews against CIS Benchmarks, CSA CCM, and provider-specific baselines
  • Support OT / ICS / SCADA security testing for defense and critical-infrastructure clients (with appropriate safety controls)
  • Develop custom tooling, scripts, and payloads (PowerShell, Python, C#, Go) to evade modern EDR and ZTNA controls during sanctioned engagements
  • Produce high-quality client deliverables: executive summaries, technical findings, reproduction steps, evidence, CVSS-scored risk ratings, and pragmatic remediation guidance
  • Deliver findings briefings to client stakeholders — from engineers to executive leadership and boards - with clarity and professionalism
  • Contribute to scoping, estimation, statements of work, and continuous improvement of Malleum's offensive security service offerings
  • Maintain meticulous engagement hygiene: rules of engagement, scope control, evidence handling, and safe-listing coordination
  • Participate in research, internal tooling development, CTFs, and conference contributions to grow Malleum's offensive capability and brand
What You Bring
  • 4+ years of professional penetration testing or red team experience, ideally in a consulting, MSSP, or in-house offensive security team
  • Demonstrated success working directly with clients - strong communication, professionalism, and stakeholder management skills
  • Deep working knowledge of network, web application, and Active Directory attack paths (Kerberoasting, AS-REP roasting, NTLM relay, ADCS abuse, BloodHound-driven pathing)
  • Hands-on proficiency with offensive tooling: Burp Suite Pro, Nmap, Nessus / Nuclei, Metasploit, Cobalt Strike, Sliver, Mythic, Impacket, BloodHound, CrackMapExec / NetExec, Responder, Mimikatz, and modern C2 frameworks
  • Strong scripting skills in Python, PowerShell, and Bash; comfort reading and modifying C#, Go, or Rust tooling
  • Experience evading or bypassing EDR (Defender, CrowdStrike, SentinelOne), AMSI, and modern Windows defenses
  • Familiarity with cloud attack paths in Azure / Entra ID (Pass-the-PRT, illicit consent grants, managed identity abuse) and AWS (IAM privilege escalation, metadata service abuse)
  • Solid grasp of ZTNA and identity-aware perimeters (e.g., Cloudflare Access, Zscaler, Entra Conditional Access) and how they reshape attacker tradecraft
  • Comfort emulating adversary TTPs mapped to MITRE ATT&CK and known threat-actor playbooks
  • Familiarity with testing standards: PTES, OWASP WSTG / MASTG / ASVS, NIST SP 800-115, OSSTMM
  • Awareness of compliance contexts that frame client expectations: PCI DSS, SOC 2, NIST 800-171 / CMMC, CPCSC, ITSG-33, ISO 27001:2022
  • Certifications such as OSCP, OSEP, OSWE, OSCE3, CRTO, CRTL, GPEN, GXPN, GWAPT, GMOB, GCSA / GPCS / GCLD (cloud), AWS Certified Security – Specialty, Microsoft SC-100 / AZ-500 strongly preferred; OSCP or equivalent practical certification (e.g., CRTO, HTB CPTS, PNPT) is a baseline expectation
  • Demonstrated ability to perform under pressure - calm, methodical, and ethical when engagements surface sensitive findings
  • Willingness and availability to work odd hours and extended shifts when supporting time-boxed red team windows, after-hours testing, or rapid-response offensive support during active IR matters
  • Comfort working across multiple client environments, tooling stacks, and rules-of-engagement simultaneously
  • Eligibility for Government of Canada security clearance (Secret or higher); existing clearance highly valued; or controlled-goods registration considered an asset
  • Bilingualism (English/French) considered a strong asset

Why Malleum

  • Test the systems behind programs with genuine national and allied security impact - across aerospace, defense, and critical infrastructure
  • Join a rapidly scaling firm with a flat, high-trust culture and direct access to senior offensive, IR, and engineering leaders
  • Exposure to a wide variety of advanced targets, sectors, and cleared environments
  • Dedicated research time, lab budget, and support for conference talks, CVE research, and open-source contributions
  • Competitive compensation, performance incentives, and comprehensive benefits
  • Continuous learning budget, certification sponsorship (OSCP, OSEP, OSWE, CRTL, SANS), and clear paths into senior red team, exploit development, or offensive research specializations

Malleum is an equal opportunity employer. We welcome applications from all qualified candidates and are committed to building a team that reflects the communities and missions we serve.

We are proud to accommodate individuals with disabilities throughout the recruitment and selection process. Please indicate your need for accommodations in your application.

Create a job alert for this search

Remote Penetration Tester - Offensive Security • Stouffville, Ontario

Similar jobs

Penetration Testing Expert At Netspi

NetSPIToronto, Canada
Full-time

Advance your cybersecurity career with NetSPI as a Penetration Testing Expert.Engage in web application assessments and deliver critical security insights for clients.This Senior Security Consultan... Show more

 • Promoted

Senior Security Engineer (Pen Tester) - C$120,000 - C$210,000 A Year

Menlo SecurityNorth York, Canada
Full-time

Seeking a Security Engineer focused on offensive and defensive security, product penetration testing, and cloud architecture in a multi-cloud environment.Responsibilities include infrastructure rev... Show more

 • Promoted

Security Engineer (Detection & Response)

Robinhoodtoronto, on, Canada
Full-time

Join us in building the future of finance.Our mission is to democratize finance for all.An estimated $124 trillion of assets will be inherited by younger generations in the next two decades.The lar... Show more

 • Promoted

Data Entry Clerk (Remote) - Paid Product Testing Survey Taker

ApexFocusGroupRichmond Hill
CA$850.00 weekly
Remote
Full-time +1

Now accepting applicants for Focus Group studies.Earn up to $850 per week part-time working from home.Must register to see if you qualify.No Data Entry experience needed.Data Entry Clerk Work From ... Show more

 • Promoted

Senior Malware Protection Specialist (Trellix) – Remote

act digitalToronto, ON, CA
Remote
Full-time

A consulting and technology expertise company is seeking an experienced Senior IT and Security Administrator specializing in Malware Protection technologies.The ideal candidate will have a strong b... Show more

 • Promoted

Join Evertz as a Security Developer

Evertz Microsystems LimitedMarkham, ON, CA
Full-time

Be a part of Evertz in Markham, Ontario, as a Security Software Developer, where you'll play a key role in advancing product security standards.Focus on CI/CD tools and the development of security ... Show more

 • Promoted

Penetration Tester: Web & Network Security Expert - C$96,900 - C$136,800 Par An

Institution Financière MajeureToronto County, Canada
Full-time

Spécialiste en sécurité informatique recherché à Toronto pour tester les vulnérabilités et évaluer les risques au sein d'une institution financière.L'expertise en réseaux et web est essenti... Show more

 • Promoted

Survey Taker: Earn up to $25 per survey (Remote)

Earn HausGeorgina, ON, CA
Remote
Full-time +1

Looking for people to participate in taking online surveys for Fortune 500 brands.All you need to do is complete online surveys by sharing your opinion.You will help influence brand decisions on se... Show more

 • Promoted

Remote Security Software Engineer (Go) - App & Privacy

TailscaleToronto, ON, CA
Remote
Full-time

A cutting-edge tech company in Canada is seeking a skilled Software Engineer specializing in security and privacy.The role involves improving security properties by implementing features, auditing ... Show more

 • Promoted

Flexible Remote Product Tester Role

FreelanceshopToronto, ON, CA
Remote
Part-time

Explore a flexible remote work role as a Product Tester with Insight Consumer Research.This entry-level job involves providing feedback on consumer goods from the comfort of your home.You'll partic... Show more

 • Promoted

Offensive Security - Penetration Tester

RSM CanadaToronto, Ontario, Canada
Full-time

We are the leading provider of professional services to the middle market globally, our purpose is to instill confidence in a world of change, empowering our clients and people to realize their ful... Show more

 • Promoted

Staff Security Engineer — Remote, Bitcoin Salary Option

Crypto Pro NetworkToronto, ON, CA
Remote
Full-time

A leading fintech company in Montreal is seeking a Staff Security Engineer to safeguard its infrastructure and customer data.The successful candidate will design security solutions, conduct threat ... Show more

 • Promoted

Senior QA Tester - Mobile & Web (Remote, Contract)

Raas InfotekToronto, ON, CA
Remote
Full-time

An established industry player is seeking a skilled Software Tester to join their Quality Assurance team.In this role, you will be responsible for conducting thorough manual testing of web, iOS, an... Show more

 • Promoted

IVVQ Test Specialist: Shipyard & Field Tests

ThalesToronto, ON, CA
Full-time

A leading defense and security company is seeking an IVVQ Test Specialist based in North Vancouver.This role involves planning and executing test events, writing test plans, and analyzing requireme... Show more

 • Promoted

Remote Mainframe Security Specialist – Risk & Compliance

Flip retailToronto, ON, CA
Remote
Full-time

A leading security consulting firm is seeking a Security Specialist remotely to ensure compliance with safety protocols.The role requires strong skills in interpreting protection plans, evaluating ... Show more

 • Promoted

Sr. Quality Assurance Developer (Performance Testing)

OpenTextrichmond hill, york region, Canada
Full-time

We’re seeking a passionate and enthusiastic Senior QA Developer to join our dynamic development team, with members based in Canada and India.This role is ideal for someone who thrives on designing,... Show more

 • Promoted

Senior SOX Controls Tester (Remote Canada)

Insight GlobalToronto, ON, CA
Remote
Full-time

A leading staffing firm is seeking a seasoned Financial Controls Tester to support SOX compliance efforts for a client in Western Canada.This remote role focuses on executing internal controls test... Show more

 • Promoted

Cyber Security Architect

Intuitive.aiToronto, ON, CA
Full-time

Talent Acquisition Leader | Hiring Cloud Professionals Globally.Cloud is one of the fastest-growing (INC 5000, CRN) Cloud & SDx solution and services companies supporting enterprise customers on a ... Show more

 • Promoted

Web & Api Security Engineer (Penetration Testing) - C$100,000 - C$150,000 A Year

Tata Consultancy ServicesToronto County, Canada
Full-time

Application Security Engineer to perform penetration testing on web applications and APIs, reporting vulnerabilities and providing remediation advice. Show more

 • Promoted

Senior Penetration Tester, Android Security - $158,800 - $218,100 A Year

Samsung Research AmericaNorth York, Canada
Full-time

Senior Penetration Tester to conduct simulated attacks, assess vulnerabilities, and test security of Android platform, apps, APIs, and cloud services. Show more