Cybersecurity Penetration Tester

CGI

$95K — $145K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, Computer Science, IT, Engineering, or equivalent experience.
  • Hands-on experience in penetration testing and security assessments.
  • Knowledge of TCP/IP, networking protocols, and operating systems.
  • Experience with Windows and Linux security testing.
  • Familiarity with cloud security concepts and platforms like AWS and Azure.
  • Strong technical documentation and reporting capabilities.
  • Excellent communication skills for both technical and non-technical audiences.

Responsibilities

  • Plan and execute penetration testing engagements across various environments.
  • Conduct vulnerability identification and controlled exploitation to assess security impact.
  • Perform application penetration testing according to OWASP standards.
  • Evaluate security controls across network and cloud infrastructures.
  • Analyze vulnerabilities to assess exploitability and business impact.
  • Develop comprehensive reports detailing findings and remediation actions.
  • Collaborate with teams to support vulnerability remediation and validation.

Benefits

  • Comprehensive health and wellness programs.
  • Professional development opportunities.
  • Collaborative work environment promoting innovation.
  • Flexible work arrangements for better work-life balance.
  • Access to cutting-edge tools and technologies.
Full Job Description
Cybersecurity Penetration Tester

Category: Cyber Security

Main location: Canada, Ontario, Mississauga

Position ID:J0726-1690

Employment Type: Full Time

Position Description:

We are seeking an experienced Penetration Tester / Offensive Security Consultant to assess the security posture of applications, infrastructure, cloud environments, and network systems through authorized penetration testing and security assessments. The successful candidate will identify exploitable vulnerabilities, evaluate potential business impact, and provide actionable remediation recommendations to strengthen the organization's overall security posture.
The role requires strong hands-on technical expertise, an understanding of modern attack techniques, and the ability to communicate complex security findings clearly to both technical and non-technical stakeholders.

Your future duties and responsibilities:

Penetration Testing & Security Assessments
• Plan and execute authorized penetration testing engagements across internal and external environments.
• Conduct network, infrastructure, web application, API, wireless, and cloud security testing, as required.
• Perform vulnerability identification, validation, and controlled exploitation to assess potential security impact.
• Assess authentication, authorization, session management, access controls, and security configurations.
• Identify vulnerabilities arising from misconfigurations, insecure implementations, weak security controls, and architectural weaknesses.
• Evaluate security controls designed to prevent, detect, and respond to potential attacks.
• Perform manual testing to validate automated vulnerability scanning results and identify vulnerabilities that automated tools may not detect.
Application & API Security
• Conduct penetration testing of web and mobile applications and APIs.
• Assess applications against recognized security standards and methodologies, including OWASP Top 10 and OWASP API Security Top 10.
• Evaluate common application security risks, including injection vulnerabilities, broken access controls, authentication weaknesses, insecure configurations, and business logic vulnerabilities.
• Review application attack surfaces and identify potential pathways that could lead to unauthorized access or data exposure.
Infrastructure & Cloud Security
Perform security assessments of internal and external network infrastructure.
• Evaluate operating systems, network devices, security appliances, and exposed services.
• Conduct penetration testing of cloud environments, where authorized, including Microsoft Azure, AWS, and Google Cloud Platform.
• Assess identity and access management configurations, cloud permissions, exposed resources, and potential privilege escalation paths.
• Evaluate Active Directory and enterprise identity environments for security weaknesses and potential attack paths.
Vulnerability Analysis & Risk Assessment
• Analyze identified vulnerabilities to determine exploitability, severity, and potential business impact.
• Prioritize findings based on technical risk, business context, and likelihood of exploitation.
• Apply industry-standard vulnerability scoring methodologies, including CVSS, where appropriate.
• Research emerging vulnerabilities, attack techniques, and threat trends relevant to the organization's technology environment.
Reporting & Remediation
• Develop clear and comprehensive penetration testing reports documenting methodology, findings, evidence, risk ratings, business impact, and recommended remediation actions.
• Provide executive-level summaries for senior management and detailed technical findings for security and technology teams.
• Present penetration testing results to technical teams, application owners, security leadership, and other stakeholders.
• Collaborate with infrastructure, application, cloud, and cybersecurity teams to support vulnerability remediation.
• Perform remediation validation and retesting to confirm that identified vulnerabilities have been effectively addressed.

Governance & Testing Standards
• Conduct all penetration testing activities within formally approved Rules of Engagement (ROE) and defined scope.
• Ensure testing activities are performed safely and minimize the risk of disruption to production systems.
• Maintain accurate documentation of testing activities, evidence, findings, and remediation status.
• Follow established penetration testing methodologies and industry standards, such as PTES, OWASP Testing Guide, NIST guidance, and relevant security frameworks.
• Support continuous improvement of penetration testing methodologies, processes, tools, and reporting standards.

Required qualifications to be successful in this role:
• Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline, or equivalent practical experience.
• Demonstrated experience conducting hands-on penetration testing and security assessments. Strong knowledge of TCP/IP, networking protocols, operating systems, web technologies, APIs, and enterprise infrastructure.
• Experience with Windows and Linux security testing. Understanding of Active Directory, identity and access management, authentication protocols, and privilege escalation techniques.
• Knowledge of web applications and API security vulnerabilities and OWASP methodologies.
• Familiarity with cloud security concepts and major cloud platforms.
• Ability to analyze technical vulnerabilities and translate findings into business risk.
• Strong technical documentation and report-writing skills.
• Excellent verbal and written communication skills.
• Ability to work independently and collaboratively with technical and business stakeholders.

CGI is providing a reasonable estimate of the pay range for this role. The determination of this range includes factors such as skill set level, geographic market, experience and training, and licenses and certifications. Compensation decisions depend on the facts and circumstances of each case. A reasonable estimate of the current range is $95,000-$145,000. This role is an existing vacancy.

#LI-YK2

Skills:
  • Cyber
  • English
  • Offensive Security Cert Prof
  • Offensive Security Cert Prof
  • Penetration Testing
  • Security assessment
  • Security Testing
  • Vulnerability Testing (IAVT)


Similar Jobs

More Jobs at CGI

More Information Technology Jobs

Find similar Cybersecurity Penetration Tester jobs: