5-7+ years in cybersecurity, preferably with Red Team experience.
Expertise in manual web/cloud penetration testing without tools.
Skilled in writing custom attack tools using Python, PHP, Golang, and Bash.
Proficient with Burp Suite Enterprise for manual attacks.
Experience in building attack automation systems and pipelines.
Comfortable with command line operations in Windows or Linux.
Familiar with exploiting vulnerabilities like XSS and SQL injection.
Responsibilities
Conduct security assessments on web applications and cloud services.
Collaborate with cross-functional teams to enhance security measures.
Create detailed reports and communicate findings to technical teams.
Perform penetration tests on cloud systems and APIs to identify vulnerabilities.
Architect automated workflows for security evaluations and assurance processes.
Engage in internal Red Team and purple team activities.
Provide training and live hacking webinars for team development.
Benefits
Opportunities for professional development and certifications.
Access to internal training labs for skill enhancement.
Collaborative work environment with cross-functional teams.
Engagement in innovative security projects and methodologies.
Full Job Description
Job Description
Your Opportunity
The Senior Ethical Hacker will conduct security assessments on web applications and cloud services by emulating real-world attacks using the Mitre Attack Framework. Their goal is to identify security weaknesses, help prevent data breaches and enhance the security posture by uncovering vulnerabilities, misconfigurations, and risks proactively before they are discovered by threat actors.
Your Key Responsibilities
Communication
Collaborate with cross-functional teams (security, engineering, cloud and network operations).
Create reports and communicate findings to various technical teams, architects and engineers.
Create and communicate processes that could help engineering teams meet remediation goals.
Create and verbally present your test findings in debrief meetings with the C-Suite or sponsors.
Cloud Application
Conduct penetration tests on cloud systems, applications and APIs to identify vulnerabilities.
Assess cloud/application specific configurations, access controls, and encryption mechanisms.
Validate and exploit security findings within web/thick client apps and cloud environments.
Validate various app services, databases, Kubernetes, serverless functions, container instances,
images and cloud storage blob/buckets for security issues.
Project work/Knowledge Share
Assist/Create rules of engagement for new pen test projects.
Architect automated workflows for independent security evaluation and assurance processes
Establish and enforce security baseline controls through Policy-as-Code implementations
Engineer custom Python, Terraform, and Ansible extensions to enable specialized security and
infrastructure use cases
Create or populate content in the internal training lab so developers and security champions can stay
current in offensive security with practical CTF's when time permits.
Provide live hacking webinars for teams interested in learning by example.
Conduct internal Red Team engagements.
Participate in purple team engagements.
Qualifications
Your Capabilities and Credentials
Minimum 5-7+ years working in some aspect of cybersecurity (Offensive Security, Red Team
experience preferred).
Proficient with manual web/cloud penetration testing without using any tools.
Proficient writing custom attack tools in Python, PHP, Golang and Bash Scripting.
Proficient with interception proxies and attacking manually via Burp Suite Enterprise tool.
Proficient building/maintaining attack automation systems (Commercial or Open-Source).
Proficient building containers and automation pipelines for attacking purposes.
Experience combining multiple low/medium findings to weaponize and achieve a higher level.
Comfortable working exclusively from Windows or Linux command line.
Comfortable "living off the land" using VIM/VI/Bash/SH/Perl/VBScript/WMI/PowerShell for post
exploitation and lateral movement.
Comfortable with writing XSS attacks, System/SQL injection payloads or weaponizing binaries.
Comfortable attacking various popular public cloud services in (Azure/AWS/GCP/Oracle).
Comfortable presenting audit findings to a small group or C-Suite during debrief meetings.
Comfortable taking ownership for testing actions and performing blameless post-mortems.
Preference for the following additional Skills/Certifications
OffSec Web Expert (OSWE) - Preferred
OffSec (OSAI) - Preferred
GIAC Web Application Penetration Tester (GWAPT)
Burp Suite Certified Practitioner (BSCP)
Pentester Academy Cloud Security Professional (PACSP)
AI/LLM Penetration testing experience
Acknowledged findings in a responsible disclosure or public, private Bug Bounty program.
Certified Kubernetes Security Specialist (CKS)
Terraform Associate (003)
DevSecOps experience
Education and Experience
Minimum 5 years relevant experience.
Related Degree or Certificate, preferably in areas of Offensive Security, AI Red Teaming or Application
Security
About Stantec
Stantec Inc. is a global engineering consulting firm headquartered in Edmonton, Alberta, Canada. The company provides professional consulting services in the areas of infrastructure, water, environment, buildings, and energy. Stantec has over 22,000 employees working in more than 400 locations across six continents. The company has a diverse client base that includes public and private sector clients. Stantec is committed to sustainability and has implemented green practices in its operations. The company has received numerous awards for its work, including the American Council of Engineering Companies' National Recognition Award for exemplary engineering achievement.