About the role

At Stantec, we have some of the world’s leading professionals passionate about enabling our business to be its best. Our business teams include finance, procurement, human resources, information technology, marketing, corporate development, HSSE, real estate, legal, and practice services. We bring diverse backgrounds, skills, and expertise and create a caring culture where everyone can thrive. Through teamwork and collaboration, we’re building a stronger, more resilient Stantec every day. Your Opportunity The Senior Ethical Hacker will conduct security assessments on web applications and cloud services by emulating real-world attacks using the Mitre Attack Framework. Their goal is to identify security weaknesses, help prevent data breaches and enhance the security posture by uncovering vulnerabilities, misconfigurations, and risks proactively before they are discovered by threat actors.
Your Key Responsibilities: Communication Collaborate with cross-functional teams (security, engineering, cloud and network operations).Create reports and communicate findings to various technical teams, architects and engineers. Create and communicate processes that could help engineering teams meet remediation goals. Create and verbally present your test findings in debrief meetings with the C-Suite or sponsors. Cloud Application Conduct penetration tests on cloud systems, applications and APIs to identify vulnerabilities. Assess cloud/application specific configurations, access controls, and encryption mechanisms. Validate and exploit security findings within web/thick client apps and cloud environments. Validate various app services, databases, Kubernetes, serverless functions, container instances, images and cloud storage blob/buckets for security issues. Project work/Knowledge ShareAssist/Create rules of engagement for new pen test projects. Architect automated workflows for independent security evaluation and assurance processes Establish and enforce security baseline controls through Policy-as-Code implementations Engineer custom Python, Terraform, and Ansible extensions to enable specialized security andinfrastructure use cases Create or populate content in the internal training lab so developers and security champions can staycurrent in offensive security with practical CTF's when time permits. Provide live hacking webinars for teams interested in learning by example. Conduct internal Red Team engagements. Participate in purple team engagements.
Your Capabilities and Credentials: Minimum 5-7+ years working in some aspect of cybersecurity (Offensive Security, Red Team experience preferred).Proficient with manual web/cloud penetration testing without using any tools. Proficient writing custom attack tools in Python, PHP, Golang and Bash Scripting. Proficient with interception proxies and attacking manually via Burp Suite Enterprise tool. Proficient building/maintaining attack automation systems (Commercial or Open-Source).Proficient building containers and automation pipelines for attacking purposes. Experience combining multiple low/medium findings to weaponize and achieve a higher level. Comfortable working exclusively from Windows or Linux command line. Comfortable "living off the land" using VIM/VI/Bash/SH/Perl/VBScript/WMI/PowerShell for postexploitation and lateral movement. Comfortable with writing XSS attacks, System/SQL injection payloads or weaponizing binaries. Comfortable attacking various popular public cloud services in (Azure/AWS/GCP/Oracle).Comfortable presenting audit findings to a small group or C-Suite during debrief meetings. Comfortable taking ownership for testing actions and performing blameless post-mortems. Preference for the following additional Skills/Certifications OffSec Web Expert (OSWE) - Preferred OffSec (OSAI) - PreferredGIAC Web Application Penetration Tester (GWAPT) Burp Suite Certified Practitioner (BSCP) Pentester Academy Cloud Security Professional (PACSP)AI/LLM Penetration testing experience Acknowledged findings in a responsible disclosure or public, private Bug Bounty program. Certified Kubernetes Security Specialist (CKS) Terraform Associate (003) DevSecOps experience
Education and Experience:
  • Minimum 5 years relevant experience.
  • Related Degree or Certificate, preferably in areas of Offensive Security, AI Red Teaming or Application
  • SecurityPay Transparency
In compliance with pay transparency laws, pay ranges are provided for positions in locations where required. Please note, the final agreed upon compensation is based on individual education, qualifications, experience, and work location. At Stantec certain roles are bonus eligible. Actual compensation for part-time roles will be pro-rated based on the agreed number of working hours per week.
Benefits Summary: Regular full-time and part-time employees (working at least 20 hours per week) have access to medical, dental, and vision plans, a wellness program, health saving accounts, flexible spending accounts, 401(k) plan, employee stock purchase program, life and accidental death & dismemberment (AD&D) insurance, short-term/long-term disability plans, emergency travel benefits, tuition reimbursement, professional membership fee coverage and paid family leave. Regular full-time and part-time employees will receive ten paid holidays in each calendar year. In addition, employees will be eligible to accrue vacation between 10 and 20 days per year and eligible for paid sick leave (and if more generous, in accordance with state and local law).Temporary/casual employees have access to 401(k) plans, employee stock purchase program, and paid leave, in accordance with state and local law. The benefits information listed above may not apply to union positions because benefits for such positions are governed by applicable collective bargaining agreements Stantec provides equal employment opportunities to all qualified employees and applicants for future and current employment and prohibit discrimination on the grounds of race, colour, religion, sex, national origin, age, marital status, genetic information, disability, sexual orientation, gender identity or gender expression. We prohibit discrimination in decisions concerning recruitment, hiring, referral, promotion, compensation, fringe benefits, job training, terminations or any other condition of employment. Stantec is in compliance with laws and regulations and ensures equitable opportunities in all aspects of employment. At Stantec we are committed to ensuring our recruitment process is accessible to all. If you require reasonable adjustments to be made during the recruitment process then please inform a member of our Talent Acquisition team.

Matching similar jobs

JOB OVERVIEW

Experience level

Senior

Location

Louisville, KY

Occupation

Penetration Testers

Industry

Computer Systems Design Services

Posted

2 days ago

Tired of running searches?

Rank the roles you'd take once, and matches like these arrive on their own.

CREATE PROFILE