4 months ago
Vancouver, CanadaSenior
Responsibilities
- Drive security operations, incident response coordination, ticket resolution, threat detection, threat intelligence integration, and SIEM tuning.
- Conduct internal penetration tests, vulnerability assessments, red-team exercises, adversary simulations, and structured threat modeling.
- Identify and exploit web application vulnerabilities such as SQL injection and XSS, and manually analyze raw logs for sophisticated or obfuscated attack activity.
- Manage vulnerability and configuration remediation, third-party penetration tests, bug bounty engagements, and emerging risks in cloud-based and agent-based AI architectures.
- Secure cloud, container, CI/CD, SaaS, endpoint, network, DNS, and email environments, including Zero Trust Architecture, DDoS protection, WAF, CDN, DAST, SAST, and SCA controls.
- Use generative AI, scripting, automation, and Infrastructure as Code to scale detection, response, testing, and security documentation.
- Develop incident, attack, defense, tabletop, and purple-team playbooks and mentor junior security personnel.
Requirements
- Degree in information technology, computer science, cybersecurity, or a related field.
- At least 5 years of experience in security analysis, penetration testing, incident response, or a related field.
- Hands-on offensive security experience, including internal penetration testing, red teaming, vulnerability research, and exploitation of common web vulnerabilities.
- Ability to manually interpret raw log and SIEM data and identify sophisticated or obfuscated attacker activity.
- OSCP certification or current progress toward it, or equivalent demonstrated offensive security capability; CISSP, CISM, or GCIH are valued.
- AWS Security Certification or equivalent experience.
- Knowledge of security principles, attacker TTPs, MITRE ATT&CK, OWASP Top 10, network protocols, operating systems, and security misconfigurations.
- Working knowledge of Infrastructure as Code, scripting, automation, and AI assistants for security workflows.
- Familiarity with Kubernetes, Helm, Docker, secure image and dependency management, NIST, ISO 27001, CIS Controls, PCI DSS, GDPR, and structured threat modeling.
- Strong analytical, problem-solving, written, verbal, collaboration, and technical communication skills.
Benefits
- Hiring salary range of $130,000-$160,000 CAD annually, with potential eligibility for a semi-annual bonus program.
- Hybrid schedule requiring attendance at the downtown Vancouver office 1–3 days per week.
- Modern MacBook and Apple equipment, downtown office fitness-center access, work-from-anywhere policy, and generous benefits.
- Extended health and dental benefits, paid time off, savings and retirement plan matching, and parenthood top-up.
- Mentorship programs, leadership series, career development, wellbeing support, stocked cupboards, catered weekly team lunches, and daily coffee runs.