Summary
β¨ AIβGenerated
A cybersecurity services provider is seeking a Penetration Tester to assess and strengthen the security of mission-critical applications. You will conduct code reviews and web, mobile, and network penetration tests, contribute to security design reviews and threat modeling, and provide actionable remediation recommendations. This is a permanent, full-time remote role open to candidates located in Canada.
Highlights
Fully remote, permanent full-time employment with the opportunity to secure mission-critical applications for a diverse client base. Gain exposure to web, mobile, and network security, threat modeling, secure development, and recognized compliance frameworks.
Description
Software Secured is a leading Penetration Testing as a Service (PTaaS) company, with a head office in beautiful Ottawa, Canada.
We help software development teams get ahead of hackers, using a suite of cybersecurity services and products.
Software Secured focuses on helping startups, scaleups, and SMBs comply with industry-specific Governance, Risk and Compliance frameworks (SOC 2, ISO27001 & PCI DSS, HIPAA, etc), prove security maturity to enterprise buyers with stringent security requirements and gain peace of mind that their most sensitive company assets have been secured.
βThe Role
As a Penetration Tester at Software Secured, you will have the opportunity to help our clients secure their mission-critical applications.
This includes performing security code review, web, mobile, and network security tests.
Help clients with security design reviews, threat modelling, and remediation strategies.
This is a remote, full-time permanent role.
However, you must be located in Canada, either a Canadian citizen or a PR holder.
What You'll Do
Run manual penetration tests across web applications, APIs, mobile apps, and network infrastructure β from scoping through testing, reporting, client readout, and retestProduce findings that are manually confirmed and exploitable, with remediation guidance a developer can act on without a follow-up callHandle nuanced test cases beyond the standard checklist: business logic flaws, authorization edge cases, vulnerability chaining, and environment-specific attack pathsPresent findings directly to client engineering teams and security leads β explaining what was found, why it matters, and how to fix itContribute to security design reviews and threat modelling engagements earlier in the SDLCMentor junior testers on test execution and report quality; contribute to methodology improvements, tooling, and internal playbooksDevelop domain depth in one or more service areas (web, network, mobile, code review) through our Domain Expertise Program β with formal recognition and stipend for engineers who build expertise that makes the whole team stronger
What We're Looking For
2+ years of hands-on manual penetration testing β not scanner-assisted, manualDemonstrated ability to run standard engagements end-to-end with minimal oversight: scope, test, report, readout, retestFinds that go beyond OWASP Top 10 basics β business logic issues, complex auth flaws, chained vulnerabilitiesReports that are client-ready with low rework: technically accurate, clearly written, correctly risk-ratedSoftware development background in one or more of Python, .NET, Ruby, or Java β you understand how the thing was built, not just how to break itStrong communication skills in both directions: writing that doesn't require a translator and calls where you can hold your own in front of an engineering teamLocated in Canada and eligible to work (citizen, permanent resident, or valid work visa)
Nice to Have
OSCP, OSCP+, or GWAPTExperience across multiple service areas (web + mobile, or web + network)Familiarity with compliance frameworks that drive our clients' security programs: SOC 2, ISO 27001, PCI DSS, HIPAA
What we are offering:
π€ Competitive base salary
π Work remotely from anywhere in Canada (you're welcome to work in the Ottawa office when you prefer).
π Work remotely from anywhere in the world for up to 2 months per year.
π° Yearly profit-sharing between 5 - 12% of your base salary, based on your performance.
πΈ Perks such as: monthly UberEats budget, annual home office stipend.
π΄ 3 weeks of vacation to start.
Additionally, the whole company is off for the week between Christmas and the New Year.
πΌ Parental, bereavement and child loss leave.
π₯ You will receive a comprehensive health benefits package (including dental, vision, and practitioner coverage, among others).