Senior Cybersecurity Test Engineer (35651)
- Ottawa, ON
- Sur place
- Publié 24 sept. 2026
- 1 poste
Ouvre un site externe
- Type d’emploi
- Contrat
- Niveau d’expérience
- Chef d’équipe · 10+ ans
- Postuler avant le
- 20 oct. 2026
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
- Niveau d’expérience
- Mid-Senior level
Résumé du poste
Lead and execute comprehensive security testing across applications, cloud environments, APIs, and infrastructure to identify vulnerabilities. Collaborate with cross-functional teams to integrate security testing into the SDLC and DevSecOps processes.
Détails du poste
Role Overview We are seeking a Senior Cybersecurity Test Engineer to lead and execute security testing activities across applications, infrastructure, cloud environments, APIs, and system integrations. This role is responsible for designing, implementing, and performing comprehensive security testing to identify vulnerabilities, validate security controls, and ensure organizational security requirements are effectively met. The successful candidate will collaborate closely with cybersecurity, development, infrastructure, and cloud teams to integrate security testing throughout the system development lifecycle. Key Responsibilities Plan, design, and execute security testing activities across applications, infrastructure, cloud environments, APIs, and system integrations. Develop and execute threat-based security test scenarios using methodologies such as STRIDE, MITRE ATT&CK, and OWASP testing approaches. Perform security testing and validation for: Identity and Access Management (IAM) APIs and microservices Data flows and system integrations Cloud environments Applications and infrastructure Conduct manual and automated security testing, including vulnerability assessments and security control validation. Execute application security testing, API security testing, cloud security testing, and infrastructure security assessments. Identify, document, and report vulnerabilities, security gaps, and control weaknesses, and provide remediation recommendations. Validate remediation efforts through retesting and verification activities. Develop and maintain reusable security test cases, scripts, automation frameworks, and testing procedures. Support security risk assessments, investigations, incident reviews, and security-related escalations. Collaborate with development, cloud, infrastructure, architecture, and cybersecurity teams to integrate security testing throughout the SDLC and DevSecOps processes. Generate security testing reports, technical findings, risk assessments, and testing metrics for stakeholders. Contribute to the development and continuous improvement of security testing standards, procedures, and best practices. Mentor junior security testers and provide guidance on security testing methodologies and tools. Required Skills & Experience 8+ years of experience in cybersecurity testing, security engineering, application security, penetration testing, or related disciplines. Strong hands-on experience executing security testing across applications, infrastructure, cloud environments, and integrations. Experience with threat modeling methodologies such as STRIDE, MITRE ATT&CK, OWASP Threat Modeling, or equivalent frameworks. Strong knowledge of cloud security testing within AWS, Azure, and/or GCP environments. Experience testing APIs, identity platforms, IAM solutions, authentication mechanisms, and authorization controls. Strong understanding of application, infrastructure, network, and integration security principles. Experience with security testing tools, vulnerability scanning, and automated testing frameworks. Hands-on experience performing vulnerability assessments, security control validation, and remediation testing. Knowledge of security requirements, controls, risk management principles, and compliance frameworks. Strong analytical, troubleshooting, and investigative skills. Excellent technical documentation, reporting, and communication skills. Ability to work effectively with developers, architects, engineers, and cybersecurity stakeholders. Preferred Qualifications Experience integrating security testing into CI/CD pipelines and DevSecOps environments. Experience with dynamic application security testing (DAST), static application security testing (SAST), software composition analysis (SCA), and container security testing. Knowledge of security testing tools such as Burp Suite, OWASP ZAP, Nessus, Qualys, Fortify, Checkmarx, Veracode, or similar solutions. Experience testing containerized and Kubernetes-based environments. Familiarity with security frameworks and standards such as NIST, ISO 27001, CIS Controls, OWASP, and PCI-DSS. Relevant certifications such as OSCP, CISSP, GIAC, CEH, GWAPT, GPEN, Security+, or cloud security certifications would be considered an asset. ,
Ce que vous ferez
Lead and execute comprehensive security testing across applications, cloud environments, APIs, and infrastructure to identify vulnerabilities. Collaborate with cross-functional teams to integrate security testing into the SDLC and DevSecOps processes.
Exigences
Requires 8+ years of experience in cybersecurity testing with strong expertise in threat modeling and cloud security (AWS, Azure, or GCP). Proficiency in API security, IAM solutions, and vulnerability scanning tools is essential.
Compétences indiquées
- Technical Documentation · Souhaitée
- Risk Management · Souhaitée
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Cybersecurity Testing
- Penetration Testing
- Threat Modeling
- Cloud Security
- API Security
- Identity and Access Management
- Vulnerability Assessment
- DevSecOps
- STRIDE
- MITRE ATT&CK
- OWASP
- Security Control Validation
- Infrastructure Security
- Automation Frameworks
- Risk Management
- Technical Documentation
Domaines d’emploi
- Security & Safety
- Technology
- Software
- Engineering
- Consulting
D’autres postes auxquels postuler directement
Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.
The Properties Group Management Ltd.
Real Estate Law Clerk
CommanditéEmployeur directCandidature simplifiée- Sur place
- Ottawa, ON
- Publié 24 sept. 2026
Desjardins
Spécialiste en assurance qualité TI - R2611533
Employeur directCandidature simplifiée- Hybride
- montreal levis shawinigan, QC
- Publié 23 sept. 2026
Desjardins
Emplois en gestion de projets TI - R2611532
Employeur directCandidature simplifiée- Hybride
- Montréal, QC
- Publié 23 sept. 2026