Retour à la recherche
S
SuncorSource d’offres vérifiée

Web Application Pentester

Offre en anglais

Plan and execute manual penetration tests against web applications and APIs to identify and remediate security vulnerabilities. Partner with development teams to drive secure design decisions and coach secure development practices throughout the SDLC.

  • Sur place
  • Calgary, AB
  • Publié 20 août 2026
  • Postuler avant le 4 sept. 2026
  • 1 poste

D’autres postes auxquels postuler directement

Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.

Résumé du poste

At Suncor, we produce and provide energy. When you join Suncor, you become part of a company that has built a solid foundation for both business and employee success. We are a place where talented people thrive. As part of our team, you play a vital role in delivering energy we all rely on, and you'll make a meaningful impact in the communities where we live and work. We are seeking a hands-on Web Application Pentester who is passionate about working directly with developers to eliminate vulnerabilities at the source. Sitting within our Cyber Defense organization, you will find, explain, and help fix security weaknesses in the applications and APIs that run our business, with periodic opportunities to join red and purple team engagements. What we offer: We recognize your contribution and offer a range of rewards and development opportunities designed to support your success. Benefits/perks listed below may vary depending on the nature of your employment with Suncor and the region where you work. Strong compensation: we offer competitive compensation, regional-based uplifts, annual bonuses, and long-term financial rewards. We also help you save for your future by offering pension programs, and savings plans with company matching Benefits: utilize an employee assistance program and comprehensive company-paid health, dental, and vision benefits for you and your family to support your mental, physical, and financial well-being Generous time-off: enjoy generous paid vacation time and personal time-off to recharge and maintain a healthy work-life balance Talent development programs: Internal mobility, succession planning, and employee training and development programs are just a few ways we’re dedicated to your development Minimum Requirements: 7+ years in cybersecurity, including 5+ years of hands-on manual testing of modern web applications and APIs Bachelor's degree in cyber security, information technology, computer science, or a related field Demonstrated experience working directly with development teams to drive remediation and secure design decisions Hands-on skill with Burp Suite or equivalent, REST and microservice API testing, threat modelling, and secure code review in Java, .NET, or JavaScript/TypeScript Strong grounding in OWASP Top 10, ASVS, and the Cheat Sheet Series; SDLC and DevSecOps practices; server-side authorization and IAM; and modern authentication protocols (OAuth 2.0, OIDC, SAML) Excellent written and verbal communication, with the ability to explain risk to both engineers and executives Experience supporting red or purple team engagements, securing OT/ICS environments, or leveraging AI to enhance secure code review, threat modelling, and vulnerability discovery is considered a strong asset Don’t have all the qualifications listed? That’s ok! Apply anyway. We acknowledge the value of transferable skills. Responsibilities: Plan and execute manual penetration tests against web applications and APIs, surfacing business logic flaws, broken access control, injection, and authentication and session weaknesses aligned to OWASP Top 10 and ASVS Build safe proof-of-concept exploits that demonstrate real impact without disrupting operations, and retest fixes to confirm they hold Test authentication and authorization implementations, including OAuth 2.0, OIDC, SAML, and token-based API access Lead secure design reviews, threat modelling sessions, and source code reviews, recommending secure patterns and reusable controls Partner with development teams to triage findings, agree on practical fixes, and coach secure development practices across the SDLC Support pipeline security tooling (SAST, DAST, SCA, and Infrastructure-as-Code scanning) and help teams tune out noise Contribute application-layer attack paths to red team campaigns and purple team exercises with SOC and detection engineering Produce reports that pair developer-ready detail with concise executive impact summaries, and translate findings into actionable backlog items with reproduction steps, severity, and acceptance criteria Location and other Key Details: This is an office-based role. You will work out of our Calgary head office, located in the Suncor Energy Centre at 150 – 6th Ave S.W Hours of work are a regular 40-hour work week, Monday to Friday with occasional site visits Our business professional roles follow internal compensation guidelines, and the pay band will generally be based on years of experience and scope of work Think we are a fit? Apply now! Suncor is committed to providing equal opportunities for employment and building an inclusive, results-oriented and high-performance culture where all members of our team feel safe, valued and respected.

Ce que vous ferez

Plan and execute manual penetration tests against web applications and APIs to identify and remediate security vulnerabilities. Partner with development teams to drive secure design decisions and coach secure development practices throughout the SDLC.

Exigences

Requires 7+ years in cybersecurity with at least 5 years of hands-on manual testing experience for web applications and APIs. Candidates must hold a bachelor's degree in a related field and possess strong technical proficiency in security testing tools and protocols.

Avantages

• Competitive compensation • Annual bonuses • Long-term financial rewards • Pension programs • Savings plans with company matching • Employee assistance program • Health benefits • Dental benefits • Vision benefits • Paid vacation time • Personal time-off • Internal mobility • Succession planning • Employee training and development programs

Compétences indiquées

  • JavaScriptSouhaitée
  • TypeScriptSouhaitée
  • .NETSouhaitée
  • JavaSouhaitée

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • Web application penetration testing
  • API security
  • Burp Suite
  • Threat modelling
  • Secure code review
  • Java
  • .NET
  • JavaScript
  • TypeScript
  • OWASP Top 10
  • OAuth 2.0
  • OIDC
  • SAML
  • DevSecOps
  • IAM
  • Vulnerability discovery
  • Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Cyber Defense
  • Time Off Management
  • Talent Development
  • Infrastructure as Code (IaC)
  • API Testing
  • Java (Programming Language)
  • JavaScript (Programming Language)
  • .NET Framework
  • Access Controls
  • Application Programming Interface (API)
  • Artificial Intelligence
  • Application Layers
  • Business Logic
  • Penetration Testing
  • Authentications
  • Authentication Protocols
  • Code Review
  • Computer Science
  • Information Technology
  • Training And Development
  • Cyber Security
  • Employee Assistance Programs
  • Manual Testing
  • OAuth
  • Operations
  • Open Web Application Security Project (OWASP)
  • Systems Development Life Cycle
  • Security Assertion Markup Language (SAML)
  • Server-Side
  • Succession Planning
  • Threat Modeling
  • Tooling

Domaines d’emploi

  • Technology
  • Security & Safety
  • Software
  • Energy
  • Engineering
  • Application Penetration Tester
  • Software QA Engineer / Tester
  • Software and Applications Developers and Analysts Not Elsewhere Classified
  • Software Quality Assurance Analysts and Testers

Renseignements supplémentaires

Formation minimale
Baccalauréat
Expérience minimale
5+ ans
Postuler avant le
4 sept. 2026
Langue de l’offre
anglais
Heures de travail
40 heures par semaine