Principal Consultant - Cybersecurity
Offre en anglaisThe role involves performing high-level offensive and defensive security operations, including penetration testing and secure code review. The consultant will also integrate security automation into developer workflows and leverage agentic AI tools for secure coding.
- Hybride
- Toronto, ON
- Publié 20 août 2026
- Postuler avant le 19 sept. 2026
- 1 poste
D’autres postes auxquels postuler directement
Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.
City of Toronto
Senior Project Manager CS
- Hybride
Desjardins
Analyste d'affaires système(BSA) Guidewire
- Hybride
Revenu Québec
Cheffe ou chef du Service des produits liés à la facturation obligatoire
- Hybride
Résumé du poste
Role: Principal Consultant - Cybersecurity Location: Toronto, ON (4 days onsite/week) Fulltime Must-have: 10+ years hands-on experience across software engineering, offensive security, and defensive security at a principal engineer level, with demonstrated personal contributions to production codebases and published vulnerability research or penetration testing engagements. Advanced technical proficiency in multiple programming language (Java, C#, C, C++, Python, JavaScript/TypeScript, .NET, Go) with proven ability to personally write, review, and remediate production code. Deep fluency in vulnerability classes including memory safety, injection authentication and authorization flaws, cryptographic misuse, deserialization, race conditions, and supply chain attacks, with hands-on experience finding and exploiting each. Extensive hands-on experience with penetration testing, red teaming, exploit development, reverse engineering, and secure code review against OWASP Top 10 and SANS 25, combined with defensive engineering experience building detection and remediation capabilities. Extensive hands-on experience with application security testing tools (SAST, DAST, IAST, SCA), including tuning, false positive analysis, exemption workflow design, and enterprise vulnerability management at scale. Deep technical fluency with agentic AI coding tools and frameworks (Claude, Devin, Copilot, Windsurf, Cursor, MCP_, including prompt engineering, agent orchestration, reusable skill and tool design, guardrail design, and evaluation. Strong architectural knowledge of modern CI.CD, container platforms (Docker, Kubernetes), cloud-native deployment patterns, and integration of security automation into developer workflows. Nice-to-have: Relevant security certifications (OSCP, OSCE, OSEP, GXPN, GWAPT, CISSP, or equivalent). Experience in financial services or highly regulated industries with exposure to SOX, SOC1, and regulatory audit. Public evidence of offensive capability: published CVEs, bug bounty track record, conference talks (DEFCON, Black Hat, Offensive Con, Recon), CTF placements, or open-source security tooling contributions. Hands-on experience with enterprise vulnerability tooling (Tenable, Aqua, Snyk, BrightSec) and remediation at scale. Demonstrated ability to advise senior technology leaders and deliver within complex, multi-stakeholder enterprise environments.
Ce que vous ferez
The role involves performing high-level offensive and defensive security operations, including penetration testing and secure code review. The consultant will also integrate security automation into developer workflows and leverage agentic AI tools for secure coding.
Exigences
Requires 10+ years of experience in software engineering and cybersecurity with proficiency in multiple programming languages and vulnerability research. Candidates should have deep expertise in application security tools and modern cloud-native architectures.
Compétences indiquées
- KubernetesSouhaitée
- CI/CDSouhaitée
- DockerSouhaitée
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Offensive Security
- Defensive Security
- Penetration Testing
- Secure Code Review
- Exploit Development
- Reverse Engineering
- Application Security Testing
- Agentic AI Coding Tools
- CI/CD
- Kubernetes
- Docker
- Vulnerability Management
- Red Teaming
- Prompt Engineering
- Cloud-Native Deployment
- Software Engineering
Domaines d’emploi
- Security & Safety
- Consulting
- Technology
- Software
- Engineering
Renseignements supplémentaires
- Expérience minimale
- 10+ ans
- Postuler avant le
- 19 sept. 2026
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
- Présence au bureau
- 4 jours par semaine
- Niveau d’expérience
- Mid-Senior level
- Mode de candidature
- La candidature directe est offerte