Pen test platform

Sorry, this job was removed at 08:35 p.m. (UTC) on Monday, Aug 31, 2026
Be an Early Applicant
Hiring Remotely in CAN
Remote
Expert/Leader
Information Technology • Professional Services • Software • Consulting
The Role
Lead Fraser Health’s penetration testing program by scoping and sizing web/API applications, executing manual and tool-assisted grey-box tests, validating attack paths safely in healthcare environments, and managing engagements through reporting and sign-off. Operate the browser-based testing platform, configure tools in PAM-accessed machines, track remediation, conduct retesting, and present findings. Required expertise includes authentication, privilege escalation, API vulnerabilities, business logic testing, OWASP, NIST, PCI DSS, and IDART standards.
Summary Generated by Built In

This is a remote position.

We are seeking an Expert-level Information Security Consultant to drive the ongoing maturity of Fraser Health's penetration testing program. In this role, you will perform end-to-end grey-box penetration tests across a large portfolio of web and API applications while utilizing a secure, browser-based management platform to schedule assessments, track vulnerabilities, and manage remediation lifecycles

Requirements
  • Scoping & Sizing: Conduct T-shirt sizing (Small, Medium, Large) and scoping for onboarded applications based on dynamic web pages and user roles.

  • Penetration Testing Execution: Execute manual and tool-assisted grey-box penetration tests across approximately 123 Web/API applications (30 Large, 51 Medium, 42 Small), completing testing within 5–10 days per application.

  • Engagement Lifecycles: Manage the end-to-end testing lifecycle for each application from kickoff meeting to final sign-off within 20–25 days.

  • In-Depth Vulnerability Assessment: Conduct expert manual assessments covering authentication, session management, MFA bypass, horizontal/vertical privilege escalation, IDOR/BOLA, API vulnerabilities, and business logic workflow abuses.

  • Attack-Path Validation: Chain vulnerabilities into realistic attack paths and perform controlled, non-destructive validation within live healthcare environments without disrupting operational or clinical systems.

  • Platform Management: Deploy and operate a browser-based, RBAC/MFA-enabled pen test platform supporting 6–12 month forward scheduling, metric dashboards, report retention, automated notifications, and GRC tool integration.

  • Tooling & Environment Setup: Install, configure, and maintain all necessary licensed testing tools inside the client-provided penetration testing machines accessed via the Privileged Access Management (PAM) platform.

  • Reporting & Debriefs: Author comprehensive reports with testing methodologies, scorecards, reproducible steps, root-cause analyses, and prioritized remediation guidance, followed by stakeholder presentations.

  • Remediation Tracking & Retesting: Follow up with application owners on vulnerability mitigations and perform targeted retests on resolved findings.

Required Qualifications & Experience

  • Certifications: Active penetration testing certification such as OSCP (Offensive Security Certified Professional), CEH (Certified Ethical Hacker), or an equivalent credential.

  • Seniority Threshold (Expert Level):

    • Relevant Degree + minimum 6 years of consulting experience.

    • Relevant Diploma + minimum 7 years of consulting experience.

    • Relevant Certificate + minimum 8 years of consulting experience.

    • Minimum 10 years of directly related consulting experience.

  • Healthcare & Production Experience: Demonstrated experience performing penetration testing safely in Canadian healthcare or sensitive enterprise environments with zero clinical/operational impact.

  • Employment Status: Must be a permanent employee of the service provider (subcontracting is prohibited).

  • Framework Alignment: Practical working knowledge of OWASP, NIST SP 800-53A, PCI DSS 11.3, and IDART standards



Skills Required

  • Active penetration testing certification such as OSCP, CEH, or equivalent
  • Relevant degree and at least 6 years of consulting experience
  • Relevant diploma and at least 7 years of consulting experience
  • Relevant certificate and at least 8 years of consulting experience
  • At least 10 years of directly related consulting experience
  • Experience performing penetration testing safely in Canadian healthcare or sensitive enterprise environments without clinical or operational impact
  • Must be a permanent employee of the service provider; subcontracting is prohibited
  • Practical working knowledge of OWASP, NIST SP 800-53A, PCI DSS 11.3, and IDART standards

Similar Jobs

Apryse Logo Apryse

Account Manager

Productivity • Software • App development • Automation
Remote
3 Locations
665 Employees
150K-220K Annually

Apryse Logo Apryse

Account Manager

Productivity • Software • App development • Automation
Remote
3 Locations
665 Employees
120K-180K Annually

Apryse Logo Apryse

Account Manager

Productivity • Software • App development • Automation
In-Office or Remote
4 Locations
665 Employees
175K-245K Annually

SailPoint Logo SailPoint

Regional Vice President Vertical and Public Sector

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
Canada
2461 Employees
183K-183K Annually
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
45 Employees
Year Founded: 2008

What We Do

Workiy is a global company with more than 20 years of experience that provides end-to-end digital solutions, consulting and implementation services to its clients, including digital solutions and staffing services.

Similar Companies Hiring

Kepler  Thumbnail
Artificial Intelligence • Fintech • Software
New York, New York
9 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees
Revel.io Thumbnail
Aerospace • Hardware • Robotics • Software
US
50 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account