SENIOR CYBERSECURITY ADVISOR, SPECIALIZED IN PENETRATION TESTING (PENTESTER)
TechnologyDescription
DESCRIPTION
We are looking for a Senior Cybersecurity Advisor, specialized in penetration testing (Pentester) to join our team of advisors at our Montreal or Quebec office.
This position is in a remote work mode, based in Quebec.
TASKS
- Define the scope of the tests, planning, work methodology, execution modalities, and schedule;
- Document the processes for managing penetration tests and vulnerabilities;
- Analyze the results of the tests;
- Analyze and establish the criticality of the vulnerabilities analyzed using the tool implemented internally, "Common Vulnerability Scoring System" version 4.0 (CVSS 4.0);
- Identify technical vulnerabilities and assess risks;
- Document each vulnerability quickly in an observation sheet;
- Document a vulnerability register with the criticality of each one according to the established process for each section;
- Conduct proactive threat intelligence on threats and their evolution;
- Update existing processes and guides, if required;
- Inform the Organizational Security Measures Coordinator (COMSI) and the Head of the Cybersecurity Operations Chapter of urgent vulnerabilities identified;
- Submit recommendations to improve traceability, protection, and preservation of evidence, conduct diagnostics, investigations, or enhance the ability to detect anomalies;
- Advise and support the concerned parties in incident management to identify causes and take the required actions to limit impacts;
- Preserve, identify, extract, and document computer materials and data for evidence and analysis purposes;
- Present observations, findings, and recommendations in the report;
- Produce an executive summary and a detailed penetration test report including recommendations and evidence of vulnerabilities found, and this within the prescribed deadlines.
- DELIVERABLES:
- Documentation of the planned work:
- o The description of the penetration test or vulnerabilities;
- o The scope;
- o The methodology or work process used;
- o The execution modalities;
o The work planning.
- Vulnerability observation sheets:
- o The technical profile;
- o The targeted assets;
- o The surface covered by the tests;
- o The vulnerabilities or problems detected;
o The evidence, data, and logs documenting the identification of the vulnerabilities found; o The affected components; o The probability of exploiting the vulnerability; o The risks associated with the exploitation of the vulnerability and their criticalities; o The recommendations to mitigate the identified risks: § The object or domain to which the recommendation(s) apply; § A description of the recommendation(s); § A description of the risks mitigated by these recommendations; § A description and advice on the means to implement the recommendations;
- An executive summary summarizing:
- § The context, objectives, and scope of the test;
- § The description of the methodology, steps of the test, and tools used;
§ The description of the identified issues and the strengths and weaknesses of the examined system; o The description of the identified vulnerabilities; o The data concerning the identification of the identified vulnerabilities; o The methods and processes used to identify the vulnerabilities; o The evaluation of the criticality of the identified vulnerabilities; o The recommendations and action plan to mitigate the identified vulnerabilities.
REQUIREMENTS
- 1. Possess at least eight (8) years of experience in cybersecurity;
2. Possess at least five (5) years of experience in conducting penetration testing and vulnerability assessments; 3. Have worked, over the past five (5) years, at least one hundred sixty (160) person-days per year on penetration testing assignments; 4. Have conducted, over the past five (5) years, at least two (2) assignments, each of at least ten (10) person-days, in threat and risk assessment based on a recognized method, for example, MEHARI, EBIOS, or OCTAVE; 5. Have conducted, over the past five (5) years, four (4) assignments, each of at least thirty (30) person-days, related to penetration testing on complex technological infrastructures, involving the use of specialized software and analysis following recognized methodologies, for example, OWASP or OSSTMM; 6. Have conducted, over the past five (5) years, at least two (2) assignments, each of at least ten (10) person-days, related to social engineering tests in a large-scale environment, using recognized social engineering methods; 7. Have conducted, over the past five (5) years, at least two (2) assignments, each of at least twenty (20) person-days, related to code reviews in a large-scale context and following the OWASP methodology or equivalent; 8. Have conducted, over the past five (5) years, at least two (2) assignments, each of at least five (5) person-days, related to physical penetration testing in a large-scale organization; 9. Have written and presented to the top management of an organization, over the past five (5) years, at least two (2) executive summaries on information security; 10. Possess one of the four (4) following certifications: o 1CRTP (Certified Red Team Professional); o CRTE (Certified Red Team Expert); o OSCP (Offensive Security Certified Professional); o eWPTX (eLearnSecurity Web Application Penetration Tester eXtreme).
11. Possess one (1) certification or one (1) diploma in code review (source code review). Here are some examples of accepted certifications. Any other equivalent certification may be accepted: Example of certification OSWE (OffSec) – Specialized in code auditing for web application security, this certification evaluates the ability to identify and exploit vulnerabilities in the code.
CSSLP (ISC2) – Oriented towards professionals on integrating security best practices into the software lifecycle, including code auditing to detect flaws.
GSSP (SANS) – Focuses on secure code auditing, certifying the ability to prevent and correct vulnerabilities in various programming languages.
CASE (EC-Council) – Targets software engineers by providing skills in code auditing to ensure security in Java and .NET environments.
s-CSPL (SECO) – Focused on secure development, it includes code auditing to identify and manage risks related to vulnerabilities throughout the software lifecycle.
This posting was aggregated from indeed. Groupe Sentinella is not the employer; applying takes you to the original site. The full text belongs to the original poster.
Want us in your corner?
Join the Sentinella talent bench. We'll reach out when a mandate matches your profile — including roles like this one.
Join the talent bench