Back to all jobs
AI-translated

SENIOR CYBERSECURITY ADVISOR, SPECIALIZED IN PENETRATION TESTING (PENTESTER)

Professional services
Chrome TechnologiesQuébec, Quebec, Canada
Temps plein

Description

Reference 2176/QC/0309

Start Date

As soon as possible

Location 100% remote work (must be based in Quebec)

Duration

Permanent

Description

We are looking for a Senior Cybersecurity Advisor, specialized in penetration testing (Pentester) to join our team of advisors at our Montreal or Quebec office.

This position is remote work, based in Quebec.

Tasks

  • Define the scope of the tests, planning, work methodology, execution modalities, and work schedule;
  • Document the intrusion test and vulnerability management processes;
  • Analyze the results of the tests;
  • Analyze and establish the criticality of the analyzed vulnerabilities using the internally implemented tool, "Common Vulnerability Scoring System" version 4.0 (CVSS 4.0);
  • Identify technical vulnerabilities and assess risks;
  • Quickly document each vulnerability in an observation sheet;
  • Document a vulnerability registry with the criticality of each one according to the established process for each section;
  • Conduct proactive threat intelligence on threats and their evolution;
  • Update existing processes and guides, if required;
  • Inform the Organizational Security Measures Coordinator (COMSI) and the Head of the Cybersecurity Operations Chapter of urgent vulnerabilities identified;
  • Submit recommendations to improve traceability, protection, and preservation of evidence, conduct diagnostics, investigations, or enhance the ability to detect anomalies;
  • Advise and support concerned parties in incident management to identify causes and implement required actions to limit impacts;
  • Preserve, identify, extract, and document computer hardware and data for evidence and analysis purposes;
  • Present observations, findings, and recommendations in the report;
  • Produce an executive summary and a detailed penetration test report including recommendations and evidence of vulnerabilities found, and this within the prescribed deadlines.

Deliverables

  • Documentation of the planned work:
  • The description of the penetration test or vulnerabilities;
  • The scope;
  • The methodology or work process used;
  • The execution modalities;
  • The work planning.
  • Vulnerability observation sheets:
  • The technical profile;
  • The targeted assets;
  • The coverage area of the tests;
  • The detected vulnerabilities or issues;
  • The evidence, data, and logs documenting the identification of found vulnerabilities;
  • The affected components;
  • The probability of vulnerability exploitation;
  • The risks associated with vulnerability exploitation and their criticalities;
  • The recommendations to mitigate identified risks:
  • The object or domain to which the recommendation(s) apply;
  • A description of the recommendation(s);
  • A description of the risks mitigated by these recommendations;
  • A description and advice on the means to implement the recommendations;
  • An executive summary:
  • The context, objectives, and scope of the test;
  • The description of the methodology, steps of the test, and tools used;
  • The description of the identified issues and the strengths and weaknesses of the examined system;
  • The description of the identified vulnerabilities;
  • The data concerning the identification of the identified vulnerabilities;
  • The methods and processes used to identify vulnerabilities;
  • The evaluation of the criticality of the identified vulnerabilities;
  • The recommendations and action plan to mitigate the identified vulnerabilities.

Requirements

  • Possess at least eight (8) years of experience in cybersecurity;
  • Possess at least five (5) years of experience in conducting penetration testing and vulnerability assessments;
  • Have worked, over the past five (5) years, at least one hundred sixty (160) person-days per year on penetration testing mandates;
  • Have conducted, over the past five (5) years, at least two (2) mandates, each of at least ten (10) person-days, in threat and risk assessment based on a recognized method, for example, MEHARI, EBIOS, or OCTAVE;
  • Have conducted, over the past five (5) years, four (4) mandates, each of at least thirty (30) person-days, related to penetration testing on complex technological infrastructures, involving the use of specialized software and analysis following recognized methodologies, for example, OWASP or OSSTMM;
  • Have conducted, over the past five (5) years, at least two (2) mandates, each of at least ten (10) person-days, related to social engineering tests in a large-scale environment, using recognized social engineering methods;
  • Have conducted, over the past five (5) years, at least two (2) mandates, each of at least twenty (20) person-days, related to code reviews in a large-scale context and following the OWASP methodology or equivalent;
  • Have conducted, over the past five (5) years, at least two (2) mandates, each of at least five (5) person-days, related to physical penetration testing in a large organization context;
  • Have written and presented to the top management of an organization, over the past five (5) years, at least two (2) executive summaries related to information security;
  • Possess one of the following four (4) certifications:
  • 1CRTP (Certified Red Team Professional);
  • CRTE (Certified Red Team Expert);
  • OSCP (Offensive Security Certified Professional);
  • eWPTX (eLearnSecurity Web Application Penetration Tester eXtreme).
  • Possess one (1) certification or one (1) degree in code review (source code review). Here are some examples of accepted certifications. Any other equivalent certification may be accepted:
  • Example of certification

OSWE (OffSec) – Specialized in web application security code audits, this certification evaluates the ability to identify and exploit vulnerabilities in the code.

CSSLP (ISC2) – Oriented towards professionals on integrating security best practices into the software lifecycle, including code audits to detect flaws.

GSSP (SANS) – Focuses on secure code audits, certifying the ability to prevent and correct vulnerabilities in various programming languages.

CASE (EC-Council) – Targets software engineers by providing code audit skills to ensure security in Java and .NET environments.

s-CSPL (SECO) – Focused on secure development, it includes code audits to identify and manage risks related to vulnerabilities throughout the software lifecycle.

Apply for this opportunity

Back

This posting was aggregated from linkedin. Groupe Sentinella is not the employer; applying takes you to the original site. The full text belongs to the original poster.

Want us in your corner?

Join the Sentinella talent bench. We'll reach out when a mandate matches your profile — including roles like this one.

Join the talent bench
CONSEILLER SÉNIOR EN CYBERSÉCURITÉ, SPÉCIALISÉ EN TESTS D'INTRUSION (PENTESTER) — Groupe Sentinella