3 Penetration Testing jobs in Canada
Senior Security Consultant (AI/ML Penetration Testing)
Posted today
Job Viewed
Job Description
Job Description
*This is a remote position, and candidates must be located in Ontario, CA
NetSPI® is an award-winning pioneer of Penetration Testing as a Service (PTaaS) with its AI-powered platform supported by more than 350 in-house cybersecurity experts. Specializing in 50+ pentest types, attack surface visibility, vulnerability prioritization, and attack simulation, NetSPI delivers security testing with unprecedented clarity, speed, and scale.
NetSPI is on an exciting growth journey as we disrupt and improve the proactive security market. We are looking for individuals with a collaborative, innovative, and customer-first mindset to join our team. Learn more about our award-winning workplace culture and get to know our A-Team at
Join the mission as a Senior Security Consultant. We’re seeking a technically skilled and analytical AI/ML Penetration Tester to strengthen our cybersecurity defenses through advanced, cutting-edge testing of AI and machine learning systems. As a Penetration Tester supporting AI/ML, you will work closely with clients to deliver clear, actionable reports and contribute to the development of security best practices.
Responsibilities :
- Conduct engagements on AI/ML systems, web applications and API’s independently and provide technical oversight
- Design and execute advanced adversarial testing (e.g., evasion, data poisoning, model extraction, inversion/inference) to expose vulnerabilities in AI/ML pipelines and architectures.
- Present comprehensive penetration test findings to clients while emphasizing AI/ML risks, and collaborate on remediation strategies with model hardening, adversarial training, and threat mitigation.
- Help author tools, presentations, white papers, and blog posts to share insights on AI/ML security best practices and emerging attack trends with the broader cybersecurity community. Contribute to the cybersecurity community through tools, presentations, white papers, and blogging.
- Review reports for accuracy in technical oversight, perform weekly QA oversight, and provide mentoring support to others
- Create, deliver, and collaborate on penetration testing reports in diverse client environments, maintaining client-specific processes, reporting standards, and access protocols to help improve their security posture
- Research and develop innovative techniques, tools, and methodologies for penetration testing services, alongside commitment to improvement and execution on NetSPI specific products and processes
- Participate in development, implementation, and oversight of testing, delivery, and management strategies for key client accounts
- Perform administrative tasks related to day-to-day consulting activities to ensure smooth business and engagement operations.
Minimum Qualifications :
- Bachelor’s degree or higher, with a focus on IT, Computer Science, Engineering or Math or equivalent experience
- Minimum of 3-5 years of work experience in Penetration Testing
- Proficiency in using and customizing offensive toolkits for network, application, and AI/ML penetration testing
- Thorough understanding of how major ML frameworks (e.g., Tensorflow, PyTorch) are implemented in real-world training and deployment pipelines.
- Understanding of how to deploy AI/ML models with LangChain, including secure configuration of data flows, environment isolation, and integration with production systems
- Understanding of Adversarial Machine Learning and its practical applications
- Familiarity with offensive tools, based on applicable skillset (e.g., Kali Linux, Burp Suite, Metasploit, Nessus)
- Familiarity with offensive and defensive IT concepts and protocols
- Extensive understanding of the OWASP Top 10, MITRE ATT&CK framework, and various security frameworks.
- Working knowledge of Windows, Linux and MacOS operating systems internals
- Experience mentoring or coaching to growing team members, while sharing knowledge externally through blogs, hosting webinars, or presenting at conferences
- Ability to work independently and as part of a team
- Proficient communication skills, both written and verbal
- Willingness to travel up to 5-10% minimum
- This position requires an 8-hour workday, with occasional evenings or weekends necessary to meet project deadlines or critical needs
Preferred Qualifications:
- Ability to provide technical and QA oversight on AI/ML service line.
- Comprehensive knowledge of secure AI/ML development protocols and architecture
- Strong problem-solving skills and the ability to think like both an attacker and a defender.
- A continuous learning mindset to keep up to date with the rapidly evolving AI/ML and cybersecurity landscapes.
- Experience with model interpretability and explainability tools to understand model behavior and potential biases.
- Experience in ML model development, feature engineering, and data pre-processing.
- Experience in one or more of the following programming or scripting languages (e.g., Ruby, Python, Perl, C, C++, Java, and C#)
- Offensive Security Certifications (e.g., GXPN, GPEN, OSCP, GWAPT)
We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law.
Senior Security Consultant (Secure Code Review + Web Application Penetration Testing)
Posted today
Job Viewed
Job Description
Job Description
*This is a remote position, and candidates must be located in Ontario, CA.
NetSPI® is an award-winning pioneer of Penetration Testing as a Service (PTaaS) with its AI-powered platform supported by more than 350 in-house cybersecurity experts. Specializing in 50+ pentest types, attack surface visibility, vulnerability prioritization, and attack simulation, NetSPI delivers security testing with unprecedented clarity, speed, and scale.
NetSPI is on an exciting growth journey as we disrupt and improve the proactive security market. We are looking for individuals with a collaborative, innovative, and customer-first mindset to join our team. Learn more about our award-winning workplace culture and get to know our A-Team at
NetSPI is seeking a Senior Security Consultant who will serve as a resource for delivery of secure code review and web application penetration assessments. This position requires an understanding of various web technologies, enterprise secure development and risk management. In addition, it requires experience with application security assessments/testing, as well as demonstrated competencies in problem solving, client service, written/verbal communication, and project execution.
Responsibilities:
- Conduct in-depth penetration testing and secure code review assessments on web applications
- Dynamically exploit vulnerabilities found in codebase and correlate insecure coding practices into dynamic application vulnerabilities
- Deliver secure code review assessment on programming languages such as Java, C#, Python, C/C++, Perl, PHP
- Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques
- Train and assist developers in writing secure software and remediating existing vulnerabilities
- Provide oversight to peers on service lines through QA process
- Mentor and assist team members in effectively delivering assessments and enhancing skillsets
- Present detailed penetration test findings to clients and assist in remediation planning
- Engage in research to develop new penetration testing methods, tools, and innovative exploit techniques
- Contribute to the cybersecurity community through tools, presentations, white papers, and blogging
- Maintain consistency with other internal requirements related to day-to-day administration tasks (time keeping, status updates to clients, etc.)
Minimum Qualifications:
- Minimum of 3-5 years of experience in application security including both secure code review and web application penetration testing
- Exceptional familiarity in all Burp Suite functions. Published Burp extensions and ability to create new Burp Suite extensions preferred
- Detailed understanding of the OWASP Top 10 and CWE Top 25 issues with focus on ability to identify and remediate vulnerability in source code
- Ability to explain risk and business impact of security vulnerabilities to variety of audience
- Bachelor’s degree or higher, preferably in Computer Science, Engineering, Mathematics, IT, or a related field; equivalent experience will also be considered.
- Willingness to travel up to 25%
Preferred Qualifications:
- Ability to provide technical and QA oversight on Web Application Penetration Testing and Secure Code Review service lines.
- Experience in detecting, analyzing and providing recommendation guidance on security vulnerabilities using SAST and/or manual secure code review in at least two of the following languages: Java, C#, PHP, Python, C/C++
- Experience in software development in at least one server-side programming language
We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law.
Be The First To Know
About the latest Penetration testing Jobs in Canada !