Pen test platform

 Posted 7 hours ago
  
 Canada
  
10+ years experience
Apply Now

Please mention DailyRemote when applying

?/100
Resume Match Score

Match your resume skills with our AI powered skill match!

Get professional review

AI Summary

The consultant will perform end-to-end grey-box penetration testing on a large portfolio of web and API applications within a healthcare environment. They are also responsible for managing the testing lifecycle, platform operations, and providing comprehensive vulnerability reporting and remediation guidance.

This is a remote position.

We are seeking an Expert-level Information Security Consultant to drive the ongoing maturity of Fraser Health's penetration testing program. In this role, you will perform end-to-end grey-box penetration tests across a large portfolio of web and API applications while utilizing a secure, browser-based management platform to schedule assessments, track vulnerabilities, and manage remediation lifecycles

Requirements

  • Scoping & Sizing: Conduct T-shirt sizing (Small, Medium, Large) and scoping for onboarded applications based on dynamic web pages and user roles.

  • Penetration Testing Execution: Execute manual and tool-assisted grey-box penetration tests across approximately 123 Web/API applications (30 Large, 51 Medium, 42 Small), completing testing within 5–10 days per application.

  • Engagement Lifecycles: Manage the end-to-end testing lifecycle for each application from kickoff meeting to final sign-off within 20–25 days.

  • In-Depth Vulnerability Assessment: Conduct expert manual assessments covering authentication, session management, MFA bypass, horizontal/vertical privilege escalation, IDOR/BOLA, API vulnerabilities, and business logic workflow abuses.

  • Attack-Path Validation: Chain vulnerabilities into realistic attack paths and perform controlled, non-destructive validation within live healthcare environments without disrupting operational or clinical systems.

  • Platform Management: Deploy and operate a browser-based, RBAC/MFA-enabled pen test platform supporting 6–12 month forward scheduling, metric dashboards, report retention, automated notifications, and GRC tool integration.

  • Tooling & Environment Setup: Install, configure, and maintain all necessary licensed testing tools inside the client-provided penetration testing machines accessed via the Privileged Access Management (PAM) platform.

  • Reporting & Debriefs: Author comprehensive reports with testing methodologies, scorecards, reproducible steps, root-cause analyses, and prioritized remediation guidance, followed by stakeholder presentations.

  • Remediation Tracking & Retesting: Follow up with application owners on vulnerability mitigations and perform targeted retests on resolved findings.

Required Qualifications & Experience

  • Certifications: Active penetration testing certification such as OSCP (Offensive Security Certified Professional), CEH (Certified Ethical Hacker), or an equivalent credential.

  • Seniority Threshold (Expert Level):

    • Relevant Degree + minimum 6 years of consulting experience.

    • Relevant Diploma + minimum 7 years of consulting experience.

    • Relevant Certificate + minimum 8 years of consulting experience.

    • Minimum 10 years of directly related consulting experience.

  • Healthcare & Production Experience: Demonstrated experience performing penetration testing safely in Canadian healthcare or sensitive enterprise environments with zero clinical/operational impact.

  • Employment Status: Must be a permanent employee of the service provider (subcontracting is prohibited).

  • Framework Alignment: Practical working knowledge of OWASP, NIST SP 800-53A, PCI DSS 11.3, and IDART standards



Similar Jobs

See all Remote Others jobs →

Personalize your Remote Job Search in 3 Easy Steps!

Discover remote opportunities in Others

Answer easy questions

Answer easy questions

200,000+ jobs across 15+ categories

Get your best job matches

Get your best job matches

Only hand-screened, legit jobs

Find a remote job faster

Find a remote job faster

No ads, scams, or junk

I was the first applicant for a remote marketing position that got listed on the company website the same day I applied. Had an interview within 48 hours!

Sarah J. — Sarah J. · Marketing Manager ★★★★★ Verified