Offensive Security Engineer
$130k - $140k per yearSynechron
We are
At Synechron, we believe in the power of digital to transform businesses for the better. Our global consulting firm combines creativity and innovative technology to deliver industry-leading digital solutions. Synechron’s progressive technologies and optimization strategies span end-to-end Artificial Intelligence, Consulting, Digital, Cloud & DevOps, Data, and Software Engineering, servicing an array of noteworthy financial services and technology firms. Through research and development initiatives in our FinLabs we develop solutions for modernization, from Artificial Intelligence and Blockchain to Data Science models, Digital Underwriting, mobile-first applications and more. Over the last 20+ years, our company has been honored with multiple employer awards, recognizing our commitment to our talented teams. With top clients to boast about, Synechron has a global workforce of 16,700 people, across 57 offices, in 22 countries, in key global markets..
Our challenge
As “Principal Consultant, Agentic AI Cybersecurity Engineer” Candidate will work hands-on alongside our cybersecurity engineering and application security teams to build, operate, and advance the agentic AI systems that find, exploit, and remediate vulnerabilities end-to-end across our application and infrastructure estate. Operating at a principal engineer level, candidate will personally direct frontier AI models do discover vulnerabilities in production code, develop proof-of-concept exploits, generate and validate fixes, and integrate them into CI/CD pipelines with safe human-in-the-loop controls. Candidate will also build reusable AI skills, prompts, and tooling that make agentic vulnerability management efficient and scalable across the estate. Candidate will bring deep dual expertise across offensive and defensive security, penetration testing, and software engineering, and apply that fluency to push the boundaries of what is possible with agentic AI in a regulated enterprise environment.
Additional Information*
The base salary for this position will vary based on geography and other factors. In accordance with law, the base salary for this role if filled within Toronto, ON is CAD $130k – CAD $140k/year & benefits (see below).
The Role
Responsibilities:
- Architect and operationalize the end-to-end agentic AI patching pipeline spanning detection, fix generation, automated testing, and release across SAST, DAST, SCA, IAST, container, and server vulnerabilities.
- Use frontier AI models to discover novel vulnerabilities in production application and infrastructure code, develop proof-of-concept exploits, and validate that AI-generated fixes close the underlying root cause.
- Build and maintain the library of reusable AI skills, prompts, evaluation harness, and tooling that power agentic vulnerability discovery, triage, remediation, false positive analysis, and exemption workflows at scale.
- Design and operationalize AI-driven false positive analysis and exemption processes to reduce manual triage burden and surface only actionable findings to development teams.
- Conduct hands-on penetration testing and red team exercise against critical applications and infrastructure to validate defensive controls and agent-generated remediations.
- Extend agentic remediation coverage across SAST, SCA, DAST, IAST, container, and server vulnerabilities, including the data and tooling needed to connect findings back to source.
- Design agent prompting, guardrails, evaluation frameworks, and appropriate human-in-the-loop controls to ensure safe autonomous code changes, testing, and deployment.
- Drive integration of agentic remediation into enterprise CI/CD pipelines (Github, Jenkins, etc.) across the deployment landscape.
- Communicate technical design, risk trade-offs, and delivery progress clearly to senior stakeholders including CIO, CISO, 2LOD, and Audit functions.
Requirements:
- 10+ years hands-on experience across software engineering, offensive security, and defensive security at a principal engineer level, with demonstrated personal contributions to production codebases and published vulnerability research or penetration testing engagements.
- Advanced technical proficiency in multiple programming language (Java, C#, C, C++, Python, JavaScript/TypeScript, .NET, Go) with proven ability to personally write, review, and remediate production code.
- Deep fluency in vulnerability classes including memory safety, injection authentication and authorization flaws, cryptographic misuse, deserialization, race conditions, and supply chain attacks, with hands-on experience finding and exploiting each.
- Extensive hands-on experience with penetration testing, red teaming, exploit development, reverse engineering, and secure code review against OWASP Top 10 and SANS 25, combined with defensive engineering experience building detection and remediation capabilities.
- Extensive hands-on experience with application security testing tools (SAST, DAST, IAST, SCA), including tuning, false positive analysis, exemption workflow design, and enterprise vulnerability management at scale.
- Deep technical fluency with agentic AI coding tools and frameworks (Claude, Devin, Copilot, Windsurf, Cursor, MCP_, including prompt engineering, agent orchestration, reusable skill and tool design, guardrail design, and evaluation.
- Strong architectural knowledge of modern CI.CD, container platforms (Docker, Kubernetes), cloud-native deployment patterns, and integration of security automation into developer workflows.
Preferred, but not required:
- Relevant security certifications (OSCP, OSCE, OSEP, GXPN, GWAPT, CISSP, or equivalent).
- Experience in financial services or highly regulated industries with exposure to SOX, SOC1, and regulatory audit.
- Public evidence of offensive capability: published CVEs, bug bounty track record, conference talks (DEFCON, Black Hat, Offensive Con, Recon), CTF placements, or open-source security tooling contributions.
- Hands-on experience with enterprise vulnerability tooling (Tenable, Aqua, Snyk, BrightSec) and remediation at scale.
- Demonstrated ability to advise senior technology leaders and deliver within complex, multi-stakeholder enterprise environments.
We offer:
- A multinational organization with 57 offices in 22 countries and the possibility to work abroad.
- 15 days (3 weeks) of paid annual leave plus an additional 10 days of personal leave (floating days and sick days).
- A comprehensive insurance plan including medical, dental, vision, life insurance, and long-term disability.
- Flexible hybrid policy.
- RRSP with employer’s contribution up to 4%.
- A higher education certification policy.
- On-demand Udemy for Business for all Synechron employees with free access to more than 5000 curated courses.
- Coaching opportunities with experienced colleagues from our Financial Innovation Labs (FinLabs) and Center of Excellences (CoE) groups.
- Cutting edge projects at the world’s leading tier-one banks, financial institutions and insurance firms.
- A truly diverse, fun-loving and global work culture.
SYNECHRON’S DIVERSITY & INCLUSION STATEMENT
Diversity & Inclusion are fundamental to our culture, and Synechron is proud to be an equal opportunity workplace and is an affirmative action employer. Our Diversity, Equity, and Inclusion (DEI) initiative ‘Same Difference’ is committed to fostering an inclusive culture – promoting equality, diversity and an environment that is respectful to all. We strongly believe that a diverse workforce helps build stronger, successful businesses as a global company. We encourage applicants from across diverse backgrounds, race, ethnicities, religion, age, marital status, gender, sexual orientations, or disabilities to apply. We empower our global workforce by offering flexible workplace arrangements, mentoring, internal mobility, learning and development programs, and more.
All employment decisions at Synechron are based on business needs, job requirements and individual qualifications, without regard to the applicant’s gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law.
- ...We are seeking a Senior Developer with AI Red Teaming and Penetration Testing experience to support security assessments of AI/LLM systems. Key Responsibilities: Execute AI Red Team exercises against LLM applications. Perform prompt injection, jailbreaking, adversarial...Suggested
- ...We are hiring a AppSec Engineer with strong experience in Snyk and CI/CD automation. Key Skills Snyk platform (setup, management, automation) GitHub Actions / CI-CD pipelines SAST / SCA security testing Python / Bash / PowerShell scripting DevSecOps / Application...Suggested
- ...We are hiring a Product Engineer to help build the next generation of a cloud-native Security and Compliance platform. This is a high-impact role for someone who can operate... ...that system correctly and create a scalable, secure, and enterprise-ready platform that simplifies...Suggested
$73.5k - $122.5k per year
...deliverables. This is a key role within the Cyber Defense - Offensive Security Team at KPMG, where the candidate will serve as a subject... ...and penetration testing, red/purple team assessment and social engineering exercises. The selected candidate will work on client projects...SuggestedInternshipLocal area$122.74k - $141.95k per year
...HelloFresh a trusted name - someone with a passion for security and appetite for new challenges. Security Engineers work in a variety of ways to constantly iterate and... ...average ability in any 4 of the following areas of offensive security: Network, Wireless, Cloud, Web, Mobile,...SuggestedWork at officeRemote workWork from homeFlexible hours2 days per week3 days per week- ...EGS”) and the Pape Tunnel and Underground Station Contract (“PTUS”), with supporting Early Works. What is the Opportunity? The Security Coordinator is responsible for assisting the Security and Site Facility Supervisor in developing and implementing security protocols...Contract workFor subcontractorWork at office
- ...publicly traded companies. Join the Hellofresh security team to help to maintain the highest... ...abuse and nefarious activities Secure containers, CI/CD pipelines and implement... ...Bachelor's degree in Computer Science, Engineering, or a related field. Work experience in...Work at officeRemote workWork from homeFlexible hours2 days per week3 days per week
- ...Position: Business Security Consultant/ Project Security Consultant (Application Security) Client: Enterprise Canadian Banking Client Type: 6 m contract + extensions Location: 2 days a week on site downtown Toronto Rate: 55-60/hr incorporated (60 is MAX rate)...Contract work2 days per week
$159.1k - $198k per year
...Drug Mart. Position Summary League is seeking a Software Security Engineer to join our Security Engineering org and focus full-time on... ...Product Engineering teams to build tools and workflows that improve secure software delivery, automate security operations, and protect...Full timeWork at officeRemote workFlexible hours$126k - $176k per year
...Our Marsh Information Security team is seeking candidates for the following position based... ...3 days a week. The Application Security Engineer/Developer will act as a security advisor... ...Design frameworks, Threat Modeling, and Secure SDLC. Good understanding of cryptography...Minimum wageWork at officeLocal areaRemote workFlexible hours3 days per week1 day per week$69k - $114k per year
...job coaching -- Deloitte Global is the engine of the Deloitte network. Our professionals... ...and architect comprehensive network security solutions tailored to meet the unique needs... ...datacenter operations teams to ensure the secure deployment and maintenance of infrastructure...Permanent employmentRemote workFlexible hours- ...Job Title: Project Manager – Cyber Security Location: Toronto, ON (Hybrid: 2 days min onsite) Interview Process: Virtual 2 rounds Length: 12 Months with possible extension Role Summary We are seeking a Project Manager to support delivery of smaller cybersecurity...Shift work
$110k - $151.8k per year
...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted... .... If you are too, let's talk. We are looking for a Software Engineer II to join the Auth0 Security Engineering organization. You'll help...Local areaWorldwide$90k - $140k per year
...Toronto | 3 + Years Description Our client is seeking an experienced full-time Securities Law Clerk to join their Corporate and Securities Practice Group in their Toronto office. This is an exciting opportunity to join a growing capital markets practice and support lawyers...Long term contractFull timeTemporary workInterim roleCasual workWork at office3 days per week$141k - $193.6k per year
...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted... .... If you are too, let's talk. The Staff Product Security Engineer Opportunity As a Staff Product Security Engineer, you will play...Local areaWorldwide$141k - $193.6k per year
...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted... .... If you are too, let's talk. The Staff Product Security Engineer Opportunity As a Staff Product Security Engineer, you will play...Local areaWorldwide- Cloud Security Engineer – BFSI Location: Greater Toronto Area, Ontario About the Role We are seeking a Cloud Security Engineer to secure enterprise cloud environments supporting critical banking, insurance, and financial services platforms. IMPORTANT NOTE – BFSI EXPERIENCE...
$20 per hour
...currently seeking candidates for seasonal Security Supervisor positions JOB SUMMARY... ..., environmental, criminal, or provincial offenses, etc.). JOB SPECIFICATIONS Deployment... ..., fire, ambulance) to provide a safe and secure environment This is a uniformed position...Hourly payFull timeContract workPart timeCasual workSeasonal workLocal areaShift workNight shiftWeekend workDay shiftAfternoon shift- Application Security Engineer (AppSec) – BFSI Location: Greater Toronto Area, Ontario About the Role We are seeking an Application Security Engineer to secure enterprise banking, insurance, payments, and customer-facing digital applications through secure development...
$65.4k - $69.49k per year
...devices, applications, and user accounts are secure, reliable, and optimized for productivity... ...Technology, Computer Science, Computer Engineering, or equivalent. Minimum 3 years’... ...Azure Administrator Associate (AZ‑104) Offensive Security Certified Professional (OSCP), Certified...Permanent employmentFull timeFor contractorsWork at officeFlexible hours- ...include: • Assessing and implementing Cloud security solutions for clients • Reviewing... ...processes to the cloud and operating it in a secure and private way. We offer cyber... ...• Degree or Diploma in Computer Science, Engineering, Management Information Systems or Information...Permanent employmentFlexible hours
$27 per hour
...Ready to suit up as a Tactical Security Guard What matters most in a role like this is your ability to read the environment, anticipate... ...activity Check identification and control access to secure areas React quickly to threats or incidents and document actions...Hourly payPart timeCasual workMonday to fridayShift work$18.35 per hour
...Ready to suit up as a {Skill} Security Guard What matters most in a role like this is your ability to engage with people easily and make them feel confident in your ability to help them. As a Concierge Security Guard, there is a high focus on customer service since you...Hourly payFull timePart timeCasual workWork at officeFlexible hoursShift work$153k - $197k per year
...Shape the future of enterprise security strategy within one of Canada’s leading insurance environments. The Role Capco... ...enterprise environments Partner with architecture and engineering teams to define secure design principles and implementation standards Provide...InternshipImmediate start$23.72 per hour
...Ready to suit up as a Security Dispatcher/Operator What matters most about a role like this is your sharp eye, capturing every detail as you scan a series of screens. Your strong observation skills with attention to detail are your greatest strengths. As a Security Dispatcher...Hourly payPart timeCasual workLocal areaFlexible hoursNight shiftDay shift$105k - $234k per year
...mentoring and on the job coaching -- What will your typical day look like? Reporting to the executive leadership for the Application Security group in Deloitte's Technology and Transformation practice, the Senior Manager is self-motivated, energetic, driven for success, and...Permanent employmentLocal areaFlexible hours$63.85 - $70.51 per hour
...highly accomplished and technical Senior Security Architect (Security Specialist) for an enterprise... ...capacity within the cybersecurity engineering and information technology governance... ...direction to ensure high availability, design secure network segmentation across multi-cloud...Contract workRemote workFlexible hours2 days per week3 days per week$90 - $95 per hour
...currently seeking the services of a "Sr. Info Security Specialist" for a contract role with one... ...as Computer Science, Business Computing, Engineering, or Commerce is required • What you... ..., Microsoft Entra ID PIM). • Develop secure architectures for privileged identity...Full timeContract workWork at office3 days per week$140k - $175k per year
...Are you excited by the opportunity to secure products used by millions of professionals around the world? Join Thomson Reuters as a Manager... ...Manager leads our Product Security Core team, a group of senior engineers responsible for scaling security across Thomson Reuters' product...Full timeWork at officeLocal areaFlexible hours2 days per week3 days per week$65.17 - $69.82 per hour
...RQ00689 - Int. Security Specialist 6-month contract (129 business days) - possible extension ONSITE 5 days - 777 Bay Street,... ...technologies Public sector experience Bachelor's in Computer Engineering, Computer Science or IT NIce-to-have: ~...Contract work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Offensive Security Engineer. Be the first to apply!
- product security engineer Toronto, ON
- security engineering manager Toronto, ON
- security engineer remote Toronto, ON
- physical security engineer Toronto, ON
- security system engineer Toronto, ON
- aws security engineer Toronto, ON
- product security engineer
- security engineering manager
- cyber security engineer
- security engineer remote
