Penetration Tester - Offensive Security
Full-time
Malleum
About Malleum
Malleum is at the forefront of next-generation cyber defense, partnering with marquee clients across space, aerospace, defense , government, financial services, and critical infrastructure. We're experiencing exceptional growth as demand accelerates for trusted advisors capable of delivering at the intersection of national security, allied intelligence cooperation, and enterprise resilience. Our offensive security consultants test the systems behind cutting-edge defensive technologies, sovereign space capabilities, and allied programs — finding the gaps before adversaries do, on networks that protect missions of genuine national consequence. If you take pride in breaking things ethically – and helping the most consequential organizations build back stronger – Malleum is where your craft meets purpose.The Opportunity
We're seeking a Penetration Tester to deliver hands-on offensive security engagements across client networks, applications, cloud environments, and operational technology. You'll work directly within client environments – including sovereign, regulated, and cleared settings – emulating real-world adversaries, documenting findings, and partnering with clients to drive meaningful remediation. This is a hands-on consulting role for a practitioner who blends deep technical tradecraft with strong client presence and the discipline to deliver findings clearly, safely, and on schedule.What You'll Do
- Scope, and execute penetration tests across external, internal, web application, API, mobile, cloud (Azure / AWS / GCP), wireless, and Active Directory targets
- Conduct red team and adversary emulation engagements aligned to MITRE ATT&CK, executing realistic TTPs against client environments
- Perform assumed-breach assessments, internal pivoting, privilege escalation, and lateral movement exercises
- Support purple team exercises in partnership with client SOC and Malleum's IR practice to improve detection and response
- Execute social engineering campaigns (phishing, vishing, physical) where contracted, with rigorous rules of engagement
- Conduct cloud configuration reviews against CIS Benchmarks, CSA CCM, and provider-specific baselines
- Support OT / ICS / SCADA security testing for defense and critical-infrastructure clients (with appropriate safety controls)
- Develop custom tooling, scripts, and payloads (PowerShell, Python, C#, Go) to evade modern EDR and ZTNA controls during sanctioned engagements
- Produce high-quality client deliverables: executive summaries, technical findings, reproduction steps, evidence, CVSS-scored risk ratings, and pragmatic remediation guidance
- Deliver findings briefings to client stakeholders — from engineers to executive leadership and boards — with clarity and professionalism
- Contribute to scoping, estimation, statements of work, and continuous improvement of Malleum's offensive security service offerings
- Maintain meticulous engagement hygiene: rules of engagement, scope control, evidence handling, and safe-listing coordination
- Participate in research, internal tooling development, CTFs, and conference contributions to grow Malleum's offensive capability and brand
What You Bring
- 4+ years of professional penetration testing or red team experience, ideally in a consulting, MSSP, or in-house offensive security team
- Demonstrated success working directly with clients — strong communication, professionalism, and stakeholder management skills
- Deep working knowledge of network, web application, and Active Directory attack paths (Kerberoasting, AS-REP roasting, NTLM relay, ADCS abuse, BloodHound-driven pathing)
- Hands-on proficiency with offensive tooling: Burp Suite Pro, Nmap, Nessus / Nuclei, Metasploit, Cobalt Strike, Sliver, Mythic, Impacket, BloodHound, CrackMapExec / NetExec, Responder, Mimikatz, and modern C2 frameworks
- Strong scripting skills in Python, PowerShell, and Bash; comfort reading and modifying C#, Go, or Rust tooling
- Experience evading or bypassing EDR (Defender, CrowdStrike, SentinelOne), AMSI, and modern Windows defenses
- Familiarity with cloud attack paths in Azure / Entra ID (Pass-the-PRT, illicit consent grants, managed identity abuse) and AWS (IAM privilege escalation, metadata service abuse)
- Solid grasp of ZTNA and identity-aware perimeters (e.g., Cloudflare Access, Zscaler, Entra Conditional Access) and how they reshape attacker tradecraft
- Comfort emulating adversary TTPs mapped to MITRE ATT&CK and known threat-actor playbooks
- Familiarity with testing standards: PTES, OWASP WSTG / MASTG / ASVS, NIST SP 800-115, OSSTMM
- Awareness of compliance contexts that frame client expectations: PCI DSS, SOC 2, NIST 800-171 / CMMC, CPCSC, ITSG-33, ISO 27001:2022
- Certifications such as OSCP, OSEP, OSWE, OSCE3, CRTO, CRTL, GPEN, GXPN, GWAPT, GMOB, GCSA / GPCS / GCLD (cloud), AWS Certified Security – Specialty, Microsoft SC-100 / AZ-500 strongly preferred; OSCP or equivalent practical certification (e.g., CRTO, HTB CPTS, PNPT) is a baseline expectation
- Demonstrated ability to perform under pressure — calm, methodical, and ethical when engagements surface sensitive findings
- Willingness and availability to work odd hours and extended shifts when supporting time-boxed red team windows, after-hours testing, or rapid-response offensive support during active IR matters
- Comfort working across multiple client environments, tooling stacks, and rules-of-engagement simultaneously
- Eligibility for Government of Canada security clearance (Secret or higher); existing clearance highly valued; or controlled-goods registration considered an asset
- Bilingualism (English/French) considered a strong asset
Why Malleum
- Test the systems behind programs with genuine national and allied security impact – across aerospace, defense, and critical infrastructure
- Join a rapidly scaling firm with a flat, high-trust culture and direct access to senior offensive, IR, and engineering leaders
- Exposure to a wide variety of advanced targets, sectors, and cleared environments
- Dedicated research time, lab budget, and support for conference talks, CVE research, and open-source contributions
- Competitive compensation, performance incentives, and comprehensive benefits
- Continuous learning budget, certification sponsorship (OSCP, OSEP, OSWE, CRTL, SANS), and clear paths into senior red team, exploit development, or offensive research specializations
Vacancy posted 18 days ago
Similar jobs that could be interesting for youBased on the Penetration Tester - Offensive Security in Ottawa, ON vacancy
- Penetration Tester / Red Team Consultant – Public Sector Location: Ottawa, Ontario About the Role We are seeking a Penetration Tester / Red Team Consultant to conduct offensive security assessments across government applications, cloud environments, infrastructure, and...Suggested
- Penetration Tester / Red Team Consultant – BFSI Location: Ottawa, OntarioAbout the Role We are seeking a Penetration Tester / Red Team Consultant to perform offensive security assessments across banking applications, cloud environments, infrastructure, APIs, and digital...Suggested
$90 per hour
...contract opportunity from March to December 2026. ~ Successful candidates will need to hold or obtain a Reliability Government of Canada security clearance. Work as part of a cross-functional agile scrum team to deliver bug fixes for a social services transformation project...SuggestedFull timeContract workRemote work- ...Job Responsibility: Title IT Security VA Specialist Location Ottawa, ON (On Site) Start... ...Undertake engagements that may perform penetration testing against a system of networked devices... ...; 14 Provide security advice from an offensive perspective; conduct security related...SuggestedFull timeInternship
$198k per year
...cybersecurity solutions across multiple security domains. ~ Must hold... ...~ Certifications related to offensive security including OSWE, BSCP... ...contribute to building a secure and resilient Canada. In this... ...offensive security assessments and penetration tests against mission-...SuggestedFull time$90k - $175k per year
...mentoring and on the job coaching -- As a seasoned network security architect, you will lead a team of consultant, be a trusted advisor... ...Security Architecture Team plays a critical role in delivering secure, resilient, and compliant solutions for our clients in a dynamic...Permanent employmentFlexible hoursShift work$68.82 - $103.23 per hour
Our client is seeking a fully remote Cyber Security Risk Analyst – Assurance to support executive cyber risk reporting in a regulated financial... ...Security Assurance, the Consultant will translate TRA and penetration test findings into clear business risk insights, apply NIST and...Full timeContract workRemote work$18.35 per hour
...Ready to suit up as a Security Guard What matters most in a role like this is your ability to adapt from one mission to the next. You embrace change and thrive in the heart of the action. As a casual Security Guard, your role will vary depending on the day and special...Hourly payCasual workFlexible hoursShift work- ...We’re hiring at Phoenix Private Security! Phoenix Private Security is expanding our team and we’re looking for professional Security Guards to support our Tactical Unit and Concierge Unit at malls and hotels. We have both part-time and full-time positions available. Key...Full timePart timeSeasonal workNight shiftWeekend workAfternoon shift
- ...Company Overview: We are North America's leading security and facility services provider with approximately 300,000 service personnel. At Allied Universal(R), we pride ourselves on fostering a promote from within culture. There are countless examples of individuals who began...Full timePart timeImmediate startShift workAfternoon shift
$70.6k - $127k per year
...Are you excited about working with cutting-edge web security systems? Do you relish opportunities to create improvements for our customers... ...customer experiences through innovative solutions. Help us secure the internet for our customers As a Security Consultant, serve...Work at officeLocal areaWork from home$91.83k - $119.37k per year
...Internal (DCC Employees) and External (General Public)Salary Range: $91,826 - $119,370Employment status: Term Term Length: 24 months Security Level: Reliability Language Requirement: Bilingual Preferred Closing Date: 06/06/2025Country: Canada The Cyber Security Analyst...Long term contractPermanent employmentFull timeTemporary workWork at officeWork from home- ...des infirmières et infirmiers autorisés de l’Ontario. Votre impact au sein de l’équipe Sous la responsabilité du gestionnaire, Sécurité et Stationnement, le coordonnateur de la sécurité est responsable de la supervision du travail effectué par l’équipe du Service de la...Work at officeDay shift
- ...ADGA Group is a Canadian-owned defence and security company that provides integrated, mission-critical technical solutions to Government and industry, specializing in C5ISRT, simulation and training, cyber and infrastructure security, and program delivery. With nearly 60...Full timeContract workTemporary workPart timeInternshipFlexible hours
- ...ADGA Group is a Canadian-owned defence and security company that provides integrated, mission-critical technical solutions to Government and industry, specializing in C5ISRT, simulation and training, cyber and infrastructure security, and program delivery. With nearly 60...Full timeContract workTemporary workPart timeInternshipFlexible hours
$140k - $300k per year
...Job Description: Responsibilities: Conduct blockchain security research and code security audits. Explore cutting-edge technologies like blockchain, plan and implement strategies in advance. Identify and analyze vulnerabilities related to blockchain, including exchanges...Full timeRelocation$20 per hour
...Ready to suit up as a Tactical Security Guard What matters most in a role like this is your ability to read the environment, anticipate... ...activity Check identification and control access to secure areas React quickly to threats or incidents and document actions...Hourly payFull timeCasual workFlexible hoursShift work$126.77k per year
...personnes d’origine autochtone, personnes handicapées, femmes ou membres d’une minorité visible ou d’un groupe racisé). Architecte en sécurité infonuagique Tenez un rôle central La Banque du Canada s’est donnée comme vision d’être une banque centrale influente –...Permanent employmentSummer workWork at officeRemote workWork from homeFlexible hours- ...Company Overview: We are North America's leading security and facility services provider with approximately 300,000 service personnel. At Allied Universal(R), we pride ourselves on fostering a promote from within culture. There are countless examples of individuals who began...Long term contractPermanent employmentFull timeFor contractorsWork at officeFlexible hoursShift work
- ...advances how people connect and transforms what’s possible, you belong on #TeamBell. Key Responsibilities We are seeking a Security Operations Analyst to join our team. This is an exciting opportunity for a motivated individual to develop their skills in a fast‑...Full timeWork at officeShift work3 days per week
$27.51 per hour
...more than 500,000 children and youth from Eastern Ontario, western Quebec, Nunavut and Northern Ontario. POSITION SUMMARY The Security Guard provides assistance to patients, staff and visitors by responding to code calls, conducting investigations, security patrolling...Local area- ...to go. Join EY and help to build a better working world. The opportunity We are seeking a Senior Advisor for Defence and Security to play a pivotal role in strengthening EY’s presence across Canada’s Government & Public Sector, with a focus on the Department of...
- ...Company Overview: We are North America's leading security and facility services provider with approximately 300,000 service personnel. At Allied Universal(R), we pride ourselves on fostering a promote from within culture. There are countless examples of individuals who began...Permanent employmentFull timeWork at officeMonday to fridayShift work
- ...Résumé Notre équipe de prestation de services professionnels en sécurité a un besoin immédiat un(e) architecte de solutions de livraison... .... Certifications avancées : CISSP-ISSAP (Information Systems Security Architecture Professional), TOGAF, SABSA ou certifications de...Daily paidPermanent employmentFull timeWork at officeFlexible hours
- ...trusted advisors capable of delivering at the intersection of national security, allied intelligence cooperation, and enterprise resilience. Our consultants embed directly with clients to design, secure, and operate the networks and systems behind cutting-edge defensive technologies...Full timeRemote workShift workWeekend workAfternoon shift
- ...As a Senior Technician - Security Systems with Bosch Building Technologies, you will collaboratively review, understand, analyze, and implement installation blueprints and plans from Project Managers and Sales Teams to complete installations. This role requires the ability...Full timeContract workWork at officeLocal areaRemote workNight shift
$17.85 per hour
...Company Overview: We are North America's leading security and facility services provider with approximately 300,000 service personnel... ...successful candidate will be responsible for maintaining a safe and secure environment through regular patrols, monitoring, incident...Hourly payFull timePart timeFor contractorsShift workWeekend work- ...Company Overview: We are North America's leading security and facility services provider with approximately 300,000 service personnel. At Allied Universal(R), we pride ourselves on fostering a promote from within culture. There are countless examples of individuals who began...Hourly payFull timeContract workPart timeWork at officeMonday to fridayShift workNight shiftRotating shift
$30.57 per hour
...for monitoring and operating centralized Fire, HVAC, CCTV , and Security systems in a dedicated Security Operations Centre (SOC). You will... ...Easy access by public transit to the Gallery, downtown Ottawa. Secure on-site indoor bicycle storage. Staff showers and change rooms....Hourly payFull timeContract workInternshipNight shiftDay shift$122.9k - $162.8k per year
...WSP . The Opportunity Shape Something Different - Ready to design and deliver cutting-edge security solutions? This is your opportunity to shape the future of secure environments. Join our Ottawa Building Technology Team and take the lead on major, multidisciplinary...Full timeLocal areaRemote workFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Penetration Tester - Offensive Security. Be the first to apply!
