Skip to main content
Menlo Security

Senior Security Engineer - Pentester

RemoteCanada only
Published
Role
Security
Experience
Senior
Employment
Full-time
CAD 158k–CAD 237k/yr
Check eligibility

Open to CA only. Set where you work from to check your eligibility.

No BS summary

Senior security engineer focused on penetration testing across AWS/GCP, containers, web apps, APIs, IAM, and cloud control planes. Must be Canada-based and able to use AI/LLM tooling in the pentesting workflow. Python, Go, or Bash automation and strong vulnerability reporting are required.

Core skills

GCPAWSPenetration Testing

Required skills

IAMCSPMGKE AutopilotGKE StandardEKSECSKubernetesk3sOCI-runcAI/LLM toolsGeminiClaudeOWASP Top 10API securityRESTWebSocketsBurp Suite Professional/OWASP ZAPCSPCORSSameSite cookiesSubresource IntegrityOAuth 2.0OIDCJWTHSTSX-Frame-OptionsPermissions-PolicyPython/Go/BashTerraformHCL

Optional skills

Gatekeeper policiesBinary Authorization

What you'll do

  • Conduct deep-dive penetration tests of products across a multi-cloud (AWS & GCP) environment, working in tandem with a peer pentester.
  • Review IAM policies, service configurations, and cloud-native permission structures across the Control Plane to ensure cloud configurations meet security baselines.
  • Execute dynamic testing against web interfaces and API endpoints (Data Plane & Web UI).
  • Assess the security posture of hybrid infrastructure spanning containers and virtual machines.
  • Triage findings, build clear and reproducible proofs-of-concept, and partner with product teams to explain risk and drive remediation.
  • Use AI and large language models to automate reconnaissance, generate attack vectors, analyze configurations, and draft vulnerability reports, applying strong prompt-engineering skills to security contexts.
  • Monitor bug bounty pipelines and external reports, validating findings and managing researcher communication.

What they require

  • Multi-Cloud Fluency: Deep architectural understanding of GCP and AWS. Capable of pivoting seamlessly between providers, performing manual configuration reviews of complex IAM/Resource hierarchies, and leveraging native APIs or modern CSPM frameworks to validate security controls.
  • Container Security: Proven experience auditing and hardening managed container services (GKE Autopilot/Standard, EKS, ECS) and self-hosted/unmanaged workloads (K8s, k3s, OCI-runc).
  • AI Tooling: Demonstrated ability to integrate AI/LLM tools (e.g., Gemini, Claude) into the pentesting lifecycle to increase speed and coverage.
  • Web Application Security: Expert-level knowledge of web application security principles and offensive testing methodologies, with deep proficiency in OWASP Top 10 vulnerabilities, modern web framework exploitation, and API security (REST, WebSockets).
  • Extensive hands-on experience conducting manual security assessments using Burp Suite Professional, OWASP ZAP, or similar tooling.
  • Strong understanding of browser security mechanisms (CSP, CORS, SameSite cookies, Subresource Integrity), secure authentication/authorization patterns (OAuth 2.0, OIDC, JWT), and security header configurations (HSTS, X-Frame-Options, Permissions-Policy).
  • Proven ability to identify complex security flaws beyond automated scanner detection, validate findings through proof-of-concept development, and provide actionable remediation guidance to engineering teams.
  • Security Automation: Proficiency in Python, Go, or Bash to eliminate "toil" — writing custom scripts and tooling to automate vulnerability discovery, validate security controls, and streamline testing workflows.
  • Infrastructure as Code: Solid grasp of Terraform and cloud-native deployment patterns; able to interpret and audit complex HCL files to identify misconfigurations before they are provisioned.
  • Communication: Ability to write high-quality technical reports that Product Teams can easily understand and act upon.
  • Preferred: Experience with Gatekeeper policies and Binary Authorization.

Benefits

  • Base Salary is one part of our competitive total compensation and benefits package and is determined using a salary range.
  • All employees may be eligible to become Menlo Security shareholders through eligibility for stock-based compensation grants, which are awarded to employees based on company and individual performance.

Menlo Security enables the world to connect, communicate and collaborate securely without compromise. It supports enterprise customers including Fortune 500 companies, 9/10 of the largest global banks, and the Department of Defense.

CybersecurityMid-size
CAD 158k–CAD 237k/yr