Penetration Testing Analyst
Job description
Job Description:At Sun Life, we work together, share common values, and encourage growth and achievement. We are seeking a skilled Penetration Testing Analyst to perform hands-on security testing of applications, infrastructure, and systems.This role is primarily focused on Penetration Testing delivery, with secondary exposure to Red Team activities, contributing to adversary simulation exercises where required. The successful candidate will have strong technical testing capabilities, with an interest in developing broader offensive security skills.Key ResponsibilitiesPerform web, API, mobile, and infrastructure penetration testing across enterprise applications.Identify, exploit, and validate security vulnerabilities using manual testing techniques and industry tools.Conduct testing in line with established methodologies and security frameworks (e.g., OWASP).Produce clear, structured reports outlining:Vulnerabilities and root causeBusiness impact and risk ratingPractical remediation recommendationsPerform research into new vulnerabilities, exploits, and attack techniques to enhance testing coverage.Support re-testing activities to validate remediation of identified issues.Support Red Team activities where required.Contribute to reconnaissance and attack surface mapping, Identification of potential attack paths.Support documentation of attack paths and identified security gaps.Assist in controlled exploitation activities under guidance, including:Initial access techniquesLimited post-exploitation validation (e.g., privilege escalation concepts, lateral movement awareness)Collaborate with senior team members to understand real-world attacker behaviour and techniques.Required Skills & ExperienceCore Penetration Testing Skills (Essential)2+ years of hands-on experience in:Web application security testing (OWASP Top 10)API security testingBasic network/infrastructure testingStrong understanding of:Authentication, session management, and access control flawsInput validation and injection vulnerabilitiesExperience with tools such as:Burp Suite, Nmap, sqlmap, or similarAbility to perform manual testing beyond automated scanning.Strong documentation and reporting skills, with focus on clear risk articulation.Red Teaming Skills (Desirable – Foundational Level)Basic understanding of adversary simulation concepts and attack lifecycle.Familiarity with:Reconnaissance techniquesCommon initial compromise methodsAwareness of:Privilege escalation and lateral movement conceptsAttack paths across enterprise environmentsInterest in developing Red Team and offensive security capabilities over time.QualificationsBachelor's degree in Computer Science, Information Security, or a related field.Certifications such as OSCP, OSWA, CISSP or CompTIA are desired but not required.Job Category:IT - Technology ServicesPosting End Date:30/12/2026","url":"https://ca.talent.com/view?id=621374193348186278","occupationalCategory":"15-1299.04
first seen 2026-05-28 04:24:01 · last verified 2026-10-11 05:00:01
pentestcareers.com // breach the job market