Senior Ethical Hacker
Stantec
Date: 3 hours ago
City: Fredericton, NB
Contract type: Full time
At Stantec, we have some of the world’s leading professionals passionate about enabling our business to be its best. Our business teams include finance, procurement, human resources, information technology, marketing, corporate development, HSSE, real estate, legal, and practice services. We bring diverse backgrounds, skills, and expertise and create a caring culture where everyone can thrive. Through teamwork and collaboration, we’re building a stronger, more resilient Stantec every day.
Your Opportunity
The Senior Ethical Hacker will conduct security assessments on web applications and cloud services by emulating real-world attacks using the Mitre Attack Framework. Their goal is to identify security weaknesses, help prevent data breaches and enhance the security posture by uncovering vulnerabilities, misconfigurations, and risks proactively before they are discovered by threat actors.
Your Key Responsibilities
Communication
Benefits Summary: Regular full-time and part-time employees (working at least 20 hours per week) will have access to health, dental, and vision plans, a wellness program, health care spending account, wellness spending account, group registered retirement savings plan, employee stock purchase program, group tax-free savings account, life and accidental death & dismemberment (AD&D) insurance, short-term/long-term disability plans, emergency travel benefits, tuition reimbursement, professional membership fee coverage, and paid time off.
Temporary/casual employees will have access to group registered retirement savings plan, employee stock purchase program, and group tax-free savings account.
The benefits information listed above may not apply to union positions because benefits for such positions are governed by applicable collective bargaining agreements.
Primary Location: Canada | ON | Toronto
Other Locations: Canada | NB | Fredericton
Organization: BC-1374 IT Services-CA Corporate
Employee Status: Regular
Business Justification: Replacement
Travel: No
Schedule: Full time
Job Posting: 19/08/2026 12:08:45
Req ID: 1007230
\#additional
Your Opportunity
The Senior Ethical Hacker will conduct security assessments on web applications and cloud services by emulating real-world attacks using the Mitre Attack Framework. Their goal is to identify security weaknesses, help prevent data breaches and enhance the security posture by uncovering vulnerabilities, misconfigurations, and risks proactively before they are discovered by threat actors.
Your Key Responsibilities
Communication
- Collaborate with cross-functional teams (security, engineering, cloud and network operations).
- Create reports and communicate findings to various technical teams, architects and engineers.
- Create and communicate processes that could help engineering teams meet remediation goals.
- Create and verbally present your test findings in debrief meetings with the C-Suite or sponsors.
- Conduct penetration tests on cloud systems, applications and APIs to identify vulnerabilities.
- Assess cloud/application specific configurations, access controls, and encryption mechanisms.
- Validate and exploit security findings within web/thick client apps and cloud environments.
- Validate various app services, databases, Kubernetes, serverless functions, container instances,
- images and cloud storage blob/buckets for security issues.
- Assist/Create rules of engagement for new pen test projects.
- Architect automated workflows for independent security evaluation and assurance processes
- Establish and enforce security baseline controls through Policy-as-Code implementations
- Engineer custom Python, Terraform, and Ansible extensions to enable specialized security and
- infrastructure use cases
- Create or populate content in the internal training lab so developers and security champions can stay
- current in offensive security with practical CTF's when time permits.
- Provide live hacking webinars for teams interested in learning by example.
- Conduct internal Red Team engagements.
- Participate in purple team engagements.
- Minimum 5-7+ years working in some aspect of cybersecurity (Offensive Security, Red Team
- experience preferred).
- Proficient with manual web/cloud penetration testing without using any tools.
- Proficient writing custom attack tools in Python, PHP, Golang and Bash Scripting.
- Proficient with interception proxies and attacking manually via Burp Suite Enterprise tool.
- Proficient building/maintaining attack automation systems (Commercial or Open-Source).
- Proficient building containers and automation pipelines for attacking purposes.
- Experience combining multiple low/medium findings to weaponize and achieve a higher level.
- Comfortable working exclusively from Windows or Linux command line.
- Comfortable "living off the land" using VIM/VI/Bash/SH/Perl/VBScript/WMI/PowerShell for post
- exploitation and lateral movement.
- Comfortable with writing XSS attacks, System/SQL injection payloads or weaponizing binaries.
- Comfortable attacking various popular public cloud services in (Azure/AWS/GCP/Oracle).
- Comfortable presenting audit findings to a small group or C-Suite during debrief meetings.
- Comfortable taking ownership for testing actions and performing blameless post-mortems.
- OffSec Web Expert (OSWE) - Preferred
- OffSec (OSAI) - Preferred
- GIAC Web Application Penetration Tester (GWAPT)
- Burp Suite Certified Practitioner (BSCP)
- Pentester Academy Cloud Security Professional (PACSP)
- AI/LLM Penetration testing experience
- Acknowledged findings in a responsible disclosure or public, private Bug Bounty program.
- Certified Kubernetes Security Specialist (CKS)
- Terraform Associate (003)
- DevSecOps experience
- Minimum 5 years relevant experience.
- Related Degree or Certificate, preferably in areas of Offensive Security, AI Red Teaming or Application
- Security
- Locations Outside of Lower Mainland - BC & Various locations in Ontario-$105,400.00 - $158,100.00 Annually
- Locations in Lower Mainland -- BC, GTA & Ottawa Ontario-$114,600.00 - $164,600.00 Annually
Benefits Summary: Regular full-time and part-time employees (working at least 20 hours per week) will have access to health, dental, and vision plans, a wellness program, health care spending account, wellness spending account, group registered retirement savings plan, employee stock purchase program, group tax-free savings account, life and accidental death & dismemberment (AD&D) insurance, short-term/long-term disability plans, emergency travel benefits, tuition reimbursement, professional membership fee coverage, and paid time off.
Temporary/casual employees will have access to group registered retirement savings plan, employee stock purchase program, and group tax-free savings account.
The benefits information listed above may not apply to union positions because benefits for such positions are governed by applicable collective bargaining agreements.
Primary Location: Canada | ON | Toronto
Other Locations: Canada | NB | Fredericton
Organization: BC-1374 IT Services-CA Corporate
Employee Status: Regular
Business Justification: Replacement
Travel: No
Schedule: Full time
Job Posting: 19/08/2026 12:08:45
Req ID: 1007230
\#additional
How to apply
To apply for this job you need to authorize on our website. If you don't have an account yet, please register.
Post a resumeSimilar jobs
Customer Rep-Station
FedEx Canada,
Fredericton, NB
3 hours ago
This is an interview position.To provide accurate information and assistance to customers requiring direct customer interface. To perform administrative duties necessary for efficient operations. Promotes continued sales and generating potential incremental revenue wherever possible.Required Knowledge, Skills And AbilitiesHigh school diploma/equivalent. College diploma preferredKnowledge of Canadian Customs regulations preferredKnowledge of FedEx Express and Ground products and services preferredAbility to successfully complete...
Sales Pro
Advance Auto Parts,
Fredericton, NB
3 weeks ago
Job DescriptionAdvanced level DIY sales position with expert knowledge of DIY business. The role has expert knowledge of store operations, advanced automotive system knowledge and parts knowledge. This role is responsible for providing advanced automotive problem resolution including identification, trouble shooting and project assistance for DIY customers. The role has the ability to source from numerous places including special order,...
Grocery Clerk Part Time Night
Loblaw Companies Limited,
Fredericton, NB
4 weeks ago
Come make your difference in communities across Canada, where authenticity, trust and making connections is valued – as we shape the future of Canadian retail, together. Our unique position as one of the country's largest employers, coupled with our commitment to positively impact the lives of all Canadians, provides our colleagues a range of opportunities and experiences to help Canadians...