Senior Professional, Offensive Cyber Operations
Vancouver (VHO)
Teck Resources
Teck is Canada's largest diversified mining company and is committed to responsible development. It has major business units focused on copper, metallurgical coal, zinc, gold and energy. Shares are listed on the TSX under the symbols TECK.A and...Responsibilities
- Be a courageous safety leader, adhere to and sponsor safety and environmental rules and procedures
- Conduct security assessments that can be multi-faceted for both IT and OT environments
- Define the scope for security testing assignments
- Create interactive quality assurance security test reports and other documentation as needed
- Build trusting relationships with clients to develop appropriate remediation plans
- Provide exceptional service in a professional, courteous and timely manner
- Provide thought leadership, direction and advice for the Information Security practice on malware, attack vectors and methods to protect against threats
- Collaborate with colleagues in other service lines in support of needs for Information Security services
- Stay informed on current tools, technologies and vulnerabilities to incorporate into testing practices
Qualifications
- Degree in Computer Science, Information Systems, Engineering or related major from an accredited University or equivalent
- At least three (3) years experience working on vulnerability assessments and penetration tests
- Outstanding critical thinking and analytical skills
- Application and infrastructure penetration testing experience that transcends running automated tools
- A comprehensive understanding of Linux, Windows and network security skills
- Excellent written and verbal communication in English
- Ability to meet deadlines and deliver a high-quality product (reports)
- Thorough and accurate attention to detail
- Ability to work independently and perform as a leader in a collaborative group setting
- Nessus
- MetaSploit
- Burp Suite
- Kali
- NMap
- Fortify
- Acunetix
- EC-Council Certified Ethical Hacker (CEH)
- EC-Council Licensed Penetration Tester (LPT)
- GIAC Certified Penetration Tester (CPEN)
- IACRB Certified Penetration Tester (CPT)
- Offensive Security Certified Professional (OSCP)
- CREST Registered Tester (CRT)
- CREST Infrastructure Certification
- CESG CHECK Team Leader
- CESG CHECK Team Member
- Tiger Scheme Senior Security Tester
- Tiger Scheme Qualified Security Tester
- Any other recognized penetration testing certification/accreditation
Nice to Haves
- ISO27001 Lead Auditor
- CISSP, CISA, CISM Certifications
- CREST recognized penetration testing certification/accreditation (CREST Certified Tester (CCT) or CHECK Team Leader (CTL)
- Experience developing custom scripts or tools used for vulnerability scanning and identification
- Familiarity with threat modelling and security design review methodologies
- Support team technical progress (e.g. through service development or research) and contribute to company technical processes overall
- Development and/or source code review experience in C/C++, C#, VB.NET, ASP, PHP, or Java and/or Fortify, Veracode, Brakeman and/or IDA Pro
- Proficiency with physical security testing, phishing and social engineering techniques
- Experience with mobile applications such as Android DeBug Bridge (ADS), OWASP ZAP, Drozer, Mobile Security Framework (MobSF), Smartphone Pentest Framework (SPF), Burp Suite, Android SDK, Friday, Cydia and/or IDB
* Salary range is an estimate based on our salary survey 💰
Tags: Android Burp Suite C CEH CESG CHECK CISA CISM CISSP Computer Science CREST GIAC ISO 27001 Java Kali Linux Malware Metasploit Mobile security Nessus Network security Nmap Offensive security OSCP OWASP Pentesting PHP Security assessment Veracode Vulnerabilities Windows
Perks/benefits: Startup environment
More jobs like this
Explore more InfoSec / Cybersecurity career opportunities
Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.
- Open Electronic Warfare Advanced Tactical Trainer jobs
- Open Security Operations Analyst jobs
- Open Senior SOC Analyst jobs
- Open Senior Information Security Engineer jobs
- Open Analyste CERT / Incident Responder senior (H/F) jobs
- Open SOC Analyst jobs
- Open Staff Product Security Engineer jobs
- Open Information Systems Security Officer (ISSO) jobs
- Open Manager Pentest H/F jobs
- Open Ethical hacker / Pentester H/F jobs
- Open Analyste CERT / Incident Responder junior (H/F) jobs
- Open IT Security Analyst jobs
- Open Security Operations Engineer jobs
- Open Senior Cybersecurity Engineer jobs
- Open Staff Security Engineer jobs
- Open Cyber Security Specialist jobs
- Open IT Security Specialist jobs
- Open Infosec Risk Manager jobs
- Open Cyber Program Manager jobs
- Open o365 Security Architect jobs
- Open Cybersecurity Specialist jobs
- Open Staff Information Security Engineer jobs
- Open Cyber Hunt SME jobs
- Open Information System Security Officer (ISSO) jobs
- Open Senior Security Operations Engineer jobs
- Open Agile-related jobs
- Open SIEM-related jobs
- Open GCP-related jobs
- Open Clearance-related jobs
- Open Risk assessment-related jobs
- Open ISO 27001-related jobs
- Open Pentesting-related jobs
- Open Analytics-related jobs
- Open Java-related jobs
- Open IAM-related jobs
- Open Security assessment-related jobs
- Open DevOps-related jobs
- Open CISM-related jobs
- Open Vulnerability management-related jobs
- Open Kubernetes-related jobs
- Open APIs-related jobs
- Open Malware-related jobs
- Open Forensics-related jobs
- Open Threat intelligence-related jobs
- Open SaaS-related jobs
- Open DevSecOps-related jobs
- Open CI/CD-related jobs
- Open Cryptography-related jobs
- Open CISA-related jobs
- Open Encryption-related jobs