About the Role
The Web Application Penetration Tester will contribute to Wawanesa’s success by delivering security testing services to enterprise client groups, ensuring internally-developed web applications and APIs are free of design flaws or vulnerabilities prior to release.
Responsibilities
- Perform evaluations of client systems, web applications, APIs and their supporting networks to discover vulnerabilities.
- Configure, run, and monitor automated security testing tools.
- Thoroughly document exploit chain/proof of concept scenarios for internal client consumption.
- Assist clients with the design, implementation, and/or monitor security measures for the protection of web applications.
- Identify, define, and/or implement system security requirements for external and internal facing web applications.
- Assist with vulnerability risk assessments.
- Follow established practices and processes.
- Perform role in cyber incident response as required.
- Generate reports based on test findings.
- Perform other duties as assigned.
Requirements
- Bachelor’s degree in computer science, an analytical discipline or equivalent experience.
- 1+ year of web application security testing experience.
- Knowledge of Web application vulnerabilities and security considerations.
- Working knowledge of industry standard technical security controls.
- Familiarity with vulnerability assessment and penetration best practices.
- Experience with vulnerability and penetration testing techniques and tools.
- Experience with Burp Suite.
- Experience testing web and mobile platforms.
- Experience working with markup, scripting, and programming languages such as HTML, XML, JavaScript, PHP, Perl, Python, Bash, ASP, C++, C#, Java, and .NET.
- Must have an ability to communicate effectively, both verbally and in writing.
- Ability to interact effectively with internal teams (such as developers, project team members, and management) to build relationships and use facilitation skills with both technical and non-technical personnel.
- Ability to work independently and within a team.
- Knowledge of and experience in the insurance industry is considered an asset.
Skills
- Web application security testing
- Automated security testing tools
- Vulnerability risk assessments
- Cyber incident response
- HTML
- XML
- JavaScript
- PHP
- Perl
- Python
- Bash
- ASP
- C++
- C#
- Java
- .NET
Location
- Winnipeg, MB
- Wawanesa, MB
- Vancouver, BC
- Calgary, AB
- Edmonton, AB
- Lethbridge, AB
- Toronto (North York), ON
- Kitchener, ON
- Ottawa, ON
- Montreal, QC
- Quebec City, QC
- Moncton, NB
- Dartmouth, NS
Work Type
- Hybrid
- Remote
- Onsite
Experience Level
- 1+ year of web application security testing experience
Education Level
- Bachelor’s degree in computer science, an analytical discipline or equivalent experience
- GIAC Penetration Tester (GPEN)
- GIAC Web Application Penetration Tester (GWAPT)
- GIAC Certified Incident Handler (GCIH)
- Offensive Security Certified Expert (OSCE)
- Offensive Security Certified Professional (OSCP)
Salary/Compensations
- $90,000 - $110,000
Benefits
- Annual bonus plan
- Leave of absence top-up programs
- Generous vacation time
- Personal days
- Premium free benefits
- Pension plan
About the Company
- Founded in 1896, The Wawanesa Mutual Insurance Company is one of Canada’s largest mutual insurers, 100% owned by its members, with more than $4.1 billion in annual revenue and $12.5 billion in assets.
- Headquartered in Winnipeg, Wawanesa is the parent company of Wawanesa Life, which provides life insurance solutions throughout Canada, and Western Financial Group, a leading national distributor of personal and business insurance.
- In March of 2026, Wawanesa entered into an agreement to acquire Everest Insurance Company of Canada to strengthen its commercial insurance capabilities and advance its long-term growth strategy.
- Wawanesa proudly serves more than 1.8 million members and is home to more than 3,000 employees across Canada.
- The company actively gives back to organizations that strengthen communities, donating more than $4 million annually to charitable organizations, including more than $2 million each year in support of people on the front lines of climate change.
Equal Opportunity
- At Wawanesa, we are committed to Diversity, Equity, Inclusion and Belonging (DEIB) and believe that our strength lies in the diversity of our people – this is supported by having a representative workforce.
- We welcome applications from all qualified candidates, including racialized persons, women, Indigenous Peoples, persons with disabilities, members of the 2SLGBTQIA+ community, gender-diverse and neurodiverse individuals, and anyone who can contribute to the further diversification of thought and ideas.
- We aim to ensure our recruitment process is accessible to all candidates. If you require accommodations during any stage of the recruitment process, please reach out in confidence to jobs@wawanesa.com.
- All Wawanesa job applicants are subject to Wawanesa's Privacy Policy.
- Please note that the recruitment process for this position may involve the use of AI tools to screen, assess, or select applicants. All final decisions are taken or reviewed by human recruiters and human hiring leaders in compliance with all applicable legislation.
