Senior Ethical Hacker at Stantec | CA | Rezi

Senior Ethical Hacker at Stantec

Senior Ethical Hacker

Stantec · CA

1 months ago

Senior Ethical Hacker

Stantec · CA

a month ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Senior Ethical Hacker role.

Rezi rewrites your resume against Stantec's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Senior Ethical Hacker posting at Stantec — free, in seconds.

About the Role

The Senior Ethical Hacker will conduct security assessments on web applications and cloud services by emulating real-world attacks using the Mitre Attack Framework. Their goal is to identify security weaknesses, help prevent data breaches and enhance the security posture by uncovering vulnerabilities, misconfigurations, and risks proactively before they are discovered by threat actors.

Responsibilities

  • Collaborate with cross-functional teams (security, engineering, cloud and network operations).
  • Create reports and communicate findings to various technical teams, architects and engineers.
  • Create and communicate processes that could help engineering teams meet remediation goals.
  • Create and verbally present test findings in debrief meetings with the C-Suite or sponsors.
  • Conduct penetration tests on cloud systems, applications and APIs to identify vulnerabilities.
  • Assess cloud/application specific configurations, access controls, and encryption mechanisms.
  • Validate and exploit security findings within web/thick client apps and cloud environments.
  • Validate various app services, databases, Kubernetes, serverless functions, container instances, images and cloud storage blob/buckets for security issues.
  • Assist/Create rules of engagement for new pen test projects.
  • Architect automated workflows for independent security evaluation and assurance processes.
  • Establish and enforce security baseline controls through Policy-as-Code implementations.
  • Engineer custom Python, Terraform, and Ansible extensions to enable specialized security and infrastructure use cases.
  • Create or populate content in the internal training lab so developers and security champions can stay current in offensive security with practical CTF's when time permits.
  • Provide live hacking webinars for teams interested in learning by example.
  • Conduct internal Red Team engagements.
  • Participate in purple team engagements.

Requirements

  • Emulate real-world attacks using the Mitre Attack Framework.
  • Identify security weaknesses, prevent data breaches, and enhance security posture.
  • Uncover vulnerabilities, misconfigurations, and risks proactively.

Skills

  • Python
  • Terraform
  • Ansible
  • Web applications
  • Cloud services
  • Cloud systems
  • APIs
  • Kubernetes
  • Serverless functions
  • Container instances
  • Cloud storage
  • Policy-as-Code

Experience Level

  • Senior

Benefits

  • Health, dental, and vision plans
  • Wellness program
  • Health care spending account
  • Wellness spending account
  • Group registered retirement savings plan
  • Employee stock purchase program
  • Group tax-free savings account
  • Life and accidental death & dismemberment (AD&D) insurance
  • Short-term/long-term disability plans
  • Emergency travel benefits
  • Tuition reimbursement
  • Professional membership fee coverage
  • Paid time off

About the Company

  • At Stantec, we have some of the world’s leading professionals passionate about enabling our business to be its best.
  • Our business teams include finance, procurement, human resources, information technology, marketing, corporate development, HSSE, real estate, legal, and practice services.
  • We bring diverse backgrounds, skills, and expertise and create a caring culture where everyone can thrive.
  • Through teamwork and collaboration, we’re building a stronger, more resilient Stantec every day.

Equal Opportunity

  • In compliance with pay transparency laws, pay ranges are provided for positions in locations where required.
  • The final agreed upon compensation is based on individual education, qualifications, experience, and work location.
  • At Stantec certain roles are bonus eligible.
  • Actual compensation for part-time roles will be pro-rated based on the agreed number of working hours per week.