Penetration Testing Lead (Contract)
$90.00/hr
Sign in to apply
New here? Create a free account in under a minute.
ascio is hiring a Penetration Testing Lead to support our offensive security and penetration testing work across networks, applications, APIs, cloud environments and identity platforms.
This role will plan, perform and report penetration tests using a documented methodology and agreed rules of engagement, and will validate remediation through retesting.
Responsibilities
- Scope external, internal, web application, API, cloud and wireless penetration tests and define appropriate rules of engagement.
- Perform reconnaissance, vulnerability discovery, manual exploitation and post-exploitation activities within agreed limits.
- Coordinate additional testers where required.
- Prepare detailed technical reports including reproduction steps, supporting evidence, severity ratings and remediation guidance.
- Prepare executive summaries and present findings to technical teams and management.
- Retest remediated findings and document closure or remaining risk.
Required Skills and Experience
- Six or more years of experience in penetration testing or offensive security.
- Strong experience conducting external and internal network penetration testing, including segmentation testing and lateral movement.
- Web application and API testing experience using the OWASP Web Security Testing Guide and OWASP API Security Top 10.
- Active Directory and Microsoft Entra ID attack path analysis, privilege escalation and identity security testing.
- Cloud configuration and identity testing experience in Microsoft Azure or AWS.
- Strong manual vulnerability validation and exploitation skills, beyond automated scanner output.
- Hands-on experience with tools such as Burp Suite Professional, Nmap, Metasploit, BloodHound, Impacket and Nessus.
- Demonstrated ability to conduct testing safely in production environments and securely handle sensitive evidence and test data.
- Strong written and verbal communication skills, with the ability to explain technical findings clearly to both technical and non-technical audiences.
Qualifications
- One or more current hands-on penetration testing certifications such as OSCP, CREST CRT, CREST CCT, GPEN or an equivalent recognized certification.
- Applicants must be able to provide certification status and expiry dates, where applicable.
- Degree or diploma in computer science, cybersecurity or a related field, or equivalent professional experience.
- OSEP, OSCE, OSWE, CRTO, GWAPT, GXPN or CISSP are considered assets.
Preferred Experience
- Red team or adversary emulation engagements.
- Mobile application testing across iOS and Android.
- Secure code review.
- Wireless security testing.
- Social engineering and phishing simulation.
Location and Work Arrangement
- Remote within Canada.
- Some assignments may require occasional onsite work or travel within Canada.
- Applicants must be based in Canada and legally entitled to work in Canada.
- A criminal record check may be required before access to sensitive systems, information or environments.