Summary
Wawanesa Insurance is one of Canada’s largest mutual insurers, and they are seeking a Web Application Penetration Tester to contribute to their security testing services. This role involves evaluating web applications and APIs for vulnerabilities, ensuring secure design and implementation for the company's internal systems.
Responsibilities
- Perform evaluations of client systems, web applications, APIs and their supporting networks to discover vulnerabilities
- Configure, run, and monitor automated security testing tools
- Thoroughly document exploit chain/proof of concept scenarios for internal client consumption
- Assist clients with the design, implementation, and/or monitor security measures for the protection of web applications
- Identify, define, and/or implement system security requirements for external and internal facing web applications
- Assist with vulnerability risk assessments
- Follow established practices and processes
- Perform role in cyber incident response as required
- Generate reports based on test findings
- Perform other duties as assigned
Skills
- Bachelor's degree in computer science, an analytical discipline or equivalent experience
- 1+ year of web application security testing experience
- Knowledge of Web application vulnerabilities and security considerations
- Working knowledge of industry standard technical security controls
- Familiarity with vulnerability assessment and penetration best practices
- Experience with the following: vulnerability and penetration testing techniques and tools
- Experience with Burp Suite
- Experience testing web and mobile platforms
- Experience working with markup, scripting, and programming languages such as HTML, XML, JavaScript, PHP, Perl, Python, Bash, ASP, C++, C#, Java, and .NET
- Possess or working towards one of the following certifications: GIAC Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), GIAC Certified Incident Handler (GCIH), Offensive Security Certified Expert (OSCE), Offensive Security Certified Professional (OSCP)
- Must have an ability to communicate effectively, both verbally and in writing, to interact effectively with internal teams (such as developers, project team members, and management) to build relationships and use facilitation skills with both technical and non-technical personnel
- Ability to work independently and within a team
- Knowledge of and experience in the insurance industry is considered an asset
Qualifications
Must Haves
- Bachelor's degree in computer science, an analytical discipline or equivalent experience
- 1+ year of web application security testing experience
- Knowledge of Web application vulnerabilities and security considerations
- Working knowledge of industry standard technical security controls
- Familiarity with vulnerability assessment and penetration best practices
- Experience with the following: vulnerability and penetration testing techniques and tools
- Experience with Burp Suite
- Experience testing web and mobile platforms
- Experience working with markup, scripting, and programming languages such as HTML, XML, JavaScript, PHP, Perl, Python, Bash, ASP, C++, C#, Java, and .NET
- Possess or working towards one of the following certifications: GIAC Penetration Tester (GPEN), GIAC Web Application Penetration Tester (GWAPT), GIAC Certified Incident Handler (GCIH), Offensive Security Certified Expert (OSCE), Offensive Security Certified Professional (OSCP)
- Must have an ability to communicate effectively, both verbally and in writing, to interact effectively with internal teams (such as developers, project team members, and management) to build relationships and use facilitation skills with both technical and non-technical personnel
- Ability to work independently and within a team
Nice to Haves
- Knowledge of and experience in the insurance industry is considered an asset
Benefits
- In addition to salary, full-time and part-time permanent employees are eligible for an annual bonus plan
- Leave of absence top-up programs
- Provided with generous vacation time
- Personal days
- Premium free benefits
- Pension plan