Senior Security Engineer - Pentester @Menlo Security
All Others
Salary cad 158,000 - 2..
Remote Location
Employment Type full-time
Posted 2mths ago

[Hiring] Senior Security Engineer - Pentester @Menlo Security

2mths ago - Menlo Security is hiring a remote Senior Security Engineer - Pentester. πŸ’Έ Salary: cad 158,000 - 237,000 per year πŸ“Location: Canada

Role Description

We're looking for a forward-thinking Security Engineer to join our security team, focused on offensive and defensive testing, penetration testing of product features, and the cloud architecture behind the product. You'll operate across a complex multi-cloud environment (AWS & GCP) spanning traditional VMs and modern managed and unmanaged container-based architectures, partnering with fellow Penetration Testing and Cloud Security engineers to run targeted assessments during the testing window immediately before each release.

The role reaches beyond the application layer into the Control Plane, reviewing cloud configurations, IAM policies, and orchestration layers against security baselines, and extends to the frontline of external defense by triaging bug bounty submissions and outside vulnerability reports. AI and large language models are core to how this team works day to day β€” you'll use them to accelerate reconnaissance, generate attack vectors, analyze configurations, and draft vulnerability reports, while applying human judgment to validate findings and communicate risk clearly to product teams. Speed matters here: the team's operating cadence is built around identifying, validating, and reporting vulnerabilities quickly enough to keep pace with release velocity.

Outcomes & KPIs

  • Ensure new product features and the underlying multi-cloud (AWS/GCP) infrastructure are rigorously security-tested before release.
  • Vulnerabilities surfaced internally or via bug bounty are triaged and communicated with speed and precision.

Success Metrics / KPIs:

  • Percentage of roadmap features assessed within the pre-release testing window.
  • Mean time to triage and validate bug bounty / external vulnerability reports.
  • Reduction in critical/high-severity vulnerabilities escaping to production post-release.
  • Time saved per assessment cycle through AI-assisted tooling and automation.
  • Quality and actionability of vulnerability reports and PoCs, as rated by product teams.

What You'll Do

  • Conduct deep-dive penetration tests of products across a multi-cloud (AWS & GCP) environment, working in tandem with a peer pentester.
  • Review IAM policies, service configurations, and cloud-native permission structures across the Control Plane to ensure cloud configurations meet security baselines.
  • Execute dynamic testing against web interfaces and API endpoints (Data Plane & Web UI).
  • Assess the security posture of hybrid infrastructure spanning containers and virtual machines.
  • Triage findings, build clear and reproducible proofs-of-concept, and partner with product teams to explain risk and drive remediation.
  • Use AI and large language models to automate reconnaissance, generate attack vectors, analyze configurations, and draft vulnerability reports, applying strong prompt-engineering skills to security contexts.
  • Monitor bug bounty pipelines and external reports, validating findings and managing researcher communication.

Functional Competencies

Required:

  • Multi-Cloud Fluency: Deep architectural understanding of GCP and AWS.
  • Container Security: Proven experience auditing and hardening managed container services (GKE Autopilot/Standard, EKS, ECS) and self-hosted/unmanaged workloads (K8s, k3s, OCI-runc).
  • AI Tooling: Demonstrated ability to integrate AI/LLM tools (e.g., Gemini, Claude) into the pentesting lifecycle.
  • Web Application Security: Expert-level knowledge of web application security principles and offensive testing methodologies.
  • Security Automation: Proficiency in Python, Go, or Bash to eliminate "toil".
  • Infrastructure as Code: Solid grasp of Terraform and cloud-native deployment patterns.
  • Communication: Ability to write high-quality technical reports that Product Teams can easily understand and act upon.

Preferred / Nice to Have:

  • Experience with Gatekeeper policies and Binary Authorization.

Benefits

  • Base Salary range for this role is 158,000 CAD - 237,000 CAD.
  • All employees may be eligible to become Menlo Security shareholders through eligibility for stock-based compensation grants.
Before You Apply
️
remote Be aware of the location restriction for this remote position: Canada
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Security Engineer - Pentester @Menlo Security
All Others
Salary cad 158,000 - 2..
Remote Location
Employment Type full-time
Posted 2mths ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Canada
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 127,100+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later