Desjardins Red Team advisor conducting adversary simulations and offensive cybersecurity operations. Developing stealth tools, attack chains and tradecraft to strengthen cyber defence.
Responsibilities
Perform adversary simulation and threat monitoring activities
Protect IT hardware, software and data against modification, destruction and accidental or unauthorized disclosure
Assist in authentication and access control by designing, administering and controlling proven security systems
Analyze IT system vulnerabilities and implement protective measures to back up, restore and secure systems
Lead practitioners on development projects and innovative, complex strategic initiatives
Develop IT security standards and policies
Make recommendations on complex projects and initiatives
Lead large-scale development projects, initiatives and activities with significant organizational impact
Advise clients and partners on positioning, planning, development, solution selection, execution and monitoring of strategic projects
Develop and update policies, standards, models and programs
Identify and analyze major issues, diagnose issues and make recommendations to decision-making bodies
Represent the unit before decision-making bodies
Represent Desjardins in agreements with external partners and organizations
Design, develop and implement attack chains for different levels of sophistication
Perform research and development to maintain and contribute to the team’s tradecraft
Work with cyber defence and insider threat teams to improve prevention, detection and response capabilities
Document and communicate detailed observations and recommendations in plain, simple language
Serve as specialist advisor, subject matter expert, resource person and coach for decision-making bodies
Requirements
Bachelor's degree in a related field
A minimum of six years of relevant experience
Please note that other combinations of qualifications and relevant experience may be considered
Strong oral and written communication skills in French
Expertise in offensive security as a Red Team operator and/or with stealth pentesting
Expertise in developing creative stealth tools and automating tasks in various programming languages
Expertise in operating with C2
Expertise in implementing and maintaining infrastructure with Terraform/Ansible
Proficiency in application security and infrastructure operations
General knowledge of defence mechanisms and business controls
Working knowledge of the MITRE ATT&CK framework
Knowledge of modern evasive techniques (for example, antivirus, EDR, NDR)
Product Security Engineer using frontier AI to discover vulnerabilities and red - team AI systems at Coinbase. Building offensive security tooling and automating vulnerability response workflows.
Expert Security Engineer building anti - cheat systems for Activision’s Call of Duty franchise. Strengthening game security, detection, performance, and fair play across studios.
Expert systèmes, réseaux et sécurité déployant et administrant les solutions de cybersécurité d’I - TRACING. Maintien des infrastructures critiques, gestion des incidents et automatisation des opérations à Montréal.
TD bank security lead overseeing audits, technology controls, and operational compliance for Business Banking platforms. Automating audit response and managing security risk remediation.
Senior security professional overseeing Canadian government contract security, controlled goods, audits, and clearances. Supporting Honeywell’s automation, aerospace, energy, and industrial solutions.
Senior Information Security Manager leading security operations, application security, and AI security. Protecting Benevity’s cloud - native platform that helps companies and employees take social action.
Senior information security manager leading operations, application, cloud, and AI security. Securing Benevity’s technology platform for corporate social - impact programs.
Conseiller senior en architecture de sécurité chez Exposant 3, firme de conseil en affaires et technologies de l’information. Évaluation des risques, gouvernance et architectures de sécurité numérique.