Offensive Security Analyst responsible for intrusion tests and enhancing security posture at iA Financial Group. Collaborating with teams to document findings and improve detection mechanisms.
Responsibilities
plan and perform intrusion tests on web applications, APIs, cloud environments, internal infrastructures
set up and participate in purple team exercises simulating real attack scenarios
collaborate with defensive teams to validate controls and improve detection mechanisms
document findings, provide remediation recommendations, and present results to stakeholders
stay informed about emerging threats, tools, and techniques in offensive security
work with a high degree of autonomy and initiative
Requirements
3 to 5 years of experience in offensive security
7 years of experience in information technology (IT)
knowledge of the OWASP Top 10, MITRE ATT&CK, and threat-modeling frameworks
ability to perform intrusion tests on various infrastructures
proficiency with offensive security tools such as Burp Suite, Nmap, Nessus, BloodHound, Metasploit, Cobalt Strike
strong ability to communicate technical concepts clearly
intermediate level of English and French proficiency
certifications such as OSCP, OSWE, OSEP, CRTP, GPEN, CPTS are strong assets
experience in scripting (Python, Bash, PowerShell) for automation and exploit development
experience with Infrastructure as Code, such as Terraform
Analyste en sécurité des produits chez Alithya, intégrant la sécurité de l’information aux projets technologiques. Évaluation des risques, recommandations et suivi des mesures de sécurité.
Intermediate SOC Analyst monitoring and responding to security incidents for Long View, a North American IT provider. Managing SIEM tools, cloud environments, escalations, and 24x7 operations.
Azure AD Security Analyst leading identity and access management for Intact, a Canadian insurer. Integrating Azure AD, supporting IAM architecture, automation, privileged access, and major incidents.
Analyste sécurité informatique chez Beneva, compagnie d’assurance et de services financiers. Intégration des contrôles IAM, analyse des exigences de sécurité et accompagnement des équipes applicatives.
Security Analyst leading Cyber Threat Exposure Management transformation for iA Financial Group, a Canadian insurance and wealth - management provider. Coordinating risk reduction, governance, and cross - functional CTEM initiatives.
Senior Security Risk Analyst at Twilio enhancing security risk management and collaborating with cross - functional teams. Focused on identifying and mitigating cyber risks effectively and ensuring compliance.