Offensive Security Analyst responsible for intrusion tests and enhancing security posture at iA Financial Group. Collaborating with teams to document findings and improve detection mechanisms.
Responsibilities
plan and perform intrusion tests on web applications, APIs, cloud environments, internal infrastructures
set up and participate in purple team exercises simulating real attack scenarios
collaborate with defensive teams to validate controls and improve detection mechanisms
document findings, provide remediation recommendations, and present results to stakeholders
stay informed about emerging threats, tools, and techniques in offensive security
work with a high degree of autonomy and initiative
Requirements
3 to 5 years of experience in offensive security
7 years of experience in information technology (IT)
knowledge of the OWASP Top 10, MITRE ATT&CK, and threat-modeling frameworks
ability to perform intrusion tests on various infrastructures
proficiency with offensive security tools such as Burp Suite, Nmap, Nessus, BloodHound, Metasploit, Cobalt Strike
strong ability to communicate technical concepts clearly
intermediate level of English and French proficiency
certifications such as OSCP, OSWE, OSEP, CRTP, GPEN, CPTS are strong assets
experience in scripting (Python, Bash, PowerShell) for automation and exploit development
experience with Infrastructure as Code, such as Terraform
Threat Intelligence Analyst investigating telecom security threats and customer deployment data for Enea, a global telecom and cybersecurity software company. Supporting client security reviews and threat intelligence operations.
Information Security Analyst governing End - User Computing risks, controls, and remediation for TD, a major North American bank. Advising stakeholders and supporting governance reporting, audits, and regulatory requirements.
IT Security Analyst II coordinating cybersecurity monitoring, MSP oversight, audits, and incident follow - up. Supporting Veristat’s global life - sciences services and regulated technology environments.
Security Analyst protecting GitLab’s DevSecOps platform through vulnerability triage and CVE operations. Coordinating researchers, customers, and internal teams on secure software response.
SIEM/SOAR cybersecurity analyst monitoring threats, building alerts, and measuring controls. Supporting Wepoint’s digital transformation work for businesses and public sector organizations.
SIEM/SOAR information security analyst supporting Wepoint’s digital transformation services. Developing cybersecurity monitoring cases, alerts, dashboards, and security - control documentation.
Security Analyst II protecting Intact’s insurance operations through incident response and SIEM monitoring. Supporting security platforms, incident resolution, dashboards, and IT security initiatives.