Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Security Engineer pentesting Menlo Security’s cloud-based security products across AWS, GCP, containers, APIs, and web interfaces. Using AI-assisted tooling to validate vulnerabilities and accelerate remediation before releases.

Responsibilities

  • Conduct deep-dive penetration tests of products across AWS and GCP environments, working with a peer pentester
  • Review IAM policies, service configurations, and cloud-native permission structures across the Control Plane against security baselines
  • Execute dynamic testing against web interfaces and API endpoints across the Data Plane and Web UI
  • Assess the security posture of hybrid infrastructure spanning containers and virtual machines
  • Triage findings and create clear, reproducible proofs of concept
  • Partner with product teams to explain risk and drive remediation
  • Use AI and large language models to automate reconnaissance, generate attack vectors, analyze configurations, and draft vulnerability reports
  • Monitor bug bounty pipelines and external reports, validate findings, and manage researcher communication
  • Ensure product features and multi-cloud infrastructure are rigorously security-tested before release
  • Track assessment coverage, triage speed, vulnerability escape rates, AI-assisted time savings, and report quality

Requirements

  • Deep architectural understanding of GCP and AWS
  • Ability to perform manual reviews of complex IAM and resource hierarchies
  • Experience with native cloud APIs or CSPM frameworks
  • Proven experience auditing and hardening GKE Autopilot/Standard, EKS, ECS, Kubernetes, k3s, and OCI-runc workloads
  • Demonstrated ability to integrate AI/LLM tools such as Gemini and Claude into the pentesting lifecycle
  • Expert knowledge of web application security and offensive testing methodologies
  • Deep proficiency in OWASP Top 10 vulnerabilities, modern web framework exploitation, and REST/WebSocket API security
  • Extensive hands-on experience with Burp Suite Professional, OWASP ZAP, or similar tools
  • Understanding of CSP, CORS, SameSite cookies, Subresource Integrity, OAuth 2.0, OIDC, JWT, HSTS, X-Frame-Options, and Permissions-Policy
  • Ability to identify complex flaws beyond automated scanners and validate them with proofs of concept
  • Proficiency in Python, Go, or Bash
  • Solid grasp of Terraform, cloud-native deployment patterns, and HCL auditing
  • Ability to write high-quality technical reports for product teams
  • Experience with Gatekeeper policies and Binary Authorization is preferred

Benefits

  • Base salary range of 158,000 CAD - 237,000 CAD
  • Eligibility for stock-based compensation grants based on company and individual performance
  • Collaborative, inclusive, and fun culture
  • Opportunities to take initiative and implement new ideas
  • Open communication and support for new ideas

Job title

Job type

Full Time

Experience level

Senior

Salary

CA$158,000 - CA$237,000 per year

Degree requirement

No Education Requirement

Tech skills

AWSCloudGoogle Cloud PlatformKubernetesPythonTerraformGo

Location requirements

RemoteCanada

Report this job

Found something wrong with the page? Please let us know by submitting a report below.