This one is closed
Live roles like this one
-
C
4h ago
Werkstudent (m/w/d) Schwachstellenmanagement: Von der SBOM zur Entscheidung
Langlauf Security Automation GmbH Lippstadt
-
C
20h ago
Senior Security Engineer, Identity and Access Management
HackerOne Netherlands, UK, USA
- D 17h ago
- C 1d ago
See every "Pen test platform" role →
Get new “Pen test platform” roles by email
One email a day with what is new in "Pen test platform". Nothing new, no email.
We confirm the address first, and every mail carries an unsubscribe link. Alerts are ours, not a third party's.
Why this grade This listing scored 27/100, which is an F. It lost the most ground on pay transparency. See the breakdown
- Description depth 20 / 20 How much the posting actually says about the work, measured in characters of real text.
- Remote clarity 8 / 15 Whether "remote" means anywhere, or is quietly restricted to one country.
- Corroboration 5 / 10 Whether more than one source carries this listing.
- Freshness 4 / 15 How recently it was posted. Older postings are likelier to be filled or abandoned.
- Role specificity 0 / 10 Whether the listing is tagged well enough to tell what the role actually is.
- Pay transparency 0 / 25 A published salary range, worth more than any other single factor because it is what a candidate cannot find out without applying.
-10 Ghost-job penalty — Deducted for signals that this posting may not be a real, currently-open role — staleness, repeated relisting, or talent-pool language.
Every figure above is arithmetic over the posting itself — its salary field, its text, its age, its tags and how many sources carry it. How the grades work →
This listing does not state a salary
$112k – $155k
That is the middle half of what comparable roles paid on this board over the last 90 days — 50 listings that did publish a figure, median $136k. It is not this employer's offer, and we have no idea what they pay. It is only what the rest of the market advertised.
This is a remote position.
We are seeking anExpert-level Information Security Consultantto drive the ongoing maturity of Fraser Health's penetration testing program. In this role, you will perform end-to-end grey-box penetration tests across a large portfolio of web and API applications while utilizing a secure, browser-based management platform to schedule assessments, track vulnerabilities, and manage remediation lifecyclesRequirements
Scoping & Sizing:Conduct T-shirt sizing (Small, Medium, Large) and scoping for onboarded applications based on dynamic web pages and user roles.
Penetration Testing Execution:Execute manual and tool-assisted grey-box penetration tests across approximately 123 Web/API applications (30 Large, 51 Medium, 42 Small), completing testing within 5–10 days per application.
Engagement Lifecycles:Manage the end-to-end testing lifecycle for each application from kickoff meeting to final sign-off within 20–25 days.
In-Depth Vulnerability Assessment:Conduct expert manual assessments covering authentication, session management, MFA bypass, horizontal/vertical privilege escalation, IDOR/BOLA, API vulnerabilities, and business logic workflow abuses.
Attack-Path Validation:Chain vulnerabilities into realistic attack paths and perform controlled, non-destructive validation within live healthcare environments without disrupting operational or clinical systems.
Platform Management:Deploy and operate a browser-based, RBAC/MFA-enabled pen test platform supporting 6–12 month forward scheduling, metric dashboards, report retention, automated notifications, and GRC tool integration.
Tooling & Environment Setup:Install, configure, and maintain all necessary licensed testing tools inside the client-provided penetration testing machines accessed via the Privileged Access Management (PAM) platform.
Reporting & Debriefs:Author comprehensive reports with testing methodologies, scorecards, reproducible steps, root-cause analyses, and prioritized remediation guidance, followed by stakeholder presentations.
Remediation Tracking & Retesting:Follow up with application owners on vulnerability mitigations and perform targeted retests on resolved findings.
Required Qualifications & Experience
Certifications:Active penetration testing certification such asOSCP(Offensive Security Certified Professional),CEH(Certified Ethical Hacker), or an equivalent credential.
-
Seniority Threshold (Expert Level):
Relevant Degree + minimum 6 years of consulting experience.
Relevant Diploma + minimum 7 years of consulting experience.
Relevant Certificate + minimum 8 years of consulting experience.
Minimum 10 years of directly related consulting experience.
Healthcare & Production Experience:Demonstrated experience performing penetration testing safely in Canadian healthcare or sensitive enterprise environments with zero clinical/operational impact.
Employment Status:Must be a permanent employee of the service provider (subcontracting is prohibited).
Framework Alignment:Practical working knowledge of OWASP, NIST SP 800-53A, PCI DSS 11.3, and IDART standards
Originally posted on Himalayas
Apply for this role Opens himalayas.app — the link as listed; we have not yet verified it is the employer's own page
Quick question · anonymous · one tap
Would you apply to this job?
Answer to see what other job seekers said.
Your turn · no account needed
Help the next applicant
You may know something about this listing that we cannot see from here. One tap. No account needed. Signed-in reports earn points once the evidence agrees with you.
I know what it pays
Sign in with Google to earn points for reports — 100 confirmed points buy a week of Early Access.
Where this listing came from
- 23 Aug 2026 Himalayas first sighting
Seen on 1 board over 0 days.