Logo for Workiy Inc.

Pen test platform

Role overview

Qualifications

  • Active penetration testing certification such as OSCP or CEH
  • Minimum 6 years of consulting experience with a relevant degree
  • Demonstrated experience in Canadian healthcare environments
  • Practical working knowledge of OWASP and PCI DSS

Responsibilities

  • Perform end-to-end grey-box penetration tests on web and API applications
  • Manage the end-to-end testing lifecycle for each application
  • Conduct expert manual vulnerability assessments and attack-path validations
  • Author comprehensive reports and track remediation efforts

About the company

Workiy Inc. logo

Workiy Inc.

IT Services & IT Consulting

Workiy provides digital solutions and staffing services, utilizing our patented delivery model and a unique and flexible, client-centric approach to tackling technology's biggest challenges. We don’t have “clients” we have partners! Our mission is to enable your talented teams and amazing systems to assist your business in optimally achieving its goals. The Workiy team, brings to the table, more than 20+ years of experience in the technology industry across many verticals in both the private and public sector.

Company details

Company typeSME
IndustryIT Services & IT Consulting
Company size11 - 50

Your match analysis

See how your profile stacks up against this role.

We compared the job requirements to your profile to show where you're strong and where you fall short.

Job description

This is a remote position.

We are seeking an Expert-level Information Security Consultant to drive the ongoing maturity of Fraser Health's penetration testing program. In this role, you will perform end-to-end grey-box penetration tests across a large portfolio of web and API applications while utilizing a secure, browser-based management platform to schedule assessments, track vulnerabilities, and manage remediation lifecycles

Requirements

  • Scoping & Sizing: Conduct T-shirt sizing (Small, Medium, Large) and scoping for onboarded applications based on dynamic web pages and user roles.

  • Penetration Testing Execution: Execute manual and tool-assisted grey-box penetration tests across approximately 123 Web/API applications (30 Large, 51 Medium, 42 Small), completing testing within 5–10 days per application.

  • Engagement Lifecycles: Manage the end-to-end testing lifecycle for each application from kickoff meeting to final sign-off within 20–25 days.

  • In-Depth Vulnerability Assessment: Conduct expert manual assessments covering authentication, session management, MFA bypass, horizontal/vertical privilege escalation, IDOR/BOLA, API vulnerabilities, and business logic workflow abuses.

  • Attack-Path Validation: Chain vulnerabilities into realistic attack paths and perform controlled, non-destructive validation within live healthcare environments without disrupting operational or clinical systems.

  • Platform Management: Deploy and operate a browser-based, RBAC/MFA-enabled pen test platform supporting 6–12 month forward scheduling, metric dashboards, report retention, automated notifications, and GRC tool integration.

  • Tooling & Environment Setup: Install, configure, and maintain all necessary licensed testing tools inside the client-provided penetration testing machines accessed via the Privileged Access Management (PAM) platform.

  • Reporting & Debriefs: Author comprehensive reports with testing methodologies, scorecards, reproducible steps, root-cause analyses, and prioritized remediation guidance, followed by stakeholder presentations.

  • Remediation Tracking & Retesting: Follow up with application owners on vulnerability mitigations and perform targeted retests on resolved findings.

Required Qualifications & Experience

  • Certifications: Active penetration testing certification such as OSCP (Offensive Security Certified Professional), CEH (Certified Ethical Hacker), or an equivalent credential.

  • Seniority Threshold (Expert Level):

    • Relevant Degree + minimum 6 years of consulting experience.

    • Relevant Diploma + minimum 7 years of consulting experience.

    • Relevant Certificate + minimum 8 years of consulting experience.

    • Minimum 10 years of directly related consulting experience.

  • Healthcare & Production Experience: Demonstrated experience performing penetration testing safely in Canadian healthcare or sensitive enterprise environments with zero clinical/operational impact.

  • Employment Status: Must be a permanent employee of the service provider (subcontracting is prohibited).

  • Framework Alignment: Practical working knowledge of OWASP, NIST SP 800-53A, PCI DSS 11.3, and IDART standards



Apply once. Then go straight to the hiring manager.

After you apply, unlock the direct contact details of the people who actually make the call. A quick follow-up makes you 5x more likely to land an interview.

MR

Marcus Rivera

Chief Revenue Officer

m.rivera@company.com
linkedin.com/in/marcusrivera
Unlocked after you apply
·

Pentester Related jobs

Other jobs at Workiy Inc.

Premium

Reach out to the hiring manager directly.

Gain access to the contact details of the hiring managers who actually decide, and reach out to network with them directly. That, plus more when you upgrade:

  • Full match report with fit score and gaps
  • Career diagnostics on how recruiters read you
  • Curated company matches and warm intros
  • 48h early access to new roles

Cancel anytime.