Senior Security Engineer - Pentester

Menlo Security
Canada
Workplace: RemoteFull timeCAD 158,000 - 237,000 annuallyFunction: CybersecuritySkills: ["Communication"]

Join the security team to run offensive and defensive testing across a multi-cloud AWS/GCP environment. Conduct deep-dive penetration tests on product features and hybrid infrastructure, review IAM and Control Plane configurations, and triage bug bounty and external vulnerability reports. Use AI/LLMs to accelerate reconnaissance, generate attack vectors, analyze configurations, and produce actionable, high-quality vulnerability reports aligned to release cadence and remediation needs.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Menlo Security
Menlo Security
4 days ago

Senior Security Engineer - Pentester

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 6 hours agoStatus: Live

Job Summary

Join the security team to run offensive and defensive testing across a multi-cloud AWS/GCP environment. Conduct deep-dive penetration tests on product features and hybrid infrastructure, review IAM and Control Plane configurations, and triage bug bounty and external vulnerability reports. Use AI/LLMs to accelerate reconnaissance, generate attack vectors, analyze configurations, and produce actionable, high-quality vulnerability reports aligned to release cadence and remediation needs.
Location: Canada
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Conduct deep-dive penetration tests across AWS/GCP, partnering with a peer pentester.
  • •Review IAM policies, service configurations, and Control Plane permission structures against security baselines.
  • •Execute dynamic testing against web interfaces and API endpoints (Data Plane & Web UI).
  • •Assess security posture across hybrid infrastructure spanning containers and virtual machines.
  • •Triage vulnerability findings (including bug bounty/external reports), build proofs-of-concept, and partner with product teams to explain risk and drive remediation.

Pay and Benefits

Salary: CAD 158,000 - 237,000 annually
Equity and Bonus:Equity

Key Requirements

  • •Deep architectural fluency in AWS and GCP, including manual IAM/resource hierarchy reviews and validating controls with native APIs or CSPM frameworks.
  • •Experience auditing and hardening container and hybrid workloads (GKE Autopilot/Standard, EKS, ECS, K8s/k3s, OCI-runc).
  • •Ability to integrate AI/LLM tools (e.g., Gemini, Claude) into the pentesting workflow for speed and coverage.
  • •Expert web application security knowledge including OWASP Top 10, API security (REST, WebSockets), browser security mechanisms (CSP, CORS, SameSite, SRI), and auth patterns (OAuth 2.0, OIDC, JWT).
  • •Strong security automation and infrastructure skills using Python/Go/Bash and Terraform/HCL to eliminate toil and audit misconfigurations.
Skills:Communication
Tech Stack:AWSGCPVMsGKE AutopilotGKE StandardEKSECSKubernetesK3sOCI-runcGeminiClaudeOWASP Top 10Burp Suite ProfessionalOWASP ZAPCSPCORSSameSite cookiesSubresource IntegrityOAuth 2.0

Company Brief

Menlo Security
Provides a cloud-based isolation platform and secure enterprise browser to protect organizations from web, email, and document-based cyberattacks by executing risky content remotely and preventing malware and data exfiltration.
Industry: Cybersecurity
Company Size: Large (251 to 1,000 employees)
Revenue: USD 100M to 250M
Growth: Scaleup
Valuation: USD 500M to 1B
Funding: Series E+
Headquarters: Mountain View, United States
Founded: 2012
Glassdoor
Glassdoor: 4.0
WebsiteLinkedInGlassdoor