Remote opportunity•Posted 9/23/2026, 5:48:35 AM
S
Software Secured
Penetration Tester
Remote•Remote
Full-timeRemoteremotejobsorg
Cyber Securityremotejobs.orgbenefits
About this role
Software Secured is a leading Penetration Testing as a Service company, with a head office in beautiful Ottawa, Canada. We help software development teams get ahead of hackers using a suite of services and products. Our team of pentesters is seeking a pentester to join us and help secure a few hundred additional applications. As a Pentester at Software Secured, you will have the opportunity to help our clients secure their mission-critical applications. This includes performing security code review, web, mobile, and network security tests. Help clients with security design reviews, threat modelling, and remediation strategies.
What You'll Do
- Run manual penetration tests across web applications, APIs, mobile apps, and network infrastructure — from scoping through testing, reporting, client readout, and retest
- Produce findings that are manually confirmed and exploitable, with remediation guidance a developer can act on without a follow-up call
- Handle nuanced test cases beyond the standard checklist: business logic flaws, authorization edge cases, vulnerability chaining, and environment-specific attack paths
- Present findings directly to client engineering teams and security leads — explaining what was found, why it matters, and how to fix it
- Contribute to security design reviews and threat modelling engagements earlier in the SDLC
- Mentor junior testers on test execution and report quality; contribute to methodology improvements, tooling, and internal playbooks
- Develop domain depth in one or more service areas (web, network, mobile, code review) through our Domain Expertise Program — with formal recognition and stipend for engineers who build expertise that makes the whole team stronger What We're Looking For
- 2+ years of hands-on manual penetration testing — not scanner-assisted, manual
- Demonstrated ability to run standard engagements end-to-end with minimal oversight: scope, test, report, readout, retest
- Finds that go beyond OWASP Top 10 basics — business logic issues, complex auth flaws, chained vulnerabilities
Posting details
Remote
Yes
Employment type
Full-time
Workplace type
Remote
Source
remotejobsorg
First seen
9/23/2026, 8:10:28 AM
Last seen
9/23/2026, 8:10:28 AM