Senior Security Consultant - Offensive Security

Location: 

Calgary, AB, CA Burnaby, BC, CA Edmonton, AB, CA Montréal, QC, CA Ottawa, ON, CA Toronto, ON, CA Vancouver, BC, CA

Req ID:  48736
Jobs by Category:  Technology Solutions
Job Function:  Cybersecurity
Status:  Full Time
Schedule:  Regular

 

Join our team and what we’ll accomplish together

 

We live in and work in a rapidly evolving digital world where cyber security is critical. Protecting information and ensuring the reliability of network and services is paramount. The TELUS Health CSO team strives to always be steps ahead, tackling the toughest cyber security challenges head-on with top talent and cutting-edge technology. 

 

Reporting to the Manager of the Offensive Security team, we are seeking an experienced Senior Security Consultant to join the team, mentor other consultants, and support our Vulnerability Management Program. This work will combine aspects of 3rd party consulting with in-house security advisory, penetration testing, application security, and vulnerability management. You’ll get the opportunity to leverage enterprise grade tools and also develop in house security tooling and integrations. As TELUS Health is comprised of many mergers and acquisitions the goal is thorough security validation at scale across many disparate systems, networks and technology stacks. Not only will you assist in identifying gaps, you’ll also be a key contributor to our remediation efforts. When applicable, you’ll help automate and create new processes to avoid the same issues in the future. 

 

The TELUS Health CSO team is committed to providing excellence in securing our internal and customers’ data and systems, ensuring world-class reliability of security networks and systems, and improving our overall cyber security posture. We manage our cyber risks and provide industry leading cyber governance, assurance and oversight to secure our data. 

 

You’ll partner with industry leaders to meet the cyber security needs of both TELUS Health and our customers to meet the demands of an increasingly complex and ever-changing cyber security landscape. We are passionate about learning and growing as individuals and as a team, all of which enables us to thrive in a dynamic environment.

What you’ll do

 

Please note, we understand that this role does span/merge across many traditional security testing specializations. We welcome security testing specialists and generalists alike for this role, we simply require the willingness to grow and learn. 

 

  • Reinforce TELUS Health's Customers First values in ensuring positive security outcomes for external customers and internal stakeholders 
  • Provide deep cyber security technical knowledge and support to business and development operations teams
  • Lead projects and client engagements and write reports and prepare presentations, making use of your communication skills to explain technical findings to non-technical crowds 
  • Help build the core Vulnerability Management Program working with various data sources and stakeholders from different lines of business. 
  • You’ll get the opportunity to design and implement a wide range of testing scenarios that emulate different threat actor sophistications across different assets. A few examples below that will fall within the team: 
    • Conduct penetration tests using OSINT, PTES, OSSTMM methodologies
    • Enhance the security data pipeline to streamline vulnerability remediation workflows, including automated vulnerability scanning, risk prioritization, remediation tracking, and metrics reporting to ensure timely resolution of security findings
    • An assumed breach scenario and applying the MITRE ATT&CK framework to assess our ability to detect and respond to a wide range of adversarial TTPs 
    • Application security assessments using OWASP Web/Mobile application Security Testing Guide to verify an application’s security posture related to the associated OWASP (M)ASVS Level 
    • Review 3rd party penetration tests to validate the findings and ensure that the mitigations are properly implemented
    • Set up attacker infrastructure for C2 communications 
    • Contribute to Offensive Security Tactics, Techniques and Procedures and aid the SecOps team with the Incident Response playbook definition 
    • Contribute to our “shift left” application security strategy by automating testing and reporting into the SDLC pipeline 
    • Write clear reports that summarize findings, detail and prioritize remediation strategies 
  • Guide and mentor others in offensive security practices

 

What you bring 

 

  • 5+ years in a combination of vulnerability scanning, penetration testing, red teaming, application (web, mobile) security testing 
  • 7 + years of demonstrable technical security and privacy experience in IT and networks, ideally in a professional role or consultative capacity 
  • Demonstrate aptitude to automate aspects of our testing process (Python, Powershell, Javascript, Perl, Bash, Ruby, etc.) 
  • Flexibility and comfortable with ambiguity, you enjoy working with others to “figure it out” when needed strong interpersonal and influencing skills to build relationships with key stakeholders 
  • You’ll have experience working at least a few combinations of the following: 
    • MITRE ATT&CK 
    • OWASP ASVS and WSTG 
    • MASVS, MASTG 
    • PTES, OSSTMM 
  • Ideally you will possess two or more of the following certifications (or any credible security testing certifications): 
    • Penetration Testing 
      • CREST CRT, OSCP, OSCE, OSEP, GPEN, eCPT, eCPTX, HTB CPTS, OSWP, PNPT 
    • Red Teaming 
      • CRTP, CRTO (1 and/or 2), CRTE 
    • Application Security 
      • BurpSuite Certified Practitioner, OSWE, GWAPT, eWPT 
    • Mobile Application Security 
      • GMOB, EMAPT 
    • Cloud Security
    • CCSP, CARTP, CAWASP, PACSP 
  • Must possess or be able to obtain at least Government of Canada Reliability Status clearance

 

Great-to-haves

 

  • Previous experience in IT administration or software development 
  • Background in exploit development and research 
  • Contributions to open-source projects or the security community

 

Advanced knowledge of English is required because you will most of the time interact in English with external parties (clients, suppliers, candidates, external partners, etc.); interact in English with internal parties (colleagues, internal partners, stakeholders, etc.); and work with IT tools whose interface is only accessible in English as part of this position's main responsibilities given its national scope.

 

 

Salary Range:  $101,000-$151,000
Performance Bonus or Sales Incentive Plan:  15%

Actual total compensation will be determined based on factors such as knowledge, skills, performance and experience. In addition, TELUS offers rewarding benefits such as:

  • Comprehensive total rewards package highlighting competitive salary and bonus structures, minimum 3 weeks of vacation, and flexible benefits plan to meet the needs of you and your family
  • Flexibility to work in-office, virtually or a combination of both, based on the role's requirements
  • Generous company matched pension and share purchase programs
  • Opportunity to give back to communities in which we work, live and serve
  • Career growth and learning & development opportunities to develop your skills
  • And much more …

A bit about us

We’re a people-focused, customer-first, purpose-driven team who works together every day to innovate and do good. We improve lives through our technology solutions and foster a culture of innovation that empowers team members to solve complex problems and create remarkable human outcomes in a digital world. 

You’ll find our engaging, high-performance culture personally fulfilling, professionally challenging, and financially rewarding. We’re committed to diversity and equitable access to employment opportunities based on ability. Your unique contributions and talents will be valued and respected here. When you join our team, you’re helping us make the future friendly.

Note for Quebec candidates: if knowledge of English is required for this position, it is because the team member will be asked, on a regular basis, to interact in English with external or internal parties or to use English applications or software as part of their tasks.

 

 

 

 

Technology Solutions

We’re into seeing where technology can take us, so if you have ever imagined what the future of supply chain management, cybersecurity, the cloud and Internet of Things will look like, we want you to be part of the team that makes it happen.

We are honoured to be recognized

5G
TELUS’s fastest network. 5G enables a superior experience with fast downloads and richer multimedia applications

6
Innovation centres across Canada that bring our team members together with customers, partners, start ups, universities, hospitals and fellow colleagues to tackle some of the biggest technological hurdles Canada will face in the near future.

1
Million active users logging into My TELUS per month (consumer mobility).

Accessibility

TELUS is proud to foster an inclusive culture that embraces diversity. We are committed to fair employment practices and all qualified applicants will receive consideration for employment.

We offer accommodation for applicants with disabilities, as required, during the recruitment process.