
Zodiac Solutions
Actively Hiring
Finding Great Employees
Offensive Security Engineer
- Old Toronto
- |10 years of exp
- |Full Time
Posted: 5 days ago• Recruiter recently active
Job Location
Old Toronto
Remote Work Policy
In office - WFH flexibility
Visa Sponsorship
Not Available
RelocationAllowed
Skills
Python
Java
Javascript
C#
Infrastructure
Penetration Testing
Exploit Development
Go
Red Teaming
OSCP
OSCE
DAST
SAST
Container
IAST
SCA
GWAPT
OSEP
GXPN
Authentication Flaws
Memory Safety
Injection
Race Conditions
Application Security Testing Tools
Deserialization
Supply Chain Attacks
OSWE
AI Agent Skills
Authorization Flaws
AI Agent Prompts
About the job
Role: Offensive Security Engineer
Location: Toronto, ON (4 days onsite/week)
Duration: Fulltime
Responsibilities:
- Lead exploitability assessment and false positive analysis across SAST, DAST, SCA, IAST, container, and infrastructure findings — and translate that analysis into reusable AI agent prompts and skills.
- Identify exploit chains across vulnerability classes that traditional scanners miss and encode the reasoning into agent workflows so the capability scales.
- Validate that AI-generated fixes close exploitable conditions, and feed validation patterns back into agent evaluation frameworks.
- Develop offensive prompts, attack scenarios, and evaluation criteria that the agentic AI capability uses to assess findings autonomously.
- Translate offensive insights into prioritization signals and remediation guidance for VM and engineering teams, delivered through AI-driven workflows.
Requirements:
- 10+ years in offensive security with hands-on exploit development, red teaming, and penetration testing.
- At least one of the following certifications: OSCP, OSCE, OSEP, OSWE, GXPN, or GWAPT.
- Demonstrated ability to identify and validate exploit chains across vulnerability classes.
- Deep fluency in vulnerability classes including memory safety, injection, authentication and authorization flaws, deserialization, race conditions, and supply chain attacks — with real exploitation experience, not just theory.
- Strong code reading skills in at least 3 languages relevant to enterprise stacks (Java, Python, JavaScript, C#, Go), with the ability to pick up new languages quickly enough to assess findings in any production code.
- Hands-on experience with application security testing tools (SAST, DAST, SCA, IAST), specifically around false positive analysis and exploitability validation.
Preferred skills:
- Public evidence of offensive capability: published CVEs, conference talks (DEF CON, Black Hat, OffensiveCon, Recon), CTF placements, bug bounty track record, or open-source offensive tooling contributions.
- Software engineering experience and contributions to production codebases.
- Defensive engineering experience building detection and remediation capabilities.
- Working familiarity with frontier LLMs and agentic AI tools applied to security analysis.
- Modern CI/CD and container platform knowledge (Docker, Kubernetes, GitHub Actions, Jenkins).
- Financial services or regulated industry experience with exposure to SOX, SOC1, and audit.
- Hands-on experience with enterprise vulnerability tooling (Tenable, Aqua, Snyk, BrightSec).