Penetration Tester
Information Systems
Quality Assurance
Your Role
Position: Penetration Tester
Duration: 2 Years assignment (contract)
Client Location: Toronto (Remote: 7.25 hours/day between 8:00 AM and 5:00 PM, Monday to Friday)
Engagement Model: Professional Services Engagement – B2B (Incorporated Entities Only)
Note on Assignment Type
This position is provisionally Remote, requiring 7.25 hours per calendar day between 8:00 AM and 5:00 PM, Monday to Friday (excluding breaks). Conditions may change based on organizational requirements and at the discretion of the Hiring Manager.
About the Engagement
Akkodis is seeking experienced Penetration Tester to support a comprehensive application security testing program involving web applications, APIs, and related enterprise systems.
The successful consultant will perform grey-box penetration testing activities, validate vulnerabilities through manual testing techniques, develop risk-based remediation recommendations, and provide technical guidance to stakeholders throughout the testing lifecycle.
Scope
Perform penetration testing of web applications, APIs, and related platforms across varying application sizes and complexity levels.
Execute primarily grey-box penetration tests within defined testing windows and engagement timelines.
Conduct both automated and manual penetration testing activities.
Perform vulnerability validation, exploitation testing, and attack path analysis in accordance with approved rules of engagement.
Assignment Deliverables
Penetration Testing Plans and Testing Schedules
Rules of Engagement Documentation
Penetration Testing Reports
Executive Summaries and Security Scorecards
Vulnerability Assessment and Risk Analysis Documentation.
Expertise Required
Must Have:
Demonstrated experience conducting web application and API penetration testing in enterprise environments.
Proven experience performing manual penetration testing beyond automated vulnerability scanning.
Strong expertise in grey-box penetration testing methodologies.
Experience testing authentication mechanisms, session management controls, password recovery processes, and multi-factor authentication implementations.
Demonstrated experience evaluating authorization controls, privilege escalation vulnerabilities, IDOR/BOLA vulnerabilities, and access control weaknesses.
Experience conducting API security assessments, including authentication, authorization, token handling, parameter manipulation, and data exposure testing.
Nice to Have:
Experience supporting healthcare, public sector, or highly regulated environments.
Experience working with centralized penetration testing management platforms.
Experience integrating security findings with, Risk, and Compliance (GRC) tools.
Security Clearance
Required.
Important
This is a business-to-business engagement. Candidates must represent an incorporated entity, hold a valid business number, maintain appropriate insurance, and invoice for services rendered.
How to Apply
Submit your resume in confidence via the Akkodis Canada website.
We thank all applicants for their interest in this opportunity. Only candidates meeting the above qualifications will be contacted for further discussions.
Accessibility:
At Akkodis, part of The Adecco Group, our purpose is simple: to make the future work for everyone. We live our values, Passion, Collaboration, Inclusion, Courage, and Customers at Heart, by fostering a workplace where diversity is celebrated and every voice matter. We encourage applications from individuals of all backgrounds and identities. Together, we’re making the future work for everyone.
Ref: 1643439