Specialist in Offensive Security
Devolutions
Lavaltrie
Specialist in Offensive Security
Devolutions
Job Type
Full time
Experience
2 to 5 years
Category
Information Technology
Specialization
Cybersecurity and Information Security
JOB DESCRIPTION
As an Offensive Security Specialist (Level 2), you will conduct end-to-end offensive security assessments to identify, exploit, and document vulnerabilities affecting the organization's products, infrastructure, applications, and platforms. You will plan, execute, and document offensive exercises, demonstrate the real-world impact of discovered weaknesses, and participate in the automation of offensive capabilities. Working closely with the product and security teams, you will contribute to risk prioritization and the strengthening of defense mechanisms, leveraging artificial intelligence technologies to accelerate research, analysis, and certain operational activities.
JOB DESCRIPTION
Core responsibilities – for all security specialists
- Actively contribute to the protection of the company's digital assets.
- Participate in projects related to the security posture and its continuous improvement.
- Document procedures, analysis results, and lessons learned.
- Work closely with coordinators and the Tech Lead.
- Participate in internal reviews, technical audits, and simulation exercises.
- Maintain your skills in day through self-directed learning or structured training.
- Respond professionally to internal communication platforms (Teams, email, tickets, etc.).
- Welcome, direct, or refer visitors appropriately to the security area.
Specific Responsibilities for the Level 2 Offensive Security Specialist Role
Offensive Testing
- Participate in penetration tests on web applications, APIs, infrastructure, SaaS platforms, and internal environments.
- Identify, exploit, and document application, network, or system vulnerabilities in a controlled manner.
- Test the limits of security controls within an authorized framework and demonstrate the real-world impact of discovered vulnerabilities.
- Participate in advanced offensive exercises in collaboration with specialists Seniors.
- Contribute to patch validation and vulnerability lifecycle management.
Analysis, Documentation, and Automation
- Document vulnerabilities with clear technical evidence, reproduction steps, and a realistic risk assessment.
- Contribute to writing penetration test reports and technical recommendations.
- Participate in risk prioritization with relevant teams.
- Automate recurring offensive testing or security validation tasks.
- Contribute to the development or improvement of internal tools related to offensive activities.
Artificial Intelligence and Continuous Improvement
- Effectively use AI tools to accelerate research, analysis, test scenario generation, and report writing. Technical.
- Validate the results produced by artificial intelligence with professional judgment.
- Experiment with new approaches using AI to improve offensive capabilities and team productivity.
- Conduct continuous monitoring of emerging vulnerabilities, offensive techniques, and specialized tools.
Collaboration
- Work collaboratively with the Security, Product, Development, Infrastructure, and IT teams.
- Clearly communicate technical risks to different types of audiences.
- Respect established scopes, rules of engagement, and operational limits.
- Contribute positively to collaboration and knowledge sharing within the team.
QUALIFICATIONS REQUIREMENTS
- Between 3 and 5 years of relevant experience in offensive cybersecurity, penetration testing, or Red Teaming.
- Recognized offensive cybersecurity certification such as OSCP, OSCP+, or HTB CPTS.
- Strong command of Windows, Linux, Active Directory, and web application environments.
- Ability to explain risks and technical recommendations clearly to non-specialist teams.
ASSETS
- Experience with modern offensive tools (Burp Suite, Nmap, Metasploit, Bloodhound, Sliver, etc.).
- Strong interest in the use of artificial intelligence applied to offensive cybersecurity.
---
CONDITIONS WORK ENVIRONMENT
- Dynamic work environment
- Flexible 35-hour work week
- 4 weeks of vacation within the first year of employment
- Comprehensive benefits package and wellness program
- Access to Telus Health telemedicine service
- Group RRSP program accessible from day one
- Cell phone and monthly plan provided
- Skills and leadership development programs
- Breakfast, snacks, and beverages provided
- On-site gym
- Entertainment room including pinball machines, table tennis, foosball, etc.
- Golf and racing simulator
Discover our benefits at: https://devolutions.net/fr/company/benefits/
About Devolutions
Ready to Apply?
Join Devolutions and take the next step in your career.
By applying, you agree to our Terms of Service and Privacy Policy.