Ovii Job Board

Senior Security Engineer - Pentester

Menlo Security

AMER - Canada, Canada • Remote - AMER - Canada, Canada • Full-Time

Posted 2026-08-03 CAD 158,000 - CAD 237,000 per year Tech & Engg

Apply on employer site

Job Description

Ovii's Interpretation of the Role

Menlo Security seeks a senior security engineer to lead offensive and defensive testing of multi‑cloud product features. The role blends deep penetration testing, cloud and container security, and AI‑augmented automation to deliver fast, high‑quality vulnerability reports.

Role Snapshot

  • Senior Security Engineer
  • Penetration Testing
  • Multi‑Cloud (AWS/GCP)
  • AI‑augmented security assessments
  • Container & VM security
  • Technical report writing

Must-Have Requirements

  • Penetration testing
  • Web application security (OWASP, API)
  • Cloud security (AWS, GCP)
  • Container security (Kubernetes, EKS, GKE, ECS)
  • Python / Go / Bash scripting
  • Terraform IaC auditing
  • Security automation
  • Technical report writing
  • penetration testing
  • cloud security
  • container security
  • web application security
  • security automation

Nice-to-Have Signals

  • Gatekeeper policies
  • Binary Authorization

Work Setup

  • Location: AMER - Canada, Canada
  • Work mode: REMOTE
  • Remote scope: COUNTRY_RESTRICTED
  • Remote countries: Canada
  • Employment type: Full-Time

Eligibility Gates

  • Visa sponsorship: unknown

Not Specified in JD

  • Visa sponsorship
  • Relocation
  • Travel
  • Security clearance
  • Coding test
  • Portfolio
  • GitHub
  • Writing sample
  • Cover letter

What You'll Likely Work On

  • Conduct deep‑dive penetration tests of product features across AWS and GCP environments
  • Review IAM policies, cloud configurations, and container workloads against security baselines
  • Perform dynamic testing of web interfaces and API endpoints
  • Assess hybrid infrastructure security for containers and virtual machines
  • Triage findings, build reproducible PoCs, and partner with product teams for remediation
  • Leverage AI/LLM tools to automate reconnaissance, generate attack vectors, and draft reports
  • Monitor bug bounty pipelines and validate external vulnerability submissions

Good Fit If You Have

  • Familiarity with Gatekeeper policies
  • Experience with Binary Authorization
  • Comfort with CSPM frameworks and native cloud APIs

Skills

  • Penetration testing
  • Web application security (OWASP, API)
  • Cloud security (AWS, GCP)
  • Container security (Kubernetes, EKS, GKE, ECS)
  • AI/LLM tooling (Gemini, Claude)
  • Python / Go / Bash scripting
  • Terraform IaC auditing
  • Security automation
  • Bug bounty triage
  • Technical communication

Remote Eligibility

  • Canada
  • AMER - Canada