Penetration Testing Specialist
Job Summary
- Conduct penetration testing of the IRMA web application using the required testing methodologies.
- Perform Grey Box and Black Box penetration testing based on the approved scope and testing plan.
- Assess the security of the web application and applicable APIs within the defined scope.
- Identify analyze evaluate and document security vulnerabilities using industry best practices.
- Review and analyze relevant penetration testing results and security scan results from the IRMA application and related systems.
- Assess vulnerabilities severity affected systems potential business/technical impacts and recommended remediation actions.
- Immediately report Critical vulnerabilities as identified using the Common Vulnerability Scoring System (CVSS) to the Cyber and Risk team and Service Nova Scotia (GeoNOVA).
- Participate in project kickoff progress/status meetings and security risk assessment activities as required.
- Work collaboratively with IT cybersecurity application owners and business stakeholders.
- Identify appropriate business owners and risk treatment owners for penetration testing recommendations.
- Provide weekly status updates throughout the engagement.
- Prepare a comprehensive Final Penetration Testing Report.
- Prepare and deliver an Executive Presentation summarizing key findings vulnerabilities impacts and recommended mitigations.
- Re-test and verify remediation of findings identified during the penetration testing engagement.
- Ensure all testing tools and toolkits are used in accordance with Government of Nova Scotia requirements.
- Obtain prior written approval before installing any testing toolkit on the Government of Nova Scotia network.
- Thoroughly remove all testing-related files binaries scripts backdoors malware and other related items following testing.
- Minimum 3 years of professional experience in penetration testing.
- Demonstrated experience conducting penetration testing on digital systems.
- Experience with application security testing and vulnerability identification.
- Offensive Security Certified Penetration Tester (OSCP) OR
- CREST Registered Penetration Tester (CRT).
- Certified Ethical Hacker Master (CEH-Master) OR
- GIAC Penetration Tester (GPEN) OR
- CompTIA PenTest.
- Proven experience conducting penetration testing for the Canadian public sector including federal provincial territorial and/or municipal government organizations.
- Experience conducting penetration testing for the Government of Nova Scotia is required as part of the stated experience requirements.
- At least one proposed resource must have conducted two (2) or more penetration tests within the last 12 months.
- Demonstrated ability to work effectively with IT cybersecurity application teams and business stakeholders.
- A clear criminal record check processed within the last six (6) months must be provided for each proposed resource.
- Web Application Penetration Testing
- API Security / API Penetration Testing
- Grey Box Testing
- Black Box Testing
- Vulnerability identification and analysis
- Security assessment and risk analysis
- CVSS-based vulnerability severity assessment
- Penetration testing reporting
- Remediation validation and re-testing
- Final Penetration Testing Report
- Scope and objectives
- Testing methodologies and tools
- Detailed vulnerabilities and findings
- Severity ratings
- Affected systems
- Potential impacts
- Recommended treatment/remediation plans
- Remediation timelines
- Major findings
- Vulnerabilities
- Potential impacts
- Recommended mitigations
- Business-level summary for non-technical stakeholders
- Re-test identified vulnerabilities
- Verify remediation effectiveness
- Document validation results
- Resume/CV
- Years and types of penetration testing experience
- Relevant penetration testing project examples from the past five years
- Tier 1 certification details where applicable
- Tier 2 certification details where applicable
- Public-sector penetration testing experience in Canada
- Government of Nova Scotia experience
- Evidence of at least two penetration tests completed within the past 12 months for at least one proposed resource
- Clear criminal record check completed within the last six months
Required Skills:
Mandatory Qualifications & Experience Candidates must meet the following requirements: 1. Penetration Testing Experience Minimum 3 years of professional experience in penetration testing. Demonstrated experience conducting penetration testing on digital systems. Experience with application security testing and vulnerability identification. 2. Tier 1 Certification Mandatory at Team Level At least one proposed resource must hold a recognized Tier 1 certification: Offensive Security Certified Penetration Tester (OSCP) OR CREST Registered Penetration Tester (CRT). 3. Tier 2 Certification Mandatory at Team Level At least one proposed resource must hold a recognized Tier 2 certification: Certified Ethical Hacker Master (CEH-Master) OR GIAC Penetration Tester (GPEN) OR CompTIA PenTest. 4. Public Sector Penetration Testing Experience Proven experience conducting penetration testing for the Canadian public sector including federal provincial territorial and/or municipal government organizations. 5. Government of Nova Scotia Experience Experience conducting penetration testing for the Government of Nova Scotia is required as part of the stated experience requirements. 6. Recent Penetration Testing Experience At least one proposed resource must have conducted two (2) or more penetration tests within the last 12 months. 7. Cross-Functional Collaboration Demonstrated ability to work effectively with IT cybersecurity application teams and business stakeholders. 8. Criminal Record Check A clear criminal record check processed within the last six (6) months must be provided for each proposed resource. Required Technical Testing Scope Experience should align with the SOWs defined penetration-testing scope including: Web Application Penetration Testing API Security / API Penetration Testing Grey Box Testing Black Box Testing Vulnerability identification and analysis Security assessment and risk analysis CVSS-based vulnerability severity assessment Penetration testing reporting Remediation validation and re-testing Testing Methodologies Grey Box Testing Testing with partial knowledge of the target environment such as credentials or system documentation simulating an attacker with some level of access. Black Box Testing Testing with no prior knowledge of the target environment simulating an external attacker using reconnaissance and trial-and-error techniques. Key Deliverables The successful resource will contribute to: Final Penetration Testing Report Scope and objectives Testing methodologies and tools Detailed vulnerabilities and findings Severity ratings Affected systems Potential impacts Recommended treatment/remediation plans Remediation timelines Executive Presentation Major findings Vulnerabilities Potential impacts Recommended mitigations Business-level summary for non-technical stakeholders Remediation Validation Re-test identified vulnerabilities Verify remediation effectiveness Document validation results Proposal / Submission Requirements For each proposed resource suppliers should be prepared to provide: Resume/CV Years and types of penetration testing experience Relevant penetration testing project examples from the past five years Tier 1 certification details where applicable Tier 2 certification details where applicable Public-sector penetration testing experience in Canada Government of Nova Scotia experience Evidence of at least two penetration tests completed within the past 12 months for at least one proposed resource Clear criminal record check completed within the last six months
Required Education:
Bachelors Degree in Computer Science Information Technology Cybersecurity or a related cybersecurity / penetration testing training and certifications CREST CRT CEH-Master GPEN or CompTIA PenTest certifications are highly relevant.