- Location
- Complexe Desjardins Montréal, Canada
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Security
- Seniority
- Senior
- Closing date
- Today
- Source
- Workday
Description
The Attack Simulation Offensive Security Department is looking for a senior advisor to join the full-scope Cross-Sector Intrusion Testing Team. This team simulates high-impact attack scenarios for the organization. The team works without a fixed scope so it can better identify the most efficient ways to run through defined scenarios, with mandates running from one to three months. In this role, you will collaborate closely with teams focused on cyber defence, internal threats, development, architecture and continuous delivery. You’ll assess cybersecurity risks from different angles and help to build the organization’s defensive capacity. As a Senior Offensive Security Advisor, you help identify, analyze and mitigate threats to Desjardins Group’s external systems, networks and apps. You plan for new threats based on the continuous development of offensive techniques and threat actors. You will serve as an expert leader in carrying out high-impact strategic offensive mandates and will play an influential role with everyone involved to help implement the proposed recommendations. You make recommendations on the development and execution of projects and initiatives with a high degree of operational and conceptual complexity. There will be a number of initiatives to align and coordinate, and interpersonal savvy is therefore essential. More specifically, you will be required to:
- Leverage advanced penetration techniques, expert knowledge in network security, web applications, source code analysis, corporate controls and identity management.
- Identify and exploit system vulnerabilities or weaknesses in a rigorous and ethical manner, demonstrating creativity and innovation.
- Act as an offensive security expert to support, advise and catalyze change to strengthen Desjardins Group’s protection against cyberattacks.
- Design, develop, implement and document effective, adapted and precise methodologies and tools, while mitigating the risks associated with their execution.
- Demonstrate autonomy and initiative in updating the technical skills and knowledge related to offensive security expertise, in line with emerging needs, to actively guide and influence change.
- Strategically monitor threats in your area of expertise to help proactively identify emerging security issues.
- Communicate offensive security activity results clearly and accurately, explaining the information in plain language so that all key players understand the risks and take the necessary actions.
- Contribute to the support, development and mentorship of colleagues and key players, both technically and in raising awareness and understanding of threats that the organization seeks to prevent
What we offer*
- Competitive salary and annual bonus
- 4 weeks of flexible vacation starting in the first year
- Defined benefit pension plan that provides predictable, stable income throughout retirement
- Group insurance including telemedicine
- Reimbursement of health and wellness expenses and telework equipment
* Benefits apply based on eligibility criteria.
#LI-Hybrid
What you bring to the table
- Bachelor’s degree in IT
- A minimum of eight years of relevant pentest experience with variety of systems
- Please note that other combinations of qualifications and relevant experience may be considered
- Recognized offensive security certification, such as OSEP, CRTO etc.
- Experience in software development
- Experience analyzing source code and configuration within a security context
- Knowledge of French is required
- Intermediate advanced proficiency of English due to the nature of the duties or work tools or because the position involves interactions with English-speaking partners, members and/or clients
- Expertise in communication and plain explanations for both technical and non-technical audiences
- Advanced proficiency in infrastructure, network, and Cloud (Azure) operations
- Minimum proficiency in the use of artificial intelligence technologies
- Advanced proficiency in the analysis, synthesis and resolution of complex problems
- Offensive knowledge related to CI/CD environments and web or mobile applications
- Knowledge of Windows and Linux operating system security (hardening and attacks)
- In-depth knowledge of attack chains and the interaction between offensive, preventive, and detection mechanisms
Action oriented, Collaborates, Customer Focus, Innovation, Interpersonal Savvy, Strategic mindset
Equity, Diversity, Inclusion and Accessibility
At Desjardins, we believe in equity, diversity and inclusion. We're committed to welcoming, respecting and valuing people for who they are as individuals, learning from their differences, embracing their uniqueness, and providing a positive workplace for all. At Desjardins, we have zero tolerance for discrimination of any kind. We believe our teams should reflect the diversity of the members, clients and communities we serve.
If there's something we can do to help make the recruitment process or the job you're applying for more accessible, let us know. We can provide accommodations at any stage in the recruitment process. Just ask!
Trade Union (If applicable)
Job Family
Security (FG)Unposting Date
2026-08-17