Web Application Pentester

At Suncor, we produce and provide energy.

When you join Suncor, you become part of a company that has built a solid foundation for both business and employee success. We are a place where talented people thrive. As part of our team, you play a vital role in delivering energy we all rely on, and you'll make a meaningful impact in the communities where we live and work.

We are seeking a hands-on Web Application Pentester who is passionate about working directly with developers to eliminate vulnerabilities at the source. Sitting within our Cyber Defense organization, you will find, explain, and help fix security weaknesses in the applications and APIs that run our business, with periodic opportunities to join red and purple team engagements.

What we offer:

We recognize your contribution and offer a range of rewards and development opportunities designed to support your success. Benefits/perks listed below may vary depending on the nature of your employment with Suncor and the region where you work.

  • Strong compensation: we offer competitive compensation, regional-based uplifts, annual bonuses, and long-term financial rewards. We also help you save for your future by offering pension programs, and savings plans with company matching

  • Benefits: utilize an employee assistance program and comprehensive company-paid health, dental, and vision benefits for you and your family to support your mental, physical, and financial well-being

  • Generous time-off: enjoy generous paid vacation time and personal time-off to recharge and maintain a healthy work-life balance

  • Talent development programs: Internal mobility, succession planning, and employee training and development programs are just a few ways we’re dedicated to your development

Minimum Requirements:

  • 7+ years in cybersecurity, including 5+ years of hands-on manual testing of modern web applications and APIs

  • Bachelor's degree in cyber security, information technology, computer science, or a related field

  • Demonstrated experience working directly with development teams to drive remediation and secure design decisions

  • Hands-on skill with Burp Suite or equivalent, REST and microservice API testing, threat modelling, and secure code review in Java, .NET, or JavaScript/TypeScript

  • Strong grounding in OWASP Top 10, ASVS, and the Cheat Sheet Series; SDLC and DevSecOps practices; server-side authorization and IAM; and modern authentication protocols (OAuth 2.0, OIDC, SAML)

  • Excellent written and verbal communication, with the ability to explain risk to both engineers and executives

  • Experience supporting red or purple team engagements, securing OT/ICS environments, or leveraging AI to enhance secure code review, threat modelling, and vulnerability discovery is considered a strong asset

Don’t have all the qualifications listed? That’s ok! Apply anyway. We acknowledge the value of transferable skills.

Responsibilities:

  • Plan and execute manual penetration tests against web applications and APIs, surfacing business logic flaws, broken access control, injection, and authentication and session weaknesses aligned to OWASP Top 10 and ASVS

  • Build safe proof-of-concept exploits that demonstrate real impact without disrupting operations, and retest fixes to confirm they hold

  • Test authentication and authorization implementations, including OAuth 2.0, OIDC, SAML, and token-based API access

  • Lead secure design reviews, threat modelling sessions, and source code reviews, recommending secure patterns and reusable controls

  • Partner with development teams to triage findings, agree on practical fixes, and coach secure development practices across the SDLC

  • Support pipeline security tooling (SAST, DAST, SCA, and Infrastructure-as-Code scanning) and help teams tune out noise

  • Contribute application-layer attack paths to red team campaigns and purple team exercises with SOC and detection engineering

  • Produce reports that pair developer-ready detail with concise executive impact summaries, and translate findings into actionable backlog items with reproduction steps, severity, and acceptance criteria

Location and other Key Details:

  • This is an office-based role. You will work out of our Calgary head office, located in the Suncor Energy Centre at 150 – 6th Ave S.W

  • Hours of work are a regular 40-hour work week, Monday to Friday with occasional site visits

  • Our business professional roles follow internal compensation guidelines, and the pay band will generally be based on years of experience and scope of work

Think we are a fit? Apply now!

Suncor is committed to providing equal opportunities for employment and building an inclusive, results-oriented and high-performance culture where all members of our team feel safe, valued and respected.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available