Web Application Pentester
At Suncor, we produce and provide energy.
When you join Suncor, you become part of a company that has built a solid foundation for both business and employee success. We are a place where talented people thrive. As part of our team, you play a vital role in delivering energy we all rely on, and you'll make a meaningful impact in the communities where we live and work.
We are seeking a hands-on Web Application Pentester who is passionate about working directly with developers to eliminate vulnerabilities at the source. Sitting within our Cyber Defense organization, you will find, explain, and help fix security weaknesses in the applications and APIs that run our business, with periodic opportunities to join red and purple team engagements.
What we offer:
We recognize your contribution and offer a range of rewards and development opportunities designed to support your success. Benefits/perks listed below may vary depending on the nature of your employment with Suncor and the region where you work.
Strong compensation: we offer competitive compensation, regional-based uplifts, annual bonuses, and long-term financial rewards. We also help you save for your future by offering pension programs, and savings plans with company matching
Benefits: utilize an employee assistance program and comprehensive company-paid health, dental, and vision benefits for you and your family to support your mental, physical, and financial well-being
Generous time-off: enjoy generous paid vacation time and personal time-off to recharge and maintain a healthy work-life balance
Talent development programs: Internal mobility, succession planning, and employee training and development programs are just a few ways we’re dedicated to your development
Minimum Requirements:
7+ years in cybersecurity, including 5+ years of hands-on manual testing of modern web applications and APIs
Bachelor's degree in cyber security, information technology, computer science, or a related field
Demonstrated experience working directly with development teams to drive remediation and secure design decisions
Hands-on skill with Burp Suite or equivalent, REST and microservice API testing, threat modelling, and secure code review in Java, .NET, or JavaScript/TypeScript
Strong grounding in OWASP Top 10, ASVS, and the Cheat Sheet Series; SDLC and DevSecOps practices; server-side authorization and IAM; and modern authentication protocols (OAuth 2.0, OIDC, SAML)
Excellent written and verbal communication, with the ability to explain risk to both engineers and executives
Experience supporting red or purple team engagements, securing OT/ICS environments, or leveraging AI to enhance secure code review, threat modelling, and vulnerability discovery is considered a strong asset
Don’t have all the qualifications listed? That’s ok! Apply anyway. We acknowledge the value of transferable skills.
Responsibilities:
Plan and execute manual penetration tests against web applications and APIs, surfacing business logic flaws, broken access control, injection, and authentication and session weaknesses aligned to OWASP Top 10 and ASVS
Build safe proof-of-concept exploits that demonstrate real impact without disrupting operations, and retest fixes to confirm they hold
Test authentication and authorization implementations, including OAuth 2.0, OIDC, SAML, and token-based API access
Lead secure design reviews, threat modelling sessions, and source code reviews, recommending secure patterns and reusable controls
Partner with development teams to triage findings, agree on practical fixes, and coach secure development practices across the SDLC
Support pipeline security tooling (SAST, DAST, SCA, and Infrastructure-as-Code scanning) and help teams tune out noise
Contribute application-layer attack paths to red team campaigns and purple team exercises with SOC and detection engineering
Produce reports that pair developer-ready detail with concise executive impact summaries, and translate findings into actionable backlog items with reproduction steps, severity, and acceptance criteria
Location and other Key Details:
This is an office-based role. You will work out of our Calgary head office, located in the Suncor Energy Centre at 150 – 6th Ave S.W
Hours of work are a regular 40-hour work week, Monday to Friday with occasional site visits
Our business professional roles follow internal compensation guidelines, and the pay band will generally be based on years of experience and scope of work
Think we are a fit? Apply now!
Suncor is committed to providing equal opportunities for employment and building an inclusive, results-oriented and high-performance culture where all members of our team feel safe, valued and respected.