ABOUT STINGRAI
Stingrai is a CREST-accredited premier offensive security firm specializing in expert-led penetration testing. Headquartered in Toronto, Canada, with a European hub in London, UK, we serve a global client base across Canada, the US, and Europe, from high-growth SaaS and fintech startups to large enterprises.
We are on a mission to transform offensive security. Alongside a team of experienced penetration testers, we operate an agentic penetration testing as a service (PTaaS) platform that delivers autonomous penetration testing, powered by Snipe, our AI pentesting agent, along with expert human pentesters. The result is world-class, real-world security validation that keeps pace with how fast modern environments change.
We are a team of security researchers, exploit developers and penetration testers. Our team holds the industry's most rigorous certifications, including OSCE³, OSCP, OSWE, and OSEP, has published dozens of CVEs, and presents research at conferences including DEF CON, BSides, and NATO Locked Shields.
THE ROLE
We are hiring a Penetration Tester on a 6 month contract, with potential to convert to a permanent full-time position within 3 to 6 months. This is a hands-on role for someone who already have experience in web application, API, and network penetration testing.
The role is hybrid and based in Toronto, with 2 to 3 days per week in our office. Roughly 10 to 20 percent of engagements also require onsite presence at client sites in the Greater Toronto Area.
WHAT YOU'LL DO
- Plan and execute penetration tests across web applications, APIs, and internal and external networks
- Dig into every finding until you have proven real, exploitable impact, then document it with clear, prioritized remediation guidance
- Validate and triage findings from Snipe, our AI pentesting agent, applying human judgment to separate real risk from noise
- Where it matters, chain application flaws into adjacent areas such as cloud or Active Directory to demonstrate full impact
- Write professional reports and debrief findings to both technical teams and executives
- Work directly with clients through our PTaaS platform, including live support during active engagements
- Keep current with new attack techniques, tooling, and disclosed vulnerabilities, and bring what you learn back to the team
- Participate in our research and development (R&D) initiatives to further enhance our offensive security solutions, publish security blogs, and contribute back to the community
WHO YOU ARE
- You think like an attacker. You are not satisfied flagging a vulnerability. You prove its impact.
- You communicate clearly and on time, with clients, project leads, and teammates alike.
- You take ownership of your work. Your name is on every report you deliver, and it shows.
- You go toward hard problems, not around them, and you adapt fast in client environments.
- You keep learning, because offensive security changes constantly.
- You leave the ego at the door. The strongest finding wins, whoever surfaces it.
MINIMUM REQUIREMENTS
- OSCP certification
- 2 to 3 years of hands-on experience in web application, API, and network penetration testing
- Strong grasp of OWASP Top 10 and common attack techniques across web, API, and network
- Based in Toronto, Canada, and available for onsite presence at client sites for certain engagements
- Legally authorized to work in Canada without restrictions
We do not offer sponsorship for this role.
PREFERRED QUALIFICATIONS
These are not required, but will strengthen your application:
- Experience in a consulting or client-facing role
- Red teaming and adversary simulation
- Physical perimeter security
- Wi-Fi security testing
- Social engineering and phishing
- Cloud security across AWS, Azure, or GCP
- Secret clearance, or eligibility to obtain one
- A bug bounty track record
- Published security research, such as CVEs or conference talks
WHY STINGRAI
- A clear path from contract to permanent, with real room to grow your craft
- Work alongside an elite team of top bug bounty hunters, OSCE³ certified senior penetration testers, dozens of published CVEs, and talks at DEF CON, BSides, and NATO Locked Shields
- Test real targets for a global client base across Canada, the US, and Europe, from high-growth startups to large enterprises
- Use and help shape our agentic PTaaS platform and Snipe, our AI pentesting agent, instead of grinding through checklists
- A clear path from contract to permanent for the right person
- Competitive compensation and real room to grow your craft
COMPENSATION
- Conversion to a permanent full-time position with salary and benefits within 3 to 6 months, based on performance during the contract term
HOW TO APPLY
Apply through LinkedIn with your resume. A cover letter is optional. Applications sent by email will not be reviewed.
We use AI-assisted tools, including LinkedIn's AI interview, to help screen and assess applications. A human reviews every shortlisted candidate.