Stantec

Stantec

London

Senior Ethical Hacker

Full-Time£63,000 - 103,000 per yearayerUnited Kingdom
IT

Job Description

Salary: £63,000 - 103,000 per year

Requirements:
  • We require a minimum of 5–7+ years of cybersecurity experience; offensive security or Red Team experience is preferred.
  • We require at least 5 years of relevant experience and a related degree or certificate, preferably in Offensive Security, AI Red Teaming, or Application Security.
  • We require proficiency in manual web and cloud penetration testing, including testing without tools.
  • We require proficiency writing custom attack tools using Python, PHP, Golang, and Bash.
  • We require proficiency with interception proxies and manual testing using Burp Suite Enterprise.
  • We require experience building or maintaining attack automation systems, containers, and automation pipelines for attack purposes.
  • We require the ability to combine multiple low- or medium-severity findings to achieve a higher level of impact.
  • We require comfort working from the Windows or Linux command line and using VIM/VI, Bash/SH, Perl, VBScript, WMI, or PowerShell for post-exploitation and lateral movement.
  • We require experience with XSS attacks, system or SQL injection payloads, or binary weaponization.
  • We require experience attacking public cloud services such as Azure, AWS, GCP, or Oracle.
  • We require the ability to present audit findings to small groups or C-suite audiences, take ownership of testing activities, and conduct blameless post-mortems.
  • Preferred additional skills or credentials include OSWE, OSAI, GWAPT, BSCP, PACSP, CKS, Terraform Associate (003), DevSecOps experience, AI/LLM penetration-testing experience, and responsible-disclosure or bug-bounty findings.
Responsibilities:
  • We conduct security assessments and penetration tests on web applications, cloud services, systems, and APIs, emulating real-world attacks using the MITRE ATT&CK Framework.
  • We identify and validate vulnerabilities, misconfigurations, access-control and encryption weaknesses, and other security risks across applications and cloud environments.
  • We assess application services, databases, Kubernetes, serverless functions, container instances and images, and cloud storage.
  • We collaborate with security, engineering, cloud, and network operations teams.
  • We prepare reports, communicate findings to technical teams, architects, and engineers, and present test results in debrief meetings with executives or sponsors.
  • We develop and communicate processes that help engineering teams meet remediation goals.
  • We assist with or create rules of engagement for penetration-testing projects.
  • We design automated workflows for independent security evaluation and assurance, establish security baseline controls through Policy-as-Code, and build custom Python, Terraform, and Ansible extensions for specialized security and infrastructure use cases.
  • We create or maintain internal training-lab content and, as time permits, provide practical CTF activities and live hacking webinars for developers and security champions.
  • We conduct internal Red Team engagements and participate in purple-team engagements.
Technologies:
  • AI
  • AWS
  • Ansible
  • Azure
  • Bash
  • Cloud
  • DevSecOps
  • GCP
  • Golang
  • Kubernetes
  • LLM
  • Linux
  • Marketing
  • Network
  • Oracle
  • PHP
  • Perl
  • PowerShell
  • Python
  • SQL
  • Security
  • Serverless
  • Terraform
  • Web
  • Windows
  • Architect
  • DevOps

More:

We are Stantec, where our business teams span finance, procurement, human resources, information technology, marketing, corporate development, HSSE, real estate, legal, and practice services. We bring together diverse backgrounds and expertise in a collaborative, caring culture. This is a regular, full-time Senior Ethical Hacker role based in Toronto, Ontario, with no travel required. The annual pay range is $105,400–$158,100 for locations outside the Lower Mainland in BC and various locations in Ontario, and $114,600–$164,600 for the Lower Mainland, GTA, and Ottawa. Final compensation depends on education, qualifications, experience, and work location; certain roles may be bonus eligible. Eligible regular employees working at least 20 hours per week can access health, dental and vision plans, wellness programs and spending accounts, retirement and savings plans, employee stock purchase, insurance and disability plans, emergency travel benefits, tuition reimbursement, professional membership fee coverage, and paid time off. Benefits for temporary or casual employees include retirement and savings plans and employee stock purchase; union-position benefits are governed by applicable collective bargaining agreements.

last updated 40 week of 2026

Interested in this role?

Submit your application now

How to Apply

Ready to apply for this position? Here's what you need:

  • An updated resume highlighting relevant experience
  • A compelling cover letter (if required)
  • Portfolio or work samples (for relevant positions)

About Stantec

Stantec

Stantec

London

IT

Skills & Technologies

PythonGoPHPAWSAzureGCPKubernetesTerraformLinuxAILLMDevOps

Inferred from job description

Salary Insight

£83,000

This role

£75,000

UK median

This salary is 11% above the UK median for Senior roles (£75,000/yr).

Based on 2024–2025 UK technology sector benchmarks

Explore More UK Opportunities

Thousands of tech jobs across the United Kingdom