Stantec
Senior Ethical Hacker
Job Description
Salary: £63,000 - 103,000 per year
Requirements:- We require a minimum of 5–7+ years of cybersecurity experience; offensive security or Red Team experience is preferred.
- We require at least 5 years of relevant experience and a related degree or certificate, preferably in Offensive Security, AI Red Teaming, or Application Security.
- We require proficiency in manual web and cloud penetration testing, including testing without tools.
- We require proficiency writing custom attack tools using Python, PHP, Golang, and Bash.
- We require proficiency with interception proxies and manual testing using Burp Suite Enterprise.
- We require experience building or maintaining attack automation systems, containers, and automation pipelines for attack purposes.
- We require the ability to combine multiple low- or medium-severity findings to achieve a higher level of impact.
- We require comfort working from the Windows or Linux command line and using VIM/VI, Bash/SH, Perl, VBScript, WMI, or PowerShell for post-exploitation and lateral movement.
- We require experience with XSS attacks, system or SQL injection payloads, or binary weaponization.
- We require experience attacking public cloud services such as Azure, AWS, GCP, or Oracle.
- We require the ability to present audit findings to small groups or C-suite audiences, take ownership of testing activities, and conduct blameless post-mortems.
- Preferred additional skills or credentials include OSWE, OSAI, GWAPT, BSCP, PACSP, CKS, Terraform Associate (003), DevSecOps experience, AI/LLM penetration-testing experience, and responsible-disclosure or bug-bounty findings.
- We conduct security assessments and penetration tests on web applications, cloud services, systems, and APIs, emulating real-world attacks using the MITRE ATT&CK Framework.
- We identify and validate vulnerabilities, misconfigurations, access-control and encryption weaknesses, and other security risks across applications and cloud environments.
- We assess application services, databases, Kubernetes, serverless functions, container instances and images, and cloud storage.
- We collaborate with security, engineering, cloud, and network operations teams.
- We prepare reports, communicate findings to technical teams, architects, and engineers, and present test results in debrief meetings with executives or sponsors.
- We develop and communicate processes that help engineering teams meet remediation goals.
- We assist with or create rules of engagement for penetration-testing projects.
- We design automated workflows for independent security evaluation and assurance, establish security baseline controls through Policy-as-Code, and build custom Python, Terraform, and Ansible extensions for specialized security and infrastructure use cases.
- We create or maintain internal training-lab content and, as time permits, provide practical CTF activities and live hacking webinars for developers and security champions.
- We conduct internal Red Team engagements and participate in purple-team engagements.
- AI
- AWS
- Ansible
- Azure
- Bash
- Cloud
- DevSecOps
- GCP
- Golang
- Kubernetes
- LLM
- Linux
- Marketing
- Network
- Oracle
- PHP
- Perl
- PowerShell
- Python
- SQL
- Security
- Serverless
- Terraform
- Web
- Windows
- Architect
- DevOps
More:
We are Stantec, where our business teams span finance, procurement, human resources, information technology, marketing, corporate development, HSSE, real estate, legal, and practice services. We bring together diverse backgrounds and expertise in a collaborative, caring culture. This is a regular, full-time Senior Ethical Hacker role based in Toronto, Ontario, with no travel required. The annual pay range is $105,400–$158,100 for locations outside the Lower Mainland in BC and various locations in Ontario, and $114,600–$164,600 for the Lower Mainland, GTA, and Ottawa. Final compensation depends on education, qualifications, experience, and work location; certain roles may be bonus eligible. Eligible regular employees working at least 20 hours per week can access health, dental and vision plans, wellness programs and spending accounts, retirement and savings plans, employee stock purchase, insurance and disability plans, emergency travel benefits, tuition reimbursement, professional membership fee coverage, and paid time off. Benefits for temporary or casual employees include retirement and savings plans and employee stock purchase; union-position benefits are governed by applicable collective bargaining agreements.
last updated 40 week of 2026
Interested in this role?
Submit your application now
How to Apply
About Stantec
Stantec
London
IT
Skills & Technologies
Inferred from job description
Salary Insight
£83,000
This role
£75,000
UK median
This salary is 11% above the UK median for Senior roles (£75,000/yr).
Based on 2024–2025 UK technology sector benchmarks