1

Penetration Testing Jobs in Ontario (NOW HIRING)

Software Secured is a leading Penetration Testing as a Service company, with a head office in beautiful Ottawa, Canada. We help software development teams get ahead of hackers using a suite of ...

Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.

Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.

Conduct manual penetration testing on web applications, network devices, and other systems * Collaborate with our clients in a fast-paced environment across many technology stacks and services ...

Director, Offensive Security

Toronto, ON · On-site

CA$138K - CA$181K/yr

You'll lead offensive security initiatives including penetration testing, red teaming, AI security validation, vulnerability management, and bug bounty programs while partnering closely with ...

You'll lead offensive security initiatives including penetration testing, red teaming, AI security validation, vulnerability management, and bug bounty programs while partnering closely with ...

next page

Showing results 1-20

Penetration Testing information

See Ontario salary details

$27K

$118.1K

$181K

How much do penetration testing jobs pay per year?

As of Sep 6, 2026, the average yearly pay for penetration testing in Ontario is $118,104.00, according to ZipRecruiter salary data. Most workers in this role earn between $90,500.00 and $150,000.00 per year, depending on experience, location, and employer.

What is penetration testing?

Penetration testing, also known as ethical hacking, is a security practice where professionals simulate cyberattacks on a computer system, network, or application to identify vulnerabilities before malicious hackers can exploit them. The goal is to find and safely exploit weaknesses, assess the impact of potential attacks, and provide recommendations to improve security. Penetration testers use a variety of tools and techniques, often mirroring real-world attack methods, to thoroughly evaluate an organization’s defenses. It is a proactive approach to improving an organization's cybersecurity posture.

What are some common challenges faced by penetration testers during client engagements?

Penetration testers often encounter challenges such as limited access to information, time constraints, and complex network environments that can hinder thorough assessments. Additionally, balancing the need to simulate real-world attacks while ensuring no disruption to client operations requires careful planning and communication. Collaborating effectively with IT teams and clearly documenting findings are crucial for ensuring that vulnerabilities are properly understood and addressed.

What is the difference between Penetration Testing vs Vulnerability Assessment?

AspectPenetration TestingVulnerability Assessment
PurposeSimulate cyberattacks to identify exploitable vulnerabilitiesIdentify and prioritize security weaknesses
DepthIn-depth, targeted testingBroad, comprehensive scanning
CertificationsOSCP, CEH, GPENOSCP, CEH, Security+
Work EnvironmentHands-on testing, simulated attacksAutomated scans, reports

While both roles focus on security weaknesses, Penetration Testing involves actively exploiting vulnerabilities to assess real-world impact, whereas Vulnerability Assessment identifies potential issues for prioritization. Penetration Testing provides a deeper, more targeted security evaluation, making it essential for comprehensive security testing.

Are penetration testers high in demand?

Penetration testers are in high demand due to increasing cybersecurity threats and the need for organizations to identify vulnerabilities. The role often requires skills in tools like Kali Linux and certifications such as OSCP, with job growth expected to remain strong in the cybersecurity field.

Is penetration testing a good career?

Penetration testing is a growing cybersecurity field that involves identifying vulnerabilities in computer systems and networks. It requires technical skills, knowledge of security tools, and often certifications like OSCP or CEH. The role offers high demand, competitive salaries, and opportunities for continuous learning, making it a viable career choice for those interested in cybersecurity.

What are the most commonly searched types of Penetration Testing jobs in Ontario?

The most popular types of Penetration Testing jobs in Ontario are:

Infographic showing various Penetration Testing job openings in Ontario as of August 2026, with employment types broken down into 1% As Needed, 81% Full Time, 14% Part Time, 3% Contract, and 1% Nights. Highlights an 87% Physical, 3% Hybrid, and 10% Remote job distribution, with an average salary of $118,104 per year, or $56.8 per hour.

Full-time

Re-posted 12 days ago


Sun Life Assurance Company of Canada rating

8.6

Company rating: 8.6 out of 10

Based on 18 frontline employees who took The Breakroom Quiz

94th of 315 rated insurance


Job description

You are as unique as your background, experience and point of view. Here, you'll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll have new and exciting opportunities to make life brighter for our Clients - who are at the heart of everything we do.


At Sun Life, we're driven by our Purpose: helping our Clients achieve lifetime financial security and live healthier lives. Our values shape how we work: caring, authentic, bold, inspiring, and impactful.


When you join Sun Life, you'll work with passionate colleagues and empowering leaders who support your growth and celebrate your contributions, so you can make a meaningful difference in our Clients' lives.


Discover how you can make a difference in the lives of individuals, families and communities around the world.


Job Description:

At Sun Life, we work together, share common values, and encourage growth and achievement. We are seeking a skilled Penetration Testing Analyst to perform hands-on security testing of applications, infrastructure, and systems.

This role is primarily focused on Penetration Testing delivery, with secondary exposure to Red Team activities, contributing to adversary simulation exercises where required. The successful candidate will have strong technical testing capabilities, with an interest in developing broader offensive security skills.

Key Responsibilities
  • Perform web, API, mobile, and infrastructure penetration testing across enterprise applications.

  • Identify, exploit, and validate security vulnerabilities using manual testing techniques and industry tools.

  • Conduct testing in line with established methodologies and security frameworks (e.g., OWASP).

  • Produce clear, structured reports outlining:

    • Vulnerabilities and root cause

    • Business impact and risk rating

    • Practical remediation recommendations

  • Perform research into new vulnerabilities, exploits, and attack techniques to enhance testing coverage.

  • Support re-testing activities to validate remediation of identified issues.

  • Support Red Team activities where required.

  • Contribute to reconnaissance and attack surface mapping, Identification of potential attack paths.

  • Support documentation of attack paths and identified security gaps.

  • Assist in controlled exploitation activities under guidance, including:

    • Initial access techniques

    • Limited post-exploitation validation (e.g., privilege escalation concepts, lateral movement awareness)

  • Collaborate with senior team members to understand real-world attacker behaviour and techniques.

Required Skills & ExperienceCore Penetration Testing Skills (Essential)
  • 2+ years of hands-on experience in:

    • Web application security testing (OWASP Top 10)

    • API security testing

    • Basic network/infrastructure testing

  • Strong understanding of:

    • Authentication, session management, and access control flaws

    • Input validation and injection vulnerabilities

  • Experience with tools such as:

    • Burp Suite, Nmap, sqlmap, or similar

  • Ability to perform manual testing beyond automated scanning.

  • Strong documentation and reporting skills, with focus on clear risk articulation.

Red Teaming Skills (Desirable - Foundational Level)
  • Basic understanding of adversary simulation concepts and attack lifecycle.

  • Familiarity with:

    • Reconnaissance techniques

    • Common initial compromise methods

  • Awareness of:

    • Privilege escalation and lateral movement concepts

    • Attack paths across enterprise environments

  • Interest in developing Red Team and offensive security capabilities over time.

Qualifications
  • Bachelor's degree in Computer Science, Information Security, or a related field.

  • Certifications such as OSCP, OSWA, CISSP or CompTIA are desired but not required.

Job Category:

IT - Technology Services

Posting End Date:

30/12/2026

What Sun Life Assurance Company of Canada employees say

Pay

Benefits

Hours and flexibility

Workplace

Get the full story on Breakroom