We are seeking a skilled Penetration Testing Analyst to perform hands-on security testing of applications, infrastructure, and systems. This role is primarily focused on Penetration Testing delivery ...
We are seeking a skilled Penetration Testing Analyst to perform hands-on security testing of applications, infrastructure, and systems. This role is primarily focused on Penetration Testing delivery ...
Penetration Testing Analyst
Toronto, ON · On-site
We are seeking a skilled Penetration Testing Analyst to perform hands-on security testing of applications, infrastructure, and systems. This role is primarily focused on Penetration Testing delivery ...
Penetration Testing Analyst
Toronto, ON · On-site
We are seeking a skilled Penetration Testing Analyst to perform hands-on security testing of applications, infrastructure, and systems. This role is primarily focused on Penetration Testing delivery ...
Penetration testing: Experience in planning, executing, and overseeing penetration testing for internet-facing and internal applications. * Regulatory & Control Frameworks : Expertise in maintaining ...
Penetration testing: Experience in planning, executing, and overseeing penetration testing for internet-facing and internal applications. * Regulatory & Control Frameworks : Expertise in maintaining ...
Perform Internet penetration testing (blackbox/greybox /whitebox testing) and network architecture reviews (manual/automated) * Perform other security testing tasks such as wireless penetration ...
Perform Internet penetration testing (blackbox/greybox /whitebox testing) and network architecture reviews (manual/automated) * Perform other security testing tasks such as wireless penetration ...
Penetration Tester
Ottawa, ON · On-site +1
Software Secured is a leading Penetration Testing as a Service company, with a head office in beautiful Ottawa, Canada. We help software development teams get ahead of hackers using a suite of ...
Penetration Tester
Ottawa, ON · On-site +1
Software Secured is a leading Penetration Testing as a Service company, with a head office in beautiful Ottawa, Canada. We help software development teams get ahead of hackers using a suite of ...
NetSPI ® is an award-winning pioneer of Penetration Testing as a Service (PTaaS) with its AI-powered platform supported by more than 350 in-house cybersecurity experts. Specializing in 50+ pentest ...
Quick apply
NetSPI ® is an award-winning pioneer of Penetration Testing as a Service (PTaaS) with its AI-powered platform supported by more than 350 in-house cybersecurity experts. Specializing in 50+ pentest ...
Web Application Penetration Tester
Ottawa, ON · Hybrid
CA$90K - CA$110K/yr
Configure, run, and monitor automated security testing tools. * Thoroughly document exploit chain ... GIAC Web Application Penetration Tester (GWAPT). * GIAC Certified Incident Handler (GCIH)
Web Application Penetration Tester
Ottawa, ON · Hybrid
CA$90K - CA$110K/yr
Configure, run, and monitor automated security testing tools. * Thoroughly document exploit chain ... GIAC Web Application Penetration Tester (GWAPT). * GIAC Certified Incident Handler (GCIH)
Web Application Penetration Tester
Kitchener, ON · Hybrid
CA$90K - CA$110K/yr
Configure, run, and monitor automated security testing tools. * Thoroughly document exploit chain ... GIAC Web Application Penetration Tester (GWAPT). * GIAC Certified Incident Handler (GCIH)
Web Application Penetration Tester
Kitchener, ON · Hybrid
CA$90K - CA$110K/yr
Configure, run, and monitor automated security testing tools. * Thoroughly document exploit chain ... GIAC Web Application Penetration Tester (GWAPT). * GIAC Certified Incident Handler (GCIH)
Web Application Penetration Tester
Toronto, ON · Hybrid
CA$90K - CA$110K/yr
Configure, run, and monitor automated security testing tools. * Thoroughly document exploit chain ... GIAC Web Application Penetration Tester (GWAPT). * GIAC Certified Incident Handler (GCIH)
Web Application Penetration Tester
Toronto, ON · Hybrid
CA$90K - CA$110K/yr
Configure, run, and monitor automated security testing tools. * Thoroughly document exploit chain ... GIAC Web Application Penetration Tester (GWAPT). * GIAC Certified Incident Handler (GCIH)
Lead Penetration Test Engineer
Toronto, ON · Hybrid
CA$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Toronto, ON · Hybrid
CA$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Toronto, ON · Hybrid
CA$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Lead Penetration Test Engineer
Toronto, ON · Hybrid
CA$135K/yr
Penetration Testing & Vulnerability Assessments Conduct comprehensive penetration testing of web applications, infrastructure, and cloud environments using both manual and automated techniques.
Offensive Security - Penetration Tester
Toronto, ON · On-site
CA$62K - CA$107K/yr
Conduct manual penetration testing on web applications, network devices, and other systems * Collaborate with our clients in a fast-paced environment across many technology stacks and services ...
Offensive Security - Penetration Tester
Toronto, ON · On-site
CA$62K - CA$107K/yr
Conduct manual penetration testing on web applications, network devices, and other systems * Collaborate with our clients in a fast-paced environment across many technology stacks and services ...
Penetration Testing Execution Standard (PTES) * Programming knowledge (python, java) * Relevant certifications, such as: * Offensive Security Certified Professional (OSCP) * Burp Suite Certified ...
Penetration Testing Execution Standard (PTES) * Programming knowledge (python, java) * Relevant certifications, such as: * Offensive Security Certified Professional (OSCP) * Burp Suite Certified ...
Penetration Testing Execution Standard (PTES) * Programming knowledge (python, java) * Relevant certifications, such as: * Offensive Security Certified Professional (OSCP) * Burp Suite Certified ...
Penetration Testing Execution Standard (PTES) * Programming knowledge (python, java) * Relevant certifications, such as: * Offensive Security Certified Professional (OSCP) * Burp Suite Certified ...
Penetration Testing Execution Standard (PTES) * Programming knowledge (python, java) * Relevant certifications, such as: * Offensive Security Certified Professional (OSCP) * Burp Suite Certified ...
Penetration Testing Execution Standard (PTES) * Programming knowledge (python, java) * Relevant certifications, such as: * Offensive Security Certified Professional (OSCP) * Burp Suite Certified ...
RBC Adversary Emulation is hiring experienced Red Team Operators and Penetration Testers. We're looking for professionals to join us in delivering scenario-driven Red Team operations, Purple Team ...
RBC Adversary Emulation is hiring experienced Red Team Operators and Penetration Testers. We're looking for professionals to join us in delivering scenario-driven Red Team operations, Purple Team ...
RBC Adversary Emulation is hiring experienced Red Team Operators and Penetration Testers. We're looking for professionals to join us in delivering scenario-driven Red Team operations, Purple Team ...
RBC Adversary Emulation is hiring experienced Red Team Operators and Penetration Testers. We're looking for professionals to join us in delivering scenario-driven Red Team operations, Purple Team ...
Director, Offensive Security
Toronto, ON · On-site
CA$138K - CA$181K/yr
You'll lead offensive security initiatives including penetration testing, red teaming, AI security validation, vulnerability management, and bug bounty programs while partnering closely with ...
Director, Offensive Security
Toronto, ON · On-site
CA$138K - CA$181K/yr
You'll lead offensive security initiatives including penetration testing, red teaming, AI security validation, vulnerability management, and bug bounty programs while partnering closely with ...
You'll lead offensive security initiatives including penetration testing, red teaming, AI security validation, vulnerability management, and bug bounty programs while partnering closely with ...
Quick apply
You'll lead offensive security initiatives including penetration testing, red teaming, AI security validation, vulnerability management, and bug bounty programs while partnering closely with ...
Senior Information Security Analyst (Secure Code Review)
Toronto, ON · On-site
CA$81K - CA$115K/yr
As aSecure Code Reviewer /Penetration Tester, you will be responsible for identifying and exploiting vulnerabilities in applications and infrastructure to help improve our cybersecurity posture. You ...
Senior Information Security Analyst (Secure Code Review)
Toronto, ON · On-site
CA$81K - CA$115K/yr
As aSecure Code Reviewer /Penetration Tester, you will be responsible for identifying and exploiting vulnerabilities in applications and infrastructure to help improve our cybersecurity posture. You ...
Penetration Testing information
See Ontario salary details
$27K - $41K
5% of jobs
$41K - $55K
5% of jobs
$55K - $69K
3% of jobs
$69K - $83K
6% of jobs
$90.9K is the 25th percentile. Wages below this are outliers.
$83K - $97K
9% of jobs
$97K - $111K
11% of jobs
The median wage is $122.7K / yr.
$111K - $125K
13% of jobs
$125K - $139K
12% of jobs
$147.2K is the 75th percentile. Wages above this are outliers.
$139K - $153K
19% of jobs
$153K - $167K
13% of jobs
$167K - $181K
4% of jobs
$27K
$118.1K
$181K
How much do penetration testing jobs pay per year?
What is penetration testing?
What are some common challenges faced by penetration testers during client engagements?
What is the difference between Penetration Testing vs Vulnerability Assessment?
| Aspect | Penetration Testing | Vulnerability Assessment |
|---|---|---|
| Purpose | Simulate cyberattacks to identify exploitable vulnerabilities | Identify and prioritize security weaknesses |
| Depth | In-depth, targeted testing | Broad, comprehensive scanning |
| Certifications | OSCP, CEH, GPEN | OSCP, CEH, Security+ |
| Work Environment | Hands-on testing, simulated attacks | Automated scans, reports |
While both roles focus on security weaknesses, Penetration Testing involves actively exploiting vulnerabilities to assess real-world impact, whereas Vulnerability Assessment identifies potential issues for prioritization. Penetration Testing provides a deeper, more targeted security evaluation, making it essential for comprehensive security testing.
Are penetration testers high in demand?
Is penetration testing a good career?
What are the most commonly searched types of Penetration Testing jobs in Ontario?
The most popular types of Penetration Testing jobs in Ontario are:

Sun Life Assurance Company of Canada rating
8.6
Based on 18 frontline employees who took The Breakroom Quiz
94th of 315 rated insurance
Job description
You are as unique as your background, experience and point of view. Here, you'll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll have new and exciting opportunities to make life brighter for our Clients - who are at the heart of everything we do.
At Sun Life, we're driven by our Purpose: helping our Clients achieve lifetime financial security and live healthier lives. Our values shape how we work: caring, authentic, bold, inspiring, and impactful.
When you join Sun Life, you'll work with passionate colleagues and empowering leaders who support your growth and celebrate your contributions, so you can make a meaningful difference in our Clients' lives.
Discover how you can make a difference in the lives of individuals, families and communities around the world.
Job Description:
At Sun Life, we work together, share common values, and encourage growth and achievement. We are seeking a skilled Penetration Testing Analyst to perform hands-on security testing of applications, infrastructure, and systems.
This role is primarily focused on Penetration Testing delivery, with secondary exposure to Red Team activities, contributing to adversary simulation exercises where required. The successful candidate will have strong technical testing capabilities, with an interest in developing broader offensive security skills.
Perform web, API, mobile, and infrastructure penetration testing across enterprise applications.
Identify, exploit, and validate security vulnerabilities using manual testing techniques and industry tools.
Conduct testing in line with established methodologies and security frameworks (e.g., OWASP).
Produce clear, structured reports outlining:
Vulnerabilities and root cause
Business impact and risk rating
Practical remediation recommendations
Perform research into new vulnerabilities, exploits, and attack techniques to enhance testing coverage.
Support re-testing activities to validate remediation of identified issues.
Support Red Team activities where required.
Contribute to reconnaissance and attack surface mapping, Identification of potential attack paths.
Support documentation of attack paths and identified security gaps.
Assist in controlled exploitation activities under guidance, including:
Initial access techniques
Limited post-exploitation validation (e.g., privilege escalation concepts, lateral movement awareness)
Collaborate with senior team members to understand real-world attacker behaviour and techniques.
2+ years of hands-on experience in:
Web application security testing (OWASP Top 10)
API security testing
Basic network/infrastructure testing
Strong understanding of:
Authentication, session management, and access control flaws
Input validation and injection vulnerabilities
Experience with tools such as:
Burp Suite, Nmap, sqlmap, or similar
Ability to perform manual testing beyond automated scanning.
Strong documentation and reporting skills, with focus on clear risk articulation.
Basic understanding of adversary simulation concepts and attack lifecycle.
Familiarity with:
Reconnaissance techniques
Common initial compromise methods
Awareness of:
Privilege escalation and lateral movement concepts
Attack paths across enterprise environments
Interest in developing Red Team and offensive security capabilities over time.
Bachelor's degree in Computer Science, Information Security, or a related field.
Certifications such as OSCP, OSWA, CISSP or CompTIA are desired but not required.
Job Category:
IT - Technology ServicesPosting End Date:
30/12/2026What Sun Life Assurance Company of Canada employees say
Pay
Benefits
Hours and flexibility
Workplace
Get the full story on Breakroom
About Sun Life
Sourced by ZipRecruiter
Industry
Insurance carriers and finance and insurance
Company size
10,000+ Employees
Headquarters location
Toronto, ON, CA