Cookies & analytics consent
We serve candidates globally, so we only activate Google Tag Manager and other analytics after you opt in. This keeps us aligned with GDPR/UK DPA, ePrivacy, LGPD, and similar rules. Essential features still run without analytics cookies.
Read how we use data in our Privacy Policy and Terms of Service.
🤖 15+ AI Agents working for you. Find jobs, score and update resumes, cover letter, interview questions, missing keywords, and lots more.

NetSPI • Toronto, Ontario, Canada
Salary: 500 compa
Role & seniority: Experienced Cloud Penetration Tester (senior level) specializing in Google Cloud Platform.
Stack/tools: Google Cloud Platform; cloud/offensive tooling; IAM and cloud security fundamentals; PAAS services; programming in Python, PowerShell, C#, or Go (nice-to-have); custom tools and TTP development.
Execute cloud penetration tests against GCP environments and develop innovative TTPs for cloud testing.
Create attack narratives and findings-based penetration test reports; collaborate with clients on remediation strategies.
Act as a technical resource, QA review cloud engagements, and help define/internal processes and TTPs; contribute tools/papers to the security community.
3–5 years in offensive/attack-oriented penetration testing of GCP and external/internal networks.
Certifications such as GXPN, OSCP, OSCE, or equivalent.
Strong communication, presentation, and writing skills.
Experience with security-focused cloud configuration reviews and offensive toolkits for cloud/network testing.
Knowledge of cloud misconfigurations in Compute, Storage, Databases, Networking, Kubernetes, and PAAS; IAM security fundamentals; ability to assess external/internal cloud attack surfaces.
Programming experience (Python, PowerShell, C#, Go).
Researching new cloud offerings to identify misconfigurations and vulnerabilities.
Web application penetration testing experience
NetSPI® pioneered Penetration Testing as a Service (PTaaS) and leads the industry in modern pentesting. Combining world-class security professionals with AI and automation, NetSPI delivers clarity, speed, and scale across 50+ pentest types, attack surface management, and vulnerability prioritization. The NetSPI platform streamlines workflows and accelerates remediation, enabling our experts to focus on deep dive testing that uncovers vulnerabilities others miss. Trusted by the top 10 U.S. banks and Fortune 500 companies worldwide, NetSPI has been driving security innovation since 2001.
NetSPI is on an exciting growth journey as we disrupt and improve the proactive security market. We are looking for individuals with a collaborative, innovative, and customer-first mindset to join our team. Learn more about our award-winning workplace culture and get to know our A-Team at www.netspi.com/careers.
We are seeking an experienced professional with demonstrated technical depth and breadth in Cloud Penetration Testing as well as the soft skills to effectively communicate with executive and technical teams. In this role, you'll have the ability to work alongside a world-class team using top-tier custom tools. Applicants are expected to leverage strong problem-solving skills, as well as lead, collaborate, and innovate to deliver high-quality exercises and exceptional experiences for our customers.
Responsibilities
Execute cloud penetration tests against Google Cloud Platform environments. Develop innovative TTPs in support of Cloud testing. Create attack narratives and findings-based penetration test reports for clients. Collaborate with clients to create remediation strategies that will help improve their security posture. Act as a resource for internal team members as it relates to in-depth technical questions or best practices in Cloud. Assist in QA review of Cloud engagements. Help define and document internal processes and TTPs. Contribute to the information security community through the development of tools, presentations, white papers, and blogs.
Minimum Qualifications
Bachelor's degree or higher with a concentration in computer science, engineering, math, IT, or equivalent experience. 3 - 5 years experience performing offensive/attack-oriented penetration tests against GCP environments and External/Internal networks. Recognized Penetration Testing specific qualifications such as GXPN, OSCP, OSCE, or similar certifications. Strong communication, presentation, and writing skills. Experience performing security focused cloud configuration reviews. Experience with offensive toolkits for both cloud and network penetration testing.
Programming experience in one or more of the following languages: Python, PowerShell, C#, Go. Experience researching new cloud service offerings with the goal of identifying misconfigurations and vulnerabilities. Web Application pentesting experience.
We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law.