We are seeking an experienced Penetration Tester / Offensive Security Consultant to assess the security posture of applications, infrastructure, cloud environments, and network systems through authorized penetration testing and security assessments. The successful candidate will identify exploitable vulnerabilities, evaluate potential business impact, and provide actionable remediation recommendations to strengthen the organization's overall security posture.
The role requires strong hands-on technical expertise, an understanding of modern attack techniques, and the ability to communicate complex security findings clearly to both technical and non-technical stakeholders.
Your future duties and responsibilities
Penetration Testing & Security Assessments
- Plan and execute authorized penetration testing engagements across internal and external environments.
- Conduct network, infrastructure, web application, API, wireless, and cloud security testing, as required.
- Perform vulnerability identification, validation, and controlled exploitation to assess potential security impact.
- Assess authentication, authorization, session management, access controls, and security configurations.
- Identify vulnerabilities arising from misconfigurations, insecure implementations, weak security controls, and architectural weaknesses.
- Evaluate security controls designed to prevent, detect, and respond to potential attacks.
- Perform manual testing to validate automated vulnerability scanning results and identify vulnerabilities that automated tools may not detect.
Application & API Security
- Conduct penetration testing of web and mobile applications and APIs.
- Assess applications against recognized security standards and methodologies, including OWASP Top 10 and OWASP API Security Top 10.
- Evaluate common application security risks, including injection vulnerabilities, broken access controls, authentication weaknesses, insecure configurations, and business logic vulnerabilities.
- Review application attack surfaces and identify potential pathways that could lead to unauthorized access or data exposure.
Infrastructure & Cloud Security
Perform security assessments of internal and external network infrastructure.
- Evaluate operating systems, network devices, security appliances, and exposed services.
- Conduct penetration testing of cloud environments, where authorized, including Microsoft Azure, AWS, and Google Cloud Platform.
- Assess identity and access management configurations, cloud permissions, exposed resources, and potential privilege escalation paths.
- Evaluate Active Directory and enterprise identity environments for security weaknesses and potential attack paths.
Vulnerability Analysis & Risk Assessment
- Analyze identified vulnerabilities to determine exploitability, severity, and potential business impact.
- Prioritize findings based on technical risk, business context, and likelihood of exploitation.
- Apply industry-standard vulnerability scoring methodologies, including CVSS, where appropriate.
- Research emerging vulnerabilities, attack techniques, and threat trends relevant to the organization's technology environment.
Reporting & Remediation
- Develop clear and comprehensive penetration testing reports documenting methodology, findings, evidence, risk ratings, business impact, and recommended remediation actions.
- Provide executive-level summaries for senior management and detailed technical findings for security and technology teams.
- Present penetration testing results to technical teams, application owners, security leadership, and other stakeholders.
- Collaborate with infrastructure, application, cloud, and cybersecurity teams to support vulnerability remediation.
- Perform remediation validation and retesting to confirm that identified vulnerabilities have been effectively addressed.
Governance & Testing Standards
- Conduct all penetration testing activities within formally approved Rules of Engagement (ROE) and defined scope.
- Ensure testing activities are performed safely and minimize the risk of disruption to production systems.
- Maintain accurate documentation of testing activities, evidence, findings, and remediation status.
- Follow established penetration testing methodologies and industry standards, such as PTES, OWASP Testing Guide, NIST guidance, and relevant security frameworks.
- Support continuous improvement of penetration testing methodologies, processes, tools, and reporting standards.
Required qualifications to be successful in this role
- Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, or a related discipline, or equivalent practical experience.
- Demonstrated experience conducting hands-on penetration testing and security assessments. Strong knowledge of TCP/IP, networking protocols, operating systems, web technologies, APIs, and enterprise infrastructure.
- Experience with Windows and Linux security testing. Understanding of Active Directory, identity and access management, authentication protocols, and privilege escalation techniques.
- Knowledge of web applications and API security vulnerabilities and OWASP methodologies.
- Familiarity with cloud security concepts and major cloud platforms.
- Ability to analyze technical vulnerabilities and translate findings into business risk.
- Strong technical documentation and report-writing skills.
- Excellent verbal and written communication skills.
- Ability to work independently and collaboratively with technical and business stakeholders.
CGI is providing a reasonable estimate of the pay range for this role. The determination of this range includes factors such as skill set level, geographic market, experience and training, and licenses and certifications. Compensation decisions depend on the facts and circumstances of each case. A reasonable estimate of the current range is $95,000–$145,000. This role is an existing vacancy.
#LI-YK2
Together, as owners, let’s turn meaningful insights into action.
Life at CGI is rooted in ownership, teamwork, respect and belonging. Here, you’ll reach your full potential because…
You are invited to be an owner from day 1 as we work together to bring our Dream to life. That’s why we call ourselves CGI Partners rather than employees. We benefit from our collective success and actively shape our company’s strategy and direction.
Your work creates value. You’ll develop innovative solutions and build relationships with teammates and clients while accessing global capabilities to scale your ideas, embrace new opportunities, and benefit from expansive industry and technology expertise.
You’ll shape your career by joining a company built to grow and last. You’ll be supported by leaders who care about your health and well-being and provide you with opportunities to deepen your skills and broaden your horizons.
At CGI, we value the strength that diversity brings and are committed to fostering a workplace where everyone belongs. We collaborate with our clients to build more inclusive communities and empower all CGI partners to thrive. As an equal-opportunity employer, being able to perform your best during the recruitment process is important to us. If you require an accommodation, please inform your recruiter.
That same commitment to fairness extends to how we use technology. To support our recruitment team, AI tools may be used to help assess applications though they never replace human judgement. All hiring decisions remain entirely in the hands of our recruitment professionals.
To learn more about accessibility at CGI, contact us via email. Please note that this email is strictly for accessibility requests and cannot be used for application status inquiries.
Come join our team—one of the largest IT and business consulting services firms in the world.