Penetration Tester

Apptoza Inc.

toronto, on, Canada
Full-time
Posted June 04, 2026

Job Description

Strong API Automation Skills, Experienced in Rest API Testing & SQL

Required Experience

  • 6+ years of IT experience with minimum 3 years of experience in Application Security including Code Security Review.
  • Professional certification or designation in information security. An application security focused certification or designation is preferred. (e.g. GPEN, OSCP, etc.)
  • Hands‑on experience in using industry‑standard tools for Penetration Testing and Source Code Review such as BurpSuite, OWASP ZAP, Fortify, Veracode etc.
  • Support/lead operational application security activities including but not limited to penetration tests, mobile tests, secure code review.
  • Provide advisory services to IT teams to support remediation of vulnerabilities.

Qualifications

  • Web Application Security (including web, mobile, API)
  • Knowledge of AppSec industry practices (including OWASP)
  • Understa...