iA Financial Group (Industrial Alliance)

Offensive Security Analyst

iA Financial Group (Industrial Alliance)

full-time

Posted on:

Location Type: Hybrid

Location: QuébecCanada

Visit company website

Explore more

AI Apply
Apply

About the role

  • plan and perform intrusion tests on web applications, APIs, cloud environments, internal infrastructures
  • set up and participate in purple team exercises simulating real attack scenarios
  • collaborate with defensive teams to validate controls and improve detection mechanisms
  • document findings, provide remediation recommendations, and present results to stakeholders
  • stay informed about emerging threats, tools, and techniques in offensive security
  • work with a high degree of autonomy and initiative

Requirements

  • 3 to 5 years of experience in offensive security
  • 7 years of experience in information technology (IT)
  • knowledge of the OWASP Top 10, MITRE ATT&CK, and threat-modeling frameworks
  • ability to perform intrusion tests on various infrastructures
  • proficiency with offensive security tools such as Burp Suite, Nmap, Nessus, BloodHound, Metasploit, Cobalt Strike
  • strong ability to communicate technical concepts clearly
  • intermediate level of English and French proficiency
  • certifications such as OSCP, OSWE, OSEP, CRTP, GPEN, CPTS are strong assets
  • experience in scripting (Python, Bash, PowerShell) for automation and exploit development
  • experience with Infrastructure as Code, such as Terraform
  • background in networking or software development
Benefits
  • flexible group insurance
  • competitive pension plan
  • employee share purchase plan
  • vacation and wellness/personal development days
  • telemedicine
  • employee and family assistance program
  • ergonomic equipment program
  • performance bonus
  • discounts on iA products
  • a healthy, safe, fair, and inclusive environment
Applicant Tracking System Keywords

Tip: use these terms in your resume and cover letter to boost ATS matches.

Hard Skills & Tools
offensive securityintrusion testingscriptingPythonBashPowerShellInfrastructure as CodeTerraformthreat modelingnetworking
Soft Skills
communicationautonomyinitiative
Certifications
OSCPOSWEOSEPCRTPGPENCPTS