Description review

Pen test platform

Workiy Inc. · United States · back to the listing

HR standards

45/100

poor

Title ↔ description

35/100

poor

Reads as

Security Engineer

98% confident

What this role officially is

ICT security administrator — ESCO, the EU occupation classification

ICT security administrators plan and carry out security measures to protect information and data from unauthorised access, deliberate attack, theft and corruption.

Also known as: network security administrator, system security administrator, ICT security administrators, IT security administrator

How others title the same work

Large employers

  • Security Risk Management Specialist Canonical Ltd.
  • Security Software Engineer Canonical Ltd.
  • Senior Security Operations Engineer Canonical Ltd.
  • Staff Security Operations Engineer Canonical Ltd.
  • Ubuntu Security Engineer Canonical Ltd.

Startups

  • Security Engineer (Bangalore, India) AiPrise
  • Security & Trust Engineer Alex
  • Elucid | Senior Security Engineer | Boston, MA | ONSITE (hybrid) | $130k–$170k Elucid
  • Factory | Security Engineer | ONSITE, San Francisco, CA | Full-Time Factory
  • Factory | Security Engineer | Onsite in San Francisco | Full-time Factory

What the listing never says

  • 18 bullet points. Long requirement lists deter qualified candidates, who read them as hard gates. Scope clarity
  • No pay range published. Candidates cannot tell whether applying is worth their time. Pay transparency

The listing, marked up

This is a remote position.

We are seeking anExpert-level Information Security Consultantto drive the ongoing maturity of Fraser Health's penetration testing program. In this role, you will perform end-to-end grey-box penetration tests across a large portfolio of web and API applications while utilizing a secure, browser-based management platform to schedule assessments, track vulnerabilities, and manage remediation lifecycles
Requirements

• Scoping & Sizing:Conduct T-shirt sizing (Small, Medium, Large) and scoping for onboarded applications based on dynamic web pages and user roles.

• Penetration Testing Execution:Execute manual and tool-assisted grey-box penetration tests across approximately 123 Web/API applications (30 Large, 51 Medium, 42 Small), completing testing within 5–10 days per application.

• Engagement Lifecycles:Manage the end-to-end testing lifecycle for each application from kickoff meeting to final sign-off within 20–25 days.

• In-Depth Vulnerability Assessment:Conduct expert manual assessments covering authentication, session management, MFA bypass, horizontal/vertical privilege escalation, IDOR/BOLA, API vulnerabilities, and business logic workflow abuses.

• Attack-Path Validation:Chain vulnerabilities into realistic attack paths and perform controlled, non-destructive validation within live healthcare environments without disrupting operational or clinical systems.

• Platform Management:Deploy and operate a browser-based, RBAC/MFA-enabled pen test platform supporting 6–12 month forward scheduling, metric dashboards, report retention, automated notifications, and GRC tool integration.

• Tooling & Environment Setup:Install, configure, and maintain all necessary licensed testing tools inside the client-provided penetration testing machines accessed via the Privileged Access Management (PAM) platform.

• Reporting & Debriefs:Author comprehensive reports with testing methodologies, scorecards, reproducible steps, root-cause analyses, and prioritized remediation guidance, followed by stakeholder presentations.

• Remediation Tracking & Retesting:Follow up with application owners on vulnerability mitigations and perform targeted retests on resolved findings.

Required Qualifications & Experience

• Certifications:Active penetration testing certification such asOSCP(Offensive Security Certified Professional),CEH(Certified Ethical Hacker), or an equivalent credential.


Seniority Threshold (Expert Level):

• Relevant Degree + minimum 6 years of consulting experience.

• Relevant Diploma + minimum 7 years of consulting experience.

• Relevant Certificate + minimum 8 years of consulting experience.

• Minimum 10 years1 of directly related consulting experience.

• Healthcare & Production Experience:Demonstrated experience performing penetration testing safely in Canadian healthcare or sensitive enterprise environments with zero clinical/operational impact.

• Employment Status:Must be a permanent employee of the service provider (subcontracting is prohibited).

• Framework Alignment:Practical working knowledge of OWASP, NIST SP 800-53A, PCI DSS 11.3, and IDART standards

Originally posted on Himalayas

How this was produced

Highlights are found by rule, not by a model: each one is a phrase matched at a known position, and every note is a template we wrote. The two scores come from a typed-decision model (Jev) that reads the listing against the official role definition and real listings for the same role, and returns probabilities rather than prose — it never writes any of the words on this page, and never chooses what to highlight.

Deterministic penalty applied to the HR score: 16 points (from 61 before penalties). Reviewed 21 Sep 2026.