cover image
Galent

Information Security Engineer

Hybrid

Toronto, Canada

Freelance

20-01-2026

Share this job:

Skills

Python Java JavaScript GraphQL Penetration Testing Cloud Security Burp Suite CI/CD Kubernetes Security Testing Architecture Programming Azure AWS .NET GCP CI/CD Pipelines Android Microservices

Job Specifications

Key Responsibilities

Perform application security testing (SAST, DAST, IAST, SCA)
Conduct manual web and API penetration testing
Identify and remediate vulnerabilities aligned with OWASP Top 10, CWE, and CVE
Review source code for security flaws (Java, .NET, Python, JavaScript)
Secure REST / GraphQL APIs, microservices, and authentication flows
Collaborate with developers to provide secure coding guidance
Integrate security tools into CI/CD pipelines
Perform threat modeling and architecture risk assessments
Validate fixes and provide risk-based security reports
Support compliance requirements (SOC2, PCI-DSS, ISO 27001)

Required Skills

Strong knowledge of Web Application Security
Hands-on experience with:
Burp Suite, OWASP ZAP, Fortify, Veracode, Checkmarx
Snyk, Mend, Black Duck (SCA)
Programming knowledge: Java, Python, JavaScript, .NET
API security (OAuth 2.0, OpenID Connect, JWT)
Understanding of DevSecOps practices
Cloud security basics (AWS / Azure / GCP)

Good to Have

Mobile security testing (iOS / Android)
Container & Kubernetes security
Infrastructure-as-Code security
Security certifications:
CEH, GWAPT, OSCP, CSSLP

About the Company

Galent is an AI-native digital engineering firm at the forefront of the AI revolution, dedicated to delivering unified, enterprise-ready AI solutions that transform businesses and industries. Our mission is to empower organizations to thrive in an ever-evolving digital landscape through cutting-edge AI-native services, consulting, and digital engineering. As enterprises face the complexities of integrating advanced technologies, Galent provides scalable, AI-enabled solutions that optimize processes, enhance productivity, an... Know more