Offensive Security Specialist

10 Minutes ago • All levels • Cyber Security

Job Summary

Job Description

Ubisoft is seeking an Offensive Security Specialist to join their cybersecurity team, focusing on identifying, assessing, and mitigating security vulnerabilities across IT, corporate systems, games, and online services. The role involves validating CVEs, developing exploit proofs-of-concept, collaborating with the Red Team, and supporting remediation efforts to reduce risk exposure. This position is crucial for strengthening Ubisoft's overall security posture.
Must have:
  • Validate the exploitation of third-party CVEs.
  • Triage and validate first-party vulnerabilities discovered through responsible disclosure programs (e.g., Bug Bounty).
  • Collaborate with the Red Team to build exploit chains and simulate real-world attack scenarios.
  • Retest vulnerabilities identified by internal security teams to confirm remediation effectiveness.
  • Document validated vulnerabilities, and communicate detailed findings and remediation recommendations to internal stakeholders.
  • Remediate vulnerabilities by following up with asset and application owners to ensure timely resolution.
  • Demonstrated track record in penetration testing or offensive security within large-scale, complex infrastructures.
  • Strong knowledge of vulnerability scoring, attack vectors, triage, and assessments.
  • Ability to exploit common flaws such as Web vulnerabilities (XSS, IDOR, CSRF), Server-side issues (SQLi, XXE, SSRF, RCE), Authentication and access control weaknesses.
  • Proven ability to build or adapt CVE exploitation proofs of concept (PoCs).
  • Skilled in vulnerability assessment and penetration testing tools, including vulnerability scanners (Tenable, Qualys) and network analysis utilities (Wireshark, tcpdump, Scapy).
  • Familiarity with OWASP, MITRE ATT&CK, remediation techniques, and system hardening.
Good to have:
  • Proficiency in Reverse engineering & debugging tools (IDA Pro, Ghidra, x64dbg, WinDbg).
  • OSCP certification.
Perks:
  • Hybrid work model.
  • Inclusive and respectful work environment.
  • Accommodation for interview process if needed.

Job Details

COMPANY DESCRIPTION

Ubisoft is a global leader in gaming with teams across the world creating original and memorable gaming experiences, from Assassin’s Creed, Rainbow Six to Just Dance and more. We believe diverse perspectives help both players and teams thrive. If you’re passionate about innovation and pushing entertainment boundaries, join our journey and help us create the unknown!

JOB DESCRIPTION

Ubisoft is seeking a skilled and motivated Offensive Security Specialist to join our cybersecurity team and strengthen Ubisoft’s ability to identify, assess, and mitigate security vulnerabilities across its diverse environments, ranging from IT and corporate systems to games and online services.

You will contribute to our vulnerability management program by validating CVEs, developing exploit proofs-of-concept, collaborating with our Red Team, and supporting remediation and triage through actionable insights. Your expertise in offensive techniques will play a critical role in reducing risk exposure across the organization.

Responsibilities

  • Validate the exploitation of third-party CVEs identified by vulnerability scanners (e.g., Tenable.io).
  • Triage and validate first-party vulnerabilities discovered through responsible disclosure programs (e.g., Bug Bounty).
  • Collaborate with the Red Team to build exploit chains and simulate real-world attack scenarios.
  • Retest vulnerabilities identified by internal security teams to confirm remediation effectiveness.
  • Contribute to the development and deployment of internal security tools and workflows aligned with industry best practices.
  • Continuously research emerging offensive techniques and integrate findings into testing methodologies and tooling.
  • Document validated vulnerabilities, and communicate detailed findings and remediation recommendations to internal stakeholders.
  • Remediate vulnerabilities by following up with asset and application owners to ensure timely resolution.

QUALIFICATIONS

  • Practical Experience: Demonstrated track record in penetration testing or offensive security within large-scale, complex infrastructures, suited for an intermediate-level professional with a with a strong commitment to keeping skills current in offensive security with certifications such as OSCP.
  • Vulnerability Assessment Expertise: Strong knowledge of vulnerability scoring, attack vectors, triage, and assessments, including the ability to exploit common flaws such as: Web vulnerabilities (XSS, IDOR, CSRF), Server-side issues (SQLi, XXE, SSRF, RCE), Authentication and access control weaknesses
  • Exploit Development: Proven ability to build or adapt CVE exploitation proofs of concept (PoCs) tailored to organizational environments.
  • Tool Proficiency: Skilled in vulnerability assessment and penetration testing tools, including vulnerability scanners (Tenable, Qualys) and network analysis utilities (Wireshark, tcpdump, Scapy); Reverse engineering & debugging tools (IDA Pro, Ghidra, x64dbg, WinDbg) is a plus.
  • Security Frameworks & Practices: Familiarity with OWASP, MITRE ATT&CK, remediation techniques, and system hardening.

ADDITIONAL INFORMATION

We embrace a hybrid work model helping you stay connected with your team and aligned with business priorities, while giving you the opportunity to maintain your work-life balance. Note, that some roles are fully office-based and are not eligible for hybrid work.

Just a heads up: If you require a work permit, your eligibility may depend on your education and years of relevant work experience, as required by the government.

Skills and competencies show up in different forms and can be based on different experiences, that is why we strongly encourage you to apply even though you may not have all the requirements listed above.

At Ubisoft, we embrace diversity in all its forms. We’re committed to fostering an inclusive and respectful work environment for all. We know the importance of providing a pleasant interview experience, therefore if you need any accommodation, please let us know if there is anything we can do to facilitate the interview process.

Similar Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Similar Skill Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Jobs in Montréal, Québec, Canada

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

Cyber Security Jobs

Looks like we're out of matches

Set up an alert and we'll send you similar jobs the moment they appear!

About The Company

Montreal, Quebec, Canada (Hybrid)

Newcastle Upon Tyne, England, United Kingdom (Hybrid)

Bucharest, Bucharest, Romania (Hybrid)

Toronto, Ontario, Canada (Hybrid)

Montreal, Quebec, Canada (Hybrid)

Cary, North Carolina, United States (Hybrid)

Montreal, Quebec, Canada (Hybrid)

Sherbrooke, Quebec, Canada (Hybrid)

Piedmont, Quebec, Canada (On-Site)

View All Jobs

Get notified when new jobs are added by Ubisoft

Level Up Your Career in Game Development!

Transform Your Passion into Profession with Our Comprehensive Courses for Aspiring Game Developers.

Job Common Plug
Contact Us
hello@outscal.com
Made in INDIA 💛💙