Pentester, Offensive Forward Deployment Engineer - Montreal

Mistral AI

Montréal, CAonsitePosted Jul 27, 2026
Posting intelligenceActively listed

Skills

azurecicdgooglecloudawsml

About the role

Location

Montréal

Employment Type

Full time

Department

Solutions

About Mistral

Mistral provides full-stack AI solutions: from frontier models to developer tools, applications, and compute. We partner with enterprises tackling the hardest problems - across high-stakes industries like finance, manufacturing, defense, healthcare, and the public sector - co-creating customized AI systems that they can run on their terms.

We are a dynamic, collaborative team passionate about AI and its potential to transform society. Our diverse workforce thrives in competitive environments and is committed to driving innovation. Our teams are distributed between Europe, North America, Asia and the Middle East. We are creative, low-ego and team-spirited.

Role summary

We are seeking hands-on Pentesters to join our Offensive Security team. You will be running our maturing offensive solution on real clients engagements while also hunting for vulnerabilities in Mistral's own systems and in the wild. This is a unique opportunity to break real client systems, discover 0-days for fun, and help build the AI that automates offensive security at scale.

Your work will directly impact both our clients' security posture and Mistral's own defensive capabilities. You'll be at the forefront of our offensive security practice, with the chance to shape how AI transforms penetration testing. We welcome offensive security experts at all levels who are passionate about breaking systems and building the tools that make security testing more effective.

What you will do

Client Engagements

Run our offensive security solution on real client engagements: scoping, executing tooling, and delivering results

Triaging output and killing false positives to ensure high-quality, actionable findings for clients

Advise clients through deployment and remediation, acting as a trusted security partner

Travel to client premises and switch between engagements in a classic pentest consulting cadence

Internal Dogfooding

Pentest Mistral's own systems, finding vulnerabilities before our offensive solution matures

Hunt for vulnerabilities internally and on open-source/in-the-wild targets between client engagements

Transfer knowledge and findings to the forming internal security team

Act as Mistral's own first customer for our cyber harnesses

Guiding the Harness

Use real offensive expertise to steer the cyber harness: identify vulnerabilities it should catch

Validate and triage the harness's output, ensuring it meets the high standards of human pentesters

Benchmark human vs. agent performance, helping to close the gap between automated and manual testing

Contribute to the development of AI-powered offensive security capabilities

About you

Current P0 specialty: web / AppSec + source-code review; also high-value: internal / Active Directory, cloud (AWS/GCP/Azure), CI/CD & supply chain

Senior enough to run an engagement solo from scoping to delivery

Uses AI in your workflow with a nuanced view of its capabilities and limitations

Comfortable being client-facing, mobile, and switching between different engagements

Proven track record of delivering high-quality penetration testing results

Strong problem-solving abilities and attention to detail in vulnerability identification

It would be ideal if you also have:

Build your own offensive tooling (builder mindset that scales your impact)

Published CVEs / GHSAs or a strong bug-bounty track record

Conference talks, CTF achievements, or other public recognition in the security community

Strong code review skills for multiple programming languages

Experience with AI/ML systems and their unique security challenges

Contributions to open-source security tools or research

What We Offer

We offer a comprehensive benefits package designed to support your well-being, growth, and work-life balance. Benefits vary by country and may include healthcare coverage, parental leave, retirement plans, relocation support, wellness programs, meal and transportation allowances, and other location-specific perks.

For the most up-to-date details on benefits available in your location, please refer to our Benefits page.

Questions about this role

Click "Apply with AI Applyd" above and you are done. Your resume is rewritten for this advert, the screening questions are answered, and it is submitted on Mistral AI's own hiring system. No retyping your history, no fourteen tabs, no evening lost.

Compensation for Penetration Tester roles in Canada varies widely by seniority, employer size, and remote vs onsite arrangement. Check the salary range on this listing when published, or browse our Penetration Tester hub for Canada medians across recent openings.

You never touch the form - the application is filled and submitted for you on Mistral AI's own hiring system. It is not marked sent when we press submit. It is marked sent when a confirmation from their system arrives at the address we apply with, and your dashboard shows which stage each application is at until then.

Twelve applicant tracking systems have a real apply path: Workday, Greenhouse, Lever, Ashby, Workable, iCIMS, Personio, Recruitee, Teamtailor, Rippling, Breezy and SmartRecruiters. Your application goes in on the employer's own hiring system, never into an aggregator queue.

Want AI Applyd to auto-apply to roles like this?

We tailor your resume per posting, fill the forms, and track replies for you.