Talent.com
Application Security Analyst, Information Security
Application Security Analyst, Information SecurityFirst National • Toronto, ON, Canada
Application Security Analyst, Information Security

Application Security Analyst, Information Security

First National • Toronto, ON, Canada
30+ days ago
Job type
  • Full-time
Job description

We are hiring an Application Security Analyst, Information Security!

The Role :

We're seeking an Application Security Analyst well-versed in risk analysis, vulnerability assessment methodologies, and information security concepts. Your role involves supporting security risk assessments for both internally developed and third-party / open-source software, setting up security processes, and educating various application teams within the organization. You'll be integral in documenting and developing security controls while ensuring compliance with established frameworks.

Reporting To :

Application Security Manager

Full-Time / Part- Time :

Full-time

Posting Date : March 5, 2024

Closing Date : April 5, 2024

Hours of Work : 8 : 30 – 5 : 00

Grade : Office Location :

Toronto, ON

Great location! Steps away from the main public transit station

What we offer :

Highly competitive compensation package which includes, base salary, bonus, benefits, and career advancement opportunities!

  • Eligibility for benefits is dependent on the terms of employment

What you will do :

  • Analyzing and documenting processes, policies, controls, and standards to comply with security frameworks and regulations.
  • Understand technical and architectural issues from a security perspective and provide recommendations.
  • Performing security reviews and provide insights throughout all phases of software development.
  • Support the Application Security Manager in managing internal and external stakeholders related to Application Security.
  • Managing and coordinating secure code reviews with stakeholders, encompassing Dynamic Application Security Testing (DAST) and Static Application Security Testing (SAST).
  • Conducting application vulnerability assessments for web, mobile, webservices and cloud applications
  • Performing or overseeing manual / automated application Vulnerability Assessment & Penetration Testing, and subsequently managing technical documentation including VAPT / Application Security tracking and reporting
  • Reviewing the configurations to Web Application Firewalls (WAF)
  • Work closely with the application development delivery teams to integrate security controls within the development pipeline ensuring an efficient development process with early security control gates.
  • Assisting the Security Leadership in collaborating with IT Groups to define, develop, communicate, and implement a comprehensive long-term application security roadmap. This involves creating threat models for web applications and supporting development teams across the agile Software Development Life Cycle (SDLC).
  • Assisting in the evaluation, selection, onboarding, and management of AppSec vendors and Solutions
  • The Requirements Needed :

  • Strong grasp of application design and architecture
  • Proficiency in manual and automated penetration testing methods / tools (, Burp Suite, Fortify, Backtrack Kali, Metasploit Framework)
  • Knowledge of programming languages (.Net, C#, JavaScript, etc.), cloud platforms (, Azure), and database technologies in the security domain
  • Familiarity with WAF technologies, security frameworks (OWASP-TOP 10, SANs-TOP 25, CWE), and participation in Bug Bounties & Capture the Flag (CTF) would be beneficial.
  • Transferable Skills :

  • Excellent verbal communication
  • Excellent written skills for preparing reports and briefings.
  • Excellent analytical reasoning
  • Problem-solving approach
  • Education :

  • Post-secondary education, University education and Technical Certifications required.
  • Certifications and Skills :
  • Preference will be given to candidates to have CISSP.
  • Good to have Offensive Security Certified Professional (OSCP)
  • The team you will join :

    Founded in 1988, First National is one of Canada’s largest non-bank lenders. We provide residential mortgages exclusively through our mortgage broker channel and service commercial clients through our national origination team of empowered advisors.

    At First National, It’s in our Nature is our rallying cry. It underlies our values, beliefs, and how we show up for each other, our clients, our partners and the community. Our nature defines who we are and guides every decision we make.

    First National is proud to be an equal opportunity employer and is committed to diversity and inclusion regardless of race, color, religion, national origin, age, gender identity, physical or mental disability, sexual orientation or any other category protected by law.

    First National supports requests for accommodation from applicants with disabilities; please contact Human Resources at .

    We would like to thank all applications for their interest, but only candidates selected for an interview will be contacted.

    #FNLOON

    Create a job alert for this search

    Information Security Analyst • Toronto, ON, Canada

    Similar jobs
    Manager, Oracle Application Security

    Manager, Oracle Application Security

    Deloitte Canada • Toronto, Canada
    Permanent
    Press Tab to Move to Skip to Content Link Select how often (in days) to receive an alert : Manager, Oracle Application Security. Toronto, ON, CA, M5C 3G7 Job Type : Permanent Work Model : Hybrid Refere...Show more
    Last updated: 30+ days ago • Promoted
    Security Analyst - 1 Year Contract

    Security Analyst - 1 Year Contract

    Toronto Parking Authority • Toronto, ON, CA
    Full-time
    Quick Apply
    POSITION SUMMARY The Security Information Analyst will assist the Toronto Parking Authority with the design, development and implementation of its security awareness plan and security initia...Show more
    Last updated: 30+ days ago
    Security Architect, ISO

    Security Architect, ISO

    Data Theorem • Toronto, ON, CA
    Full-time
    Quick Apply
    Overview : Data Theorem is an exciting company focused on creating a more secure world for data.Rooted in a strong engineer first culture, every employee has an impact on product and directio...Show more
    Last updated: 30+ days ago
    Investment Analyst - Project

    Investment Analyst - Project

    Vaco by Highspring • Richmond Hill, Ontario, Canada
    Temporary
    Investment Analyst – 6 Month Contract.Supports investment finance team with month-end close process.Lead various reconciliation process. Analyzes and provides performance return information (e.Work ...Show more
    Last updated: 5 days ago • Promoted
    Security Analyst

    Security Analyst

    Hire DigITalent • Aurora, ON, Canada
    Full-time
    Security Monitoring & Incident Response.Partner closely with a managed security service / SOC provider to oversee threat monitoring, investigations, incident response activities, and security rep...Show more
    Last updated: 11 days ago • Promoted
    Principal Engineer - Information Security

    Principal Engineer - Information Security

    Tucows Inc. • Toronto, ON, Canada
    Full-time
    Wavelo is a SaaS business on a mission to make telecoms a breeze.We provide flexible software that modernizes how communication service providers (CSPs) do business, helping them drive more value, ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Data Security Architect – Azure, Governance & Banking

    Senior Data Security Architect – Azure, Governance & Banking

    Equitable Group • Toronto C6A, ON, Canada
    Remote
    Full-time
    A leading Canadian financial institution is seeking a Senior Data Security Consultant to design and implement robust data protection strategies across its digital ecosystem.The ideal candidate has ...Show more
    Last updated: 7 days ago • Promoted
    Senior Manager, Digital Asset Business - Risk Consulting

    Senior Manager, Digital Asset Business - Risk Consulting

    KPMG in the Cayman Islands • Greater Toronto Area, Canada
    Full-time
    Please note : this is an on-site role and can be based in The Cayman Islands, Bermuda, The Bahamas or the Crown Dependencies and relocation is required. At KPMG our goal is to be the Clear Choice for...Show more
    Last updated: 1 day ago • Promoted
    Security Analyst – Prisma Cloud & Palo Alto

    Security Analyst – Prisma Cloud & Palo Alto

    Bell • Toronto C6A, ON, Canada
    Remote
    Full-time
    A leading telecommunications company in Toronto is seeking a Systems Security Analyst to join their Managed Security Operations team. In this role, you will work with security technologies like Palo...Show more
    Last updated: 2 days ago • Promoted
    Director, Security Architecture & Engineering, Information & Corporate Security

    Director, Security Architecture & Engineering, Information & Corporate Security

    CPP Investments | Investissements RPC • Toronto, Canada
    Full-time
    Make an impact at a global and dynamic investment organization.When you join CPP Investments, you are joining one of the world’s most admired and respected institutional investors.As a professional...Show more
    Last updated: 6 hours ago • Promoted • New!
    Principal Engineer - Information Security

    Principal Engineer - Information Security

    Tucows • Toronto, ON, Canada
    Full-time
    Wavelo is a SaaS business on a mission to make telecoms a breeze.We provide flexible software that modernizes how communication service providers (CSPs) do business, helping them drive more value, ...Show more
    Last updated: 30+ days ago • Promoted
    DW_Account Executive - Integrated Security Solutions

    DW_Account Executive - Integrated Security Solutions

    Just Sales Jobs • Markham, ON, Canada
    Full-time
    As an Account Executive, you will be providing Security Solutions to Property Management Companies and Real Estate Developers across the Greater Toronto and surrounding areas.This role focuses main...Show more
    Last updated: 28 days ago • Promoted
    Senior Security Solutions Architect (Canada) – MDR & Cloud

    Senior Security Solutions Architect (Canada) – MDR & Cloud

    Cyderes co • Toronto, ON, Canada
    Full-time
    A cybersecurity services firm in Toronto is seeking a Senior Solutions Architect.This role involves leading technical sessions, designing security solutions tailored to client needs, and collaborat...Show more
    Last updated: 8 days ago • Promoted
    Threat Hunting & Detection Content Analyst

    Threat Hunting & Detection Content Analyst

    CGI • Toronto, ON, Canada
    Full-time
    Threat Hunting & Detection Content Analyst.The Global Security Operations Center (GSOC) Threat Hunting & Detection Content Engineering Analyst contribute to strengthening our security posture on mu...Show more
    Last updated: 5 hours ago • Promoted • New!
    Information Technology Private Tutoring Jobs Aurora

    Information Technology Private Tutoring Jobs Aurora

    Superprof • Aurora, Canada
    Full-time +1
    Superprof is Canada's #1 tutoring platform, and we're actively recruiting passionate tutors! Whether you're a student, a professional, or simply someone who loves teaching, join the largest communi...Show more
    Last updated: 30+ days ago • Promoted
    Application Support Analyst

    Application Support Analyst

    Bay Street Staffing • Greater Toronto Area, Canada
    Full-time
    You’ll be joining BANK’s Application Operations team.You will be responsible for providing analysis and second level support on client issues, technical issues, system / web site outages and question...Show more
    Last updated: 2 days ago • Promoted
    Business Analyst

    Business Analyst

    Enercare Inc. • Markham, ON, Canada
    Full-time
    Canada’s largest home and commercial services companies servicing over one million customers across Ontario, Manitoba, Saskatchewan, Alberta, British Columbia, Quebec and New Brunswick.Enercare is ...Show more
    Last updated: 8 days ago • Promoted
    Application Security and identity / Infrastructure Security Engineer (Kubernetes clusters)

    Application Security and identity / Infrastructure Security Engineer (Kubernetes clusters)

    freelance.ca • Toronto, Canada
    Full-time
    Application Security and identity Engineer / Infrastructure security engineer (Kubernetes clusters).Work Location : hybrid, downtown Toronto, ON. Contract Term : 6 months, highly renewable extended be...Show more
    Last updated: 30+ days ago • Promoted