Talent.com
Astra North Infoteck Inc.
Application Security Engineer (SME) DevSecOps, Pen TestingAstra North Infoteck Inc. • Toronto, Ontario, Canada
Application Security Engineer (SME) DevSecOps, Pen Testing

Application Security Engineer (SME) DevSecOps, Pen Testing

Astra North Infoteck Inc. • Toronto, Ontario, Canada
Il y a plus de 30 jours
Salaire
10,00 $CA par heure
Type de contrat
  • Temps plein
Description de poste
Role Description

We are seeking an experienced Senior Application Security SME/ DevSecOps Security Consultant to lead and mature application security practices across enterprise platforms and development teams. The ideal candidate will have deep expertise in modern application architectures secure coding practices security testing methodologies and the ability to partner effectively with development engineering DevOps and risk teams to embed security throughout the software delivery lifecycle.

Primary Skills
  • Application Security
  • Secure SDLC (SSDLC)
  • DevSecOps
  • Threat Modeling
  • Cloud Security (Azure AWS GCP)
  • Security Architecture
  • Vulnerability Management
  • SAST / DAST / SCA
  • OWASP Top 10
  • API Security
Key Responsibilities

Application Security Strategy & Advisory

  • Act as the Subject Matter Expert (SME) for application security across enterprise platforms and development teams.
  • Define and enhance the organizations application security strategy standards and control frameworks.
  • Provide expert guidance on secure design secure coding threat mitigation and vulnerability management.
  • Partner with engineering and architecture teams to embed security-by-design principles into applications and digital initiatives.

Secure SDLC / DevSecOps Enablement

  • Drive implementation and maturity of the Secure Software Development Lifecycle (SSDLC).
  • Integrate security controls and testing into CI/CD pipelines and DevSecOps workflows.
  • Enable use of security tools and automation across build and release processes.
  • Promote a shift-left security approach to detect and remediate issues early in the development lifecycle.

Architecture Reviews & Threat Modeling

  • Perform application architecture and design reviews to identify security risks and recommend remediation strategies.
  • Lead threat modeling sessions for web mobile API and cloud-native applications.
  • Review application components for vulnerabilities related to authentication authorization session management input validation data protection and API security.
  • Recommend secure reference architectures reusable security patterns and implementation guardrails.

Security Testing & Vulnerability Management

  • Lead or support application security assessments including:
    • Static Application Security Testing (SAST)
    • Dynamic Application Security Testing (DAST)
    • Software Composition Analysis (SCA)
    • API Security Testing
    • Manual Security Reviews and Penetration Testing Coordination
  • Analyze triage and prioritize vulnerabilities based on risk and business impact.
  • Work closely with development teams to track remediation and validate closure of security issues.
  • Support secure management of open-source components and third-party libraries.

Cloud & Modern Application Security

  • Provide security guidance for modern application environments including:
    • Microservices and APIs
    • Containers and Kubernetes
    • Cloud-Native Applications
    • Serverless and Event-Driven Architectures
  • Collaborate with cloud and platform engineering teams to secure application workloads in Azure AWS or GCP.

Compliance Governance & Risk

  • Ensure application security practices align with internal security policies and external standards and regulations.
  • Support compliance requirements related to secure development and application security controls.
  • Contribute to audit responses control evidence collection and security risk assessments.
  • Develop security metrics dashboards and reporting to track application security posture and control effectiveness.
Required Qualifications
  • Bachelors degree in Computer Science Information Security Engineering or related field.
  • 8 years of experience in Application Security Secure Software Engineering Cybersecurity Architecture or related roles.
  • Proven experience implementing and managing application security programs in enterprise environments.

Strong Understanding Of

  • Secure SDLC / SSDLC
  • DevSecOps Principles
  • OWASP Top 10
  • API Security Top 10
  • Common Software and Web Application Vulnerabilities

Hands-On Experience With Application Security Testing Tools

SAST

  • Checkmarx
  • Fortify
  • Veracode
  • SonarQube

DAST

  • Burp Suite
  • AppScan
  • Acunetix

SCA

  • Snyk
  • Black Duck
  • Mend / WhiteSource

Additional Requirements

  • Experience in Threat Modeling methodologies (e.g. STRIDE).
  • Strong knowledge of Authentication Authorization Encryption Secrets Management and Secure Design Principles.
  • Experience working with Cloud Platforms such as Azure AWS or GCP.
  • Strong verbal and written communication skills with the ability to work across technical and non-technical stakeholders.
Preferred Qualifications
  • Experience in highly regulated industries such as:
    • Banking
    • Financial Services
    • Insurance (BFSI)
    • Healthcare
    • Public Sector

Familiarity With

  • NIST
  • ISO 27001
  • PCI-DSS
  • SOC 2
  • OSFI Guidelines (Canada)

CI/CD Platforms

  • Azure DevOps
  • Jenkins
  • GitHub Actions
  • GitLab

Additional Exposure

  • Container Security
  • Kubernetes Security
  • Cloud Workload Protection
  • Red Team / Blue Team Collaboration
  • Application-Layer Attack Simulation
  • Security Incident Response Readiness
Preferred Certifications
  • CISSP
  • CSSLP
  • CISM
  • CEH
  • GWAPT
  • OSCP
  • Azure Security Certifications
  • AWS Security Certifications
  • GCP Security Certifications



Required Skills:

60-70


Required Education:

Job Overview:Were seeking an experienced ETL Pipeline Developer proficient in Python to design implement and maintain robust data pipelines. This role is critical for transforming raw data into valuable business insights across our Responsibilities: Architect and build efficient ETL pipelines in Python to process diverse data sources Implement data transformation logic using pandas for complex manipulations and aggregations Document pipeline architecture data flows


Employment Type : Full Time
Experience: years
Vacancy: 1
Monthly Salary Salary: 10 - 10
Créer une alerte emploi pour cette recherche

Application Security Engineer (SME) DevSecOps, Pen Testing • Toronto, Ontario, Canada

Offres similaires

Lead Application Security Engineer at Opendoor

Segment (Twilio)Toronto, ON, CA
Temps plein

Step into a leadership position as a Lead Application Security Engineer at Opendoor, where you'll shape the future of secure software development.Automate security processes while mentoring enginee... Voir plus

 • Offre sponsorisée

Opendoor Enterprise Security Engineer Role

OpendoorToronto, ON, CA
Temps plein

Be part of Opendoor’s mission as an Enterprise Security Engineer.This hands-on role is focused on identity systems and enhancing endpoint security through automation.In your role at Opendoor, you w... Voir plus

 • Offre sponsorisée

Remote Security & DevOps Engineer for SaaS/IoT Cloud

KeycafeToronto, ON, CA
Télétravail
Temps plein

A leading technology firm in Canada is seeking a passionate Security & DevOps Engineer to enhance its cloud environments and ensure high security across its global IoT platform.You'll manage applic... Voir plus

 • Offre sponsorisée

Movable Ink Product Security Engineering Role

Movable InkToronto, ON, CA
Temps plein

Join Movable Ink as a Product Security Engineer, focusing on securing codebases and fostering safe development practices.Your expertise will directly impact our software delivery and security strat... Voir plus

 • Offre sponsorisée

Cloud Security Engineer – DevSecOps & AWS Expertise

AquanowToronto
Temps plein

A leading infrastructure provider is seeking a Cloud Security Engineer to join the technology team in Toronto.The role involves performing security assessments, managing security tools in CI/CD pip... Voir plus

 • Offre sponsorisée

Security Software Engineer

TailscaleToronto, ON, CA
Temps plein

Tailscale is building the new Internet by delivering software that makes it easy to securely interconnect people and their devices, no matter where they are.From hobbyists to multinational corporat... Voir plus

 • Offre sponsorisée

Security Engineer I (Application Security Engineer) - C$41.6 - C$52.4 An Hour

WorkSafeBCToronto, Canada
Temps plein

Want to use your expertise to connect to an IT career with a difference? Join our team as a Security Engineer I and help shape the future of secure applications that protect millions of British Col... Voir plus

 • Offre sponsorisée

IT Application Security Manager

Randstad DigitalToronto
Temps plein

Candidates MUST be located in Toronto, ON / GTA --- This is a HYBRID Role --- 3 days a week work from office.Seniority Level - 10+ Years (Senior).People Management Experience is a MUST.App Sec tech... Voir plus

 • Offre sponsorisée

Senior Application Security Engineer

CognizantToronto, ON, CA
Temps plein

Job Title - App Security Specialist.DevOps, with at least 2 - 3 years hands-on security exposure (secure coding, pipeline security, API security, threat modeling).Seniority level: Mid-Senior level.... Voir plus

 • Offre sponsorisée

Penetration Testing & Application Security Consultant

Rsm Us Llp.Toronto
Temps plein

A leading professional services firm in Toronto is seeking a Security Analyst with expertise in web security.The role involves performing security assessments, conducting penetration testing, and c... Voir plus

 • Offre sponsorisée

Senior Enterprise Security Engineer

Thumbtacktoronto, on, Canada
Temps plein

Thumbtack helps millions of people confidently care for their homes.Thumbtack is the one app you need to take care of and improve your home — from personalized guidance to AI tools and a best‑in‑cl... Voir plus

 • Offre sponsorisée

Penetration Testing Engineer - Web and Cloud Security

RSM CanadaToronto, ON, CA
Temps plein

A leading professional services firm is seeking a talented individual for security assessments, involving penetration testing and collaboration with clients across various technology stacks.Candida... Voir plus

 • Offre sponsorisée

Security Engineer: Build Threat-Detecting Cloud Tools

RenderToronto, ON, CA
Temps plein

A leading cloud platform company is seeking a talented individual for a full-stack security role.In this position, you will own the security lifecycle, implement monitoring systems, and directly im... Voir plus

 • Offre sponsorisée

Palo Alto Security SME - Implementation

Tech Talent Internationaltoronto, on, Canada
Temps plein

About the job Palo Alto Security SME - Implementation.Fortune 100/500/1000 and other companies in Canada/US.We are currently hiring for a Palo Alto Security SME - Implementation for our IT infrastr... Voir plus

 • Offre sponsorisée

Senior Application Security Engineer

HelloFreshToronto, ON, CA
Temps plein

We're looking for a new teammate to join us on the journey of keeping HelloFresh a trusted name - someone with a passion for security and appetite for new challenges.Security Engineers work in a va... Voir plus

 • Offre sponsorisée

Senior DevSecOps Security Engineer

Compunnel, Inc.Toronto
Temps plein

A tech company in Toronto, Canada is looking for an experienced Security Engineer to enhance application and cloud security.The role requires strong development skills and expertise in modern appli... Voir plus

 • Offre sponsorisée

Cohere's Security Engineer Opportunity

Coheretoronto, on, Canada
Temps plein

Advance your career as Cohere's Senior Security Engineer, focusing on securing AI platforms through vulnerability management and agile practices.Collaborate across teams and drive security initiati... Voir plus

 • Offre sponsorisée

IAM-Focused Security Engineer Role

SentryToronto, ON, CA
Temps plein

Take your security career to the next level as an IAM-focused Security Engineer at Sentry.Lead projects that secure Sentry’s identity management and access practices.Become a vital member of Sentry... Voir plus

 • Offre sponsorisée

Senior Security Engineer Focused on Detection and Response Frameworks

1PasswordToronto, ON, CA
Temps plein

Join as a Senior Security Engineer to strengthen detection and incident response frameworks.Lead initiatives that optimize security measures and enhance organizational resilience in a remote enviro... Voir plus

 • Offre sponsorisée

Senior Cloud Security Engineer, Information Security

Peoples GroupToronto
Temps plein

We are hiring for this position out of our Toronto, Vancouver and Calgary offices.Successful candidates who apply outside of these areas will be expected to relocate and reside in a location that i... Voir plus