Talent.com
Marsh
Senior Specialist - IT Security (Dev Sec Ops)Marsh • Toronto, ON, Canada
Les candidatures ne sont plus acceptées
Senior Specialist - IT Security (Dev Sec Ops)

Senior Specialist - IT Security (Dev Sec Ops)

Marsh • Toronto, ON, Canada
Il y a 26 jours
Salaire
126 000,00 $CA par an
Type de contrat
  • Temps plein
Description de poste

DevSecOps & Secure-SDLC Engineer

Lead initiatives related to DevSecOps and Secure-SDLC.

Enhance the company’s Secure Software development Liability (Secure-Business) (Secure-Business) which in turn will reflect the company’s Application Development Security Policy,

Select and standardize application security tools. This includes vendor/tool assessments and full POC,

Integrate Secure-SDLC requirements and other security policy/requirements into the DevSecOps processes,

Define and enhance application security requirements and standards which must be designed for agile development methods leveraging traditional application architectures as well as cloud architectures and container workloads.

What can you expect?

  • Lead initiatives related to DevSecOps and Secure-SDLC.
  • Enhance the company’s Secure Software development Lifecycle (Secure-SDLC) which in turn will reflect the company’s Application Development Security Policy,
  • Select and standardize application security tools. This includes vendor/tool assessments and full POC,
  • Integrate Secure-SDLC requirements and other security policy/requirements into the DevSecOps processes,
  • Define and enhance application security requirements and standards which must be designed for agile development methods leveraging traditional application architectures as well as cloud architectures and container workloads.

We will count on you to:

  • Advise the application security leadership on best practices and standards around application security tools with main focus on shift-left, create predictable CI/CD pipeline processes, and enable application teams to develop new capabilities securely, and free from security defects, by design
  • Assess security tools and related processes currently used within the various Software Development Life Cycle processes to identify improvements opportunities, and rationalize the tools set
  • Select new application security tools including vendor/tool assessments and conduct full POC to prove that the security solutions/products are fit-for-purpose and fit-for-use
  • Draft documentations for the Secure-SDLC and DevSecOps to illustrate the frameworks and its process guidelines to internal customers ensuring the style is palatable and easy to navigate
  • Assess impact of new publications from the security industry (e.g. NIST 800-XXX, ISO 2700X:2022, etc) on the company’s AppSec programs
  • Research new trends and advise the application security leaderships on impact of the new trends as they relate to currently used tools, tool chain roadmap, efficiency and effectiveness of current processes, etc.
  • Promote secure coding standard and all related processes
  • Promote the priorities set forth by Global Information Security function, and the roadmap set forth by the Global Application Security
  • Automate and integrate security scan and analysis tools into the DevSecOps pipeline

What you need to have:

  • 5 years+ DevSecOps and Secure-SDLC work experience
  • CISSP, CSSLP, cloud security, DevSecOps automation, or similar is required
  • Post‑secondary education or equivalent experience as a DevSecOps Engineer
  • Develop/enhance and implement the Secure‑SDLC framework
  • Design, implement, and rollout DevSecOps automations and tool chain
  • Implement sensors to collect data on key metrics for statistics and reporting
  • Serve as the subject matter expert in Secure‑SDLC and DevSecOps
  • Advise on the processes and standards that are designed to implement a company’s Application Development Security Policy
  • Experience in designing Secure‑SDLC processes and relevant tooling to support the processes
  • Experience in software/application analysis tools like SAST, DAST, SCA, threat modeling, supply‑chain etc.
  • Technical hands‑on experience in automating and integrating security scan and analysis tools into the DevSecOps pipeline.
  • Experience in one or more programming languages
  • Familiarity with security frameworks (OWASP Top 10, SANS Top 25, CWE)

What makes you stand out:

  • Identify application security requirements and brainstorm solutions factoring in industry best practices
  • Assess the tooling and remediation of threats and vulnerabilities within our software/applications, and the hosting environment

Marsh (NYSE: MRSH) is a global leader in risk, reinsurance and capital, people and investments, and management consulting, advising clients in 130 countries. With annual revenue of over $27 billion and more than 95,000 colleagues, Marsh helps build the confidence to thrive through the power of perspective. For more information, visit corporate.marsh.com, or follow us on LinkedIn and X.

Marsh is committed to embracing a diverse, inclusive and flexible work environment. We aim to attract and retain the best people and embrace diversity of age background, disability, ethnic origin, family duties, gender orientation or expression, marital status, nationality, parental status, personal or social status, political affiliation, race, religion and beliefs, sex/gender, sexual orientation or expression, skin color, or any other characteristic protected by applicable law. In accordance with the Accessibility for Ontarians with Disabilities Act, 2005, Marsh will provide a reasonable accommodation to employees and prospective employees to the point of undue hardship upon request and as required in respect of the individual’s particular restrictions and limitations. If you require a specific accommodation because of a disability or medical need, please contact reasonableaccommodations@marsh.com.

Marsh is committed to hybrid work, which includes the flexibility of working remotely and the collaboration, connections and professional development benefits of working together in the office. All Marsh colleagues are expected to be in their local office or working onsite with clients at least three days per week. Office‑based teams will identify at least one “anchor day” per week on which their full team will be together in person.

The applicable base salary range for this role is $126,000 to $176,000.

The base pay offered will be determined on factors such as experience, skills, training, location, certifications, education, and any applicable minimum wage requirements. Decisions will be determined on a case‑by‑case basis. In addition to the base salary, this position may be eligible for performance‑based incentives.

We are excited to offer a competitive total rewards package which includes health and welfare benefits, tuition assistance, retirement programs as well as employee assistance programs.

This is a New position.

#J-18808-Ljbffr
Créer une alerte emploi pour cette recherche

Senior Specialist - IT Security (Dev Sec Ops) • Toronto, ON, Canada

Offres similaires

AWS IT Security Specialist (Intermediate)

InbentaToronto
Temps plein

AWS IT Security Specialist (Intermediate).Intermediate AWS IT Security Specialist.The successful candidate will collaborate with DevOps, Infrastructure, and Application teams to secure cloud-native... Voir plus

 • Offre sponsorisée

Senior Information Security Architect Role

ColliersToronto
Temps plein

Shape the future of cybersecurity at Colliers as a Senior Information Security Architect.This remote role offers the chance to lead strategic security initiatives for global operations.You'll be at... Voir plus

 • Offre sponsorisée

IT Infrastructure & Security Specialist

Frontier Dental CAMarkham
Temps plein

IT Infrastructure & Security Specialist.The ideal candidate has strong experience managing.Microsoft 365, Azure, AWS infrastructure, networking, and enterprise systems.IT operations in a fast-growi... Voir plus

 • Offre sponsorisée

Senior Security Analyst

MindlanceToronto, ON, CA
Temps plein

Global Cyber Security team, providing deep technical expertise and advisory support across endpoint and threat surface security platforms.This role focuses on maintaining and strengthening enterpri... Voir plus

 • Offre sponsorisée

It Director: Lead Transformation, Security & Ops - $130,000 - $150,000 A Year

ConfidentialAurora, Canada
Temps plein

A technology-driven organization in Aurora is seeking a Director of IT who will manage the organization’s IT infrastructure, enterprise systems, and service management.The successful candidate will... Voir plus

 • Offre sponsorisée

Senior IT Manager - Threat and Vulnerability

Tree Top Staffing LLCToronto, Ontario, Canada
Temps plein

Senior IT Manager - Threat and Vulnerability.The Senior Manager of the Vulnerability and Attack Surface Management Team is a critical technical leadership role within our Information Security team ... Voir plus

 • Offre sponsorisée

Security Specialist - Senior_10+yrs

Maarut IncToronto
Temps plein

The Cyber Security Centre of Excellence (COE) is seeking one (1) Senior Cyber Security Specialist to support in strengthening Ontario’s cyber security infrastructure as the province collectively mo... Voir plus

 • Offre sponsorisée

Senior It Director, Strategy, Security & Ops - $120,000 - $160,000 A Year

Educational InstitutionToronto, Canada
Temps plein

IT Director role focused on aligning IT strategy, security, and operations with educational goals, requiring strong leadership and project management. Voir plus

 • Offre sponsorisée

Senior Information Security Specialist - C$96,900 - C$136,800 Par An

Institution FinancièreToronto, Canada
Temps plein

Institution financière recherche un Spécialiste en Sécurité de l'information pour offrir des conseils sur les programmes de sécurité et gérer les évaluations de risques à Toronto. Voir plus

 • Offre sponsorisée

Senior IT Security Analyst at ERCO Worldwide

ERCO WorldwideToronto, ON, CA
Temps plein

Take the next step in your career as a Senior IT Security Analyst with ERCO Worldwide in a hybrid work environment in Mississauga.Play a key role in safeguarding our digital assets and infrastructu... Voir plus

 • Offre sponsorisée

Hands-On Senior IT Security Administrator

Confluencetoronto, on, Canada
Temps plein

Join as a Hands-On Senior IT Security Administrator and make a measurable impact on security practices.Your role focuses on vulnerability management and operational resilience across enterprise sys... Voir plus

 • Offre sponsorisée

Senior Associate, IT, Security Operations - Purview SME

MUFG Investor ServicesToronto, ON, CA
Temps plein

MUFG Investor Services is a trusted partner to many of the world’s largest public and private funds, providing asset servicing and operational solutions built for alternatives.With over $1 trillion... Voir plus

 • Offre sponsorisée

Senior Security Architect – Enterprise Security & DevSecOps

VancityToronto, ON, CA
Temps plein

A member-owned credit union is seeking a Senior Security Architect to design and implement secure technology solutions.This role includes mentoring junior architects, leading security assessments, ... Voir plus

 • Offre sponsorisée

Senior Associate, Information Security

Publicis Groupe Holdings B.VToronto, ON, CA
Temps plein

The Senior Associate, Information Security is part of a global team and is responsible for incident response of cyber security incidents that are associated with our businesses, clients, and vendor... Voir plus

 • Offre sponsorisée

Senior Information Security Specialist - C$96,900 - C$136,800 Par An

TD BankToronto County, Canada
Temps plein

Le candidat conseillera sur les programmes de sécurité et gérera l'évaluation des risques. Voir plus

 • Offre sponsorisée

IT Security Specialist - Cloud, WAF & SOC Expert

IBMToronto
Temps plein

A leading technology company in Toronto is seeking an experienced IT Security Specialist.You will protect clients from cyber threats using industry-leading security tools and participate in various... Voir plus

 • Offre sponsorisée

Senior Security Operations Specialist - C$140,000 - C$154,000 A Year

RelayToronto, Canada
Temps plein

Senior Security Operations Specialist to join a digital banking platform.Responsibilities include monitoring, investigating, and containing security threats in real-time, building detection logic, ... Voir plus

 • Offre sponsorisée

SENIOR SPECIALIST Cyber Architecture

City of TorontoToronto, ON, CA
Temps plein

SENIOR SPECIALIST Cyber Architecture.Consider Your Role with Aliant Resources and Our Municipal Government Client The City of Toronto.Aliant Resources is a dedicated provider of IT staffing service... Voir plus

 • Offre sponsorisée

Senior IT and security Administrator – Malware Protection Specialist

act digitalToronto, ON, CA
Temps plein

Senior IT and security Administrator – Malware Protection Specialist.ALTER SOLUTIONS is a consulting and technology expertise company founded in 2006.Our mission is to support our clients with thei... Voir plus

 • Offre sponsorisée

Senior Specialist in Cyber Security Strategies

Rubicon PathToronto, Ontario, Canada
Temps plein

Enhance Ontario's cyber security infrastructure as a Senior Cyber Security Specialist.Leverage your expertise to implement security architectural best practices and expand cyber safety education in... Voir plus