Talent.com
Marsh
Senior Specialist - IT Security (Dev Sec Ops)Marsh • Vancouver, Metro Vancouver Regional District, Canada
Les candidatures ne sont plus acceptées
Senior Specialist - IT Security (Dev Sec Ops)

Senior Specialist - IT Security (Dev Sec Ops)

Marsh • Vancouver, Metro Vancouver Regional District, Canada
Il y a plus de 30 jours
Salaire
126 000,00 $CA par an
Type de contrat
  • Temps plein
Description de poste

DevSecOps & Secure-SDLC Engineer

Lead initiatives related to DevSecOps and Secure-SDLC.

Enhance the company’s Secure Software development Liability (Secure-Business) (Secure-Business) which in turn will reflect the company’s Application Development Security Policy,

Select and standardize application security tools. This includes vendor/tool assessments and full POC,

Integrate Secure-SDLC requirements and other security policy/requirements into the DevSecOps processes,

Define and enhance application security requirements and standards which must be designed for agile development methods leveraging traditional application architectures as well as cloud architectures and container workloads.

What can you expect?

  • Lead initiatives related to DevSecOps and Secure-SDLC.
  • Enhance the company’s Secure Software development Lifecycle (Secure-SDLC) which in turn will reflect the company’s Application Development Security Policy,
  • Select and standardize application security tools. This includes vendor/tool assessments and full POC,
  • Integrate Secure-SDLC requirements and other security policy/requirements into the DevSecOps processes,
  • Define and enhance application security requirements and standards which must be designed for agile development methods leveraging traditional application architectures as well as cloud architectures and container workloads.

We will count on you to:

  • Advise the application security leadership on best practices and standards around application security tools with main focus on shift-left, create predictable CI/CD pipeline processes, and enable application teams to develop new capabilities securely, and free from security defects, by design
  • Assess security tools and related processes currently used within the various Software Development Life Cycle processes to identify improvements opportunities, and rationalize the tools set
  • Select new application security tools including vendor/tool assessments and conduct full POC to prove that the security solutions/products are fit-for-purpose and fit-for-use
  • Draft documentations for the Secure-SDLC and DevSecOps to illustrate the frameworks and its process guidelines to internal customers ensuring the style is palatable and easy to navigate
  • Assess impact of new publications from the security industry (e.g. NIST 800-XXX, ISO 2700X:2022, etc) on the company’s AppSec programs
  • Research new trends and advise the application security leaderships on impact of the new trends as they relate to currently used tools, tool chain roadmap, efficiency and effectiveness of current processes, etc.
  • Promote secure coding standard and all related processes
  • Promote the priorities set forth by Global Information Security function, and the roadmap set forth by the Global Application Security
  • Automate and integrate security scan and analysis tools into the DevSecOps pipeline

What you need to have:

  • 5 years+ DevSecOps and Secure-SDLC work experience
  • CISSP, CSSLP, cloud security, DevSecOps automation, or similar is required
  • Post‑secondary education or equivalent experience as a DevSecOps Engineer
  • Develop/enhance and implement the Secure‑SDLC framework
  • Design, implement, and rollout DevSecOps automations and tool chain
  • Implement sensors to collect data on key metrics for statistics and reporting
  • Serve as the subject matter expert in Secure‑SDLC and DevSecOps
  • Advise on the processes and standards that are designed to implement a company’s Application Development Security Policy
  • Experience in designing Secure‑SDLC processes and relevant tooling to support the processes
  • Experience in software/application analysis tools like SAST, DAST, SCA, threat modeling, supply‑chain etc.
  • Technical hands‑on experience in automating and integrating security scan and analysis tools into the DevSecOps pipeline.
  • Experience in one or more programming languages
  • Familiarity with security frameworks (OWASP Top 10, SANS Top 25, CWE)

What makes you stand out:

  • Identify application security requirements and brainstorm solutions factoring in industry best practices
  • Assess the tooling and remediation of threats and vulnerabilities within our software/applications, and the hosting environment

Marsh (NYSE: MRSH) is a global leader in risk, reinsurance and capital, people and investments, and management consulting, advising clients in 130 countries. With annual revenue of over $27 billion and more than 95,000 colleagues, Marsh helps build the confidence to thrive through the power of perspective. For more information, visit corporate.marsh.com, or follow us on LinkedIn and X.

Marsh is committed to embracing a diverse, inclusive and flexible work environment. We aim to attract and retain the best people and embrace diversity of age background, disability, ethnic origin, family duties, gender orientation or expression, marital status, nationality, parental status, personal or social status, political affiliation, race, religion and beliefs, sex/gender, sexual orientation or expression, skin color, or any other characteristic protected by applicable law. In accordance with the Accessibility for Ontarians with Disabilities Act, 2005, Marsh will provide a reasonable accommodation to employees and prospective employees to the point of undue hardship upon request and as required in respect of the individual’s particular restrictions and limitations. If you require a specific accommodation because of a disability or medical need, please contact reasonableaccommodations@marsh.com.

Marsh is committed to hybrid work, which includes the flexibility of working remotely and the collaboration, connections and professional development benefits of working together in the office. All Marsh colleagues are expected to be in their local office or working onsite with clients at least three days per week. Office‑based teams will identify at least one “anchor day” per week on which their full team will be together in person.

The applicable base salary range for this role is $126,000 to $176,000.

The base pay offered will be determined on factors such as experience, skills, training, location, certifications, education, and any applicable minimum wage requirements. Decisions will be determined on a case‑by‑case basis. In addition to the base salary, this position may be eligible for performance‑based incentives.

We are excited to offer a competitive total rewards package which includes health and welfare benefits, tuition assistance, retirement programs as well as employee assistance programs.

This is a New position.

#J-18808-Ljbffr

Créer une alerte emploi pour cette recherche

Senior Specialist - IT Security (Dev Sec Ops) • Vancouver, Metro Vancouver Regional District, Canada

Offres similaires

Senior Cloud Security Engineer, Information Security

Peoples GroupVancouver, Metro Vancouver Regional District, CA
Temps plein

We are hiring for this position out of our Toronto, Vancouver and Calgary offices.Successful candidates who apply outside of these areas will be expected to relocate and reside in a location that i... Voir plus

 • Offre sponsorisée

Senior Security Engineer Focused on Detection and Response Frameworks

1PasswordVancouver, Metro Vancouver Regional District, CA
Temps plein

Join as a Senior Security Engineer to strengthen detection and incident response frameworks.Lead initiatives that optimize security measures and enhance organizational resilience in a remote enviro... Voir plus

 • Offre sponsorisée

Senior Cybersecurity Analyst — Architecture & Threat Response

Surrey Police ServiceSurrey, Metro Vancouver Regional District, CA
Temps plein

A law enforcement agency in Canada is seeking a Cybersecurity Analyst 3 to manage information security architecture and governance.This role involves developing security standards, conducting compl... Voir plus

 • Offre sponsorisée

Security and Loss Prevention Specialist, NA, Worldwide Operations Security (WWOS)

AmazonDelta, Metro Vancouver Regional District, CA
Temps plein

Worldwide Operations Security (WWOS) is the global organization that supports field Security and Loss Prevention and is designed to support Amazon’s Worldwide Operations, as well as affiliate and r... Voir plus

 • Offre sponsorisée • Nouvelle offre

Senior IT Security Engineer

Zema Global Data CorporationVancouver, Metro Vancouver Regional District, CA
Temps plein +1

Position Type: Full-time, Permanent.Industry: Commodities & Energy.Work model: Hybrid (8 days in office per month).Founded in 1995, Zema Global Data Corporation empowers organizations to simplify c... Voir plus

 • Offre sponsorisée

Senior Security Analyst, Third Party Risk

Insight GlobalVancouver, Metro Vancouver Regional District, CA
Temporaire

Senior Security Analyst, Third Party Risk.We’re seeking a seasoned security professional to join a Cybersecurity Governance, Risk & Compliance (GRC) team for a leading retail and wellness client in... Voir plus

 • Offre sponsorisée

Senior Analyst, Security Compliance

P2PVancouver, Metro Vancouver Regional District, CA
Temps plein

Our Krakenites are a world-class team with crypto conviction, united by our desire to discover and unlock the potential of crypto and blockchain technology.Kraken is a mission-focused company roote... Voir plus

 • Offre sponsorisée

Prenuvo IT Specialist II - Hybrid Role

PrenuvoVancouver, Metro Vancouver Regional District, CA
Temps plein

Take your talents to Prenuvo as an IT Support Specialist II, where hybrid work meets impactful health care technology.Support our mission with your IT expertise and proactive mindset.As part of the... Voir plus

 • Offre sponsorisée

Senior Application Security Engineer

Spring Financialvancouver, metro vancouver regional district, Canada
Permanent

Senior Application Security Engineer at Spring Financial.Senior Application Security Engineer.Spring Financial is revolutionizing financial access for Canadians, providing smart credit‑building, mo... Voir plus

 • Offre sponsorisée

Strategic Information Security Architect

ColliersVancouver, Metro Vancouver Regional District, CA
Temps plein

Transform global security architecture as a Strategic Information Security Architect.Spearhead cloud migration security strategies while ensuring systems are secure and compliant.This pivotal role ... Voir plus

 • Offre sponsorisée

Security Specialist

FedEx CanadaRichmond, Metro Vancouver Regional District, CA
Temps plein

We are looking for a Security Specialist to investigate incidents, conduct audits, support sales with high‑value packages, and collaborate across departments to minimize risk.Investigate incidents ... Voir plus

 • Offre sponsorisée

IT Technician - Information Security Specialist

OpenRoad Auto Group LimitedRichmond, Metro Vancouver Regional District, CA
Temps plein

IT Technician – Information Security Specialist – Full‑Time – Head Office, Richmond.Implement and maintain information security controls across networks, endpoints, applications, and cloud services... Voir plus

 • Offre sponsorisée

Senior Security Operations Engineer

CohereVancouver, Metro Vancouver Regional District, CA
Temps plein

Our mission is to scale intelligence to serve humanity.We’re training and deploying frontier models for developers and enterprises who are building AI systems to power magical experiences like cont... Voir plus

 • Offre sponsorisée

Remote IT Security Consultant - Leading Security Initiatives

ExperisVancouver, Metro Vancouver Regional District, CA
Télétravail
Temps plein

A leading technology staffing firm is seeking experienced IT Security Consultants to enhance cybersecurity initiatives across Canada.In this remote role, you will lead security implementations, con... Voir plus

 • Offre sponsorisée

Senior Security Engineer

fispanVancouver
Temps plein +1

As a Senior Security Engineer, you will provide leadership, expertise, and advanced security analysis capabilities within the organization’s security operations.Operating at a senior level, you wil... Voir plus

 • Offre sponsorisée

On-Site IT Security Technical Manager — Vancouver

JotformVancouver
Temps plein

Join a forward-thinking company as an IT Security Technical Manager, where you'll lead the charge in safeguarding vital information assets.This hands-on role demands a blend of strategic oversight ... Voir plus

 • Offre sponsorisée

IT Advisor - Cloud and Application Security Advisor

BC HydroVancouver, Metro Vancouver Regional District, CA
Temps plein

IT Advisor - Cloud and Application Security Advisor.Work with stakeholders to establish a set of security practices that cover all aspects of application development, from design to deployment, to ... Voir plus

 • Offre sponsorisée

Strategic IT Security Leader | Hybrid/Remote Role

TEEMArichmond, metro vancouver regional district, Canada
Télétravail
Temps plein

A leading technology solutions provider is seeking a Senior Associate to drive their cybersecurity posture and end-user technology strategy.The role requires strong operational leadership and the a... Voir plus

 • Offre sponsorisée

Remote Director of IT Security Role

DirectiveVancouver, Metro Vancouver Regional District, CA
Télétravail
Temps plein

Shape Directive Consulting's cybersecurity landscape as the Director of IT Security.This fully remote position emphasizes strategic oversight of information security across multiple regions.As the ... Voir plus

 • Offre sponsorisée

Senior IT and security Administrator – Malware Protection Specialist

act digitalVancouver, Metro Vancouver Regional District, CA
Temps plein

Senior IT and security Administrator – Malware Protection Specialist.ALTER SOLUTIONS is a consulting and technology expertise company founded in 2006.Our mission is to support our clients with thei... Voir plus