Application security engineer

Tundra Talent Community
London, ON, Canada (Hybrid)
170K $-215K $ / an (estimé)
Temps plein

As an Application Security Engineer within the Information Security Department, you will be responsible for building security into all products end-to-end.

You will be both hands-on technical and influential, where you will be expected to directly communicate with cross-functional teams in Product, Development, and DevOps.

You will be responsible for analyzing the security of applications and services, discovering, and addressing security issues, building automation, and decisively taking action to mitigate emerging threats throughout the Secure Software Development Lifecycle (SSDLC).

What you will do :

  • Act as a subject matter expert for strategic initiatives, quarterly projects, and on-demand consultations.
  • Collaborate with product and development teams to ensure the adoption of SSDLC best practices across the entire application lifecycle (SAST, SCA, DAST, WAF, ASPM, etc.).
  • Write code to implement security policies and controls for well-known orchestration platforms (GitLab, Jenkins, etc.).
  • Participate in vulnerability management operations, such as : retesting and reprioritizing vulnerabilities, reviewing code changes, approving proposed remediations, etc.
  • Perform white box testing on a portfolio of products.
  • Contribute technical and procedural documentation towards the organization’s knowledge base.

What you will bring :

  • Ability to think offensively like a hacker and defensively by evaluating applications and architecture.
  • Excellent written communication skills, with a focus on translating technically complex issues into simple, easy to understand concepts.
  • Read and write multiple programming languages. Java, C#, JavaScript, Apex, and Python are highly valued, but others will help too.
  • Demonstrated knowledge of security best practices, principles, and common frameworks, such as : OWASP, NIST, ISO, SOC, etc.
  • Prior experience in implementing and integrating tools for static analysis, dynamic analysis, fuzzing, bug bounty, etc.
  • Microservice architecture expertise and best practices in securing APIs across multi-cloud environments.
  • Relevant industry certifications, such as : OSCP, OSWE, GPEN, GWAPT, etc.

Job 69851

Il y a plus de 30 jours
Emplois reliés
Tundra Talent Community
London, Ontario
Temps plein

As an Application Security Engineer within the Information Security Department, you will be responsible.. You will be responsible for analyzing the security of applications and services, discovering, and..

Humber College
Ontario, Canada
Temps plein

Senior Applications Engineer. Application Administrator. E&AR. I O. ( 29486 ) Description. Find Your.. User management, including maintaining profiles, users, security settings, data sharing rules Maintain..

CARFAX
London, Ontario
Temps plein

Description Join Team CARFAX as a Cloud Engineer At CARFAX, we believe in the power of teamwork and.. DEVSECOPS. Development, Security and OperationsOperational experience. ready to own the uptime and..

Offre sponsorisée
GalaxE.Solutions
London, Ontario
Temps plein

Analytical and problem solving skills Skills and Experience You Will Need Required 5 7 years' experience in an Engineer Developer or DevOps related role5. years' experience working with Linux..

Highbrow LLC
London, Ontario
Temps plein

Required 5 7 years' experience in an Engineer Developer or DevOps related role5. years' experience working with Linux operating systems (ideally Red Hat Enterprise Linux), especially experiences..

CB Canada
London, Ontario
Temps partiel