Talent.com
Application Security Engineer
Application Security EngineerTata Consultancy Services • Toronto, ON, CA
Application Security Engineer

Application Security Engineer

Tata Consultancy Services • Toronto, ON, CA
Il y a 4 jours
Type de contrat
  • Temps plein
Description de poste

About TCS

TCS is an IT services, consulting, and business solutions organization that has been partnering with many of the world’s largest businesses in their transformation journeys for over 55 years. Its consulting‑led, cognitive‑powered portfolio of business, technology, and engineering services and solutions is delivered through its unique Location Independent Agile delivery model, recognized as a benchmark of excellence in software development. A part of the Tata group, India's largest multinational business group, TCS operates in 55 countries and employs over 607,000 highly skilled individuals, including more than 10,000 in Canada.

Equal Opportunity & Inclusion

TCS is an equal opportunity employer, and embraces diversity in race, nationality, ethnicity, gender, age, physical ability, neurodiversity, and sexual orientation, to create a workforce that reflects the societies we operate in. Our continued commitment to Culture and Diversity is reflected in our people stories across our workforce and implemented through equitable workplace policies and processes.

Additional Information

Note : TCS does not use artificial intelligence tools for candidate screening or evaluation.

Tata Consultancy Services Canada Inc. is committed to meeting the accessibility needs of all individuals in accordance with the Accessibility for Ontarians with Disabilities Act (AODA) and the Ontario Human Rights Code (OHRC). Should you require accommodations during the recruitment and selection process, please inform Human Resources.

Job Summary

The Application Security Engineer will perform end‑to‑end penetration testing on web applications and APIs to identify security vulnerabilities, assess risk, and drive remediation. The role includes planning and executing manual and automated tests, producing clear and actionable reports, collaborating with engineering teams to fix issues, and ensuring all findings are logged and tracked through closure in the vulnerability management system.

Key Responsibilities

Penetration Testing & Assessment

  • Plan, scope, and execute web application and API penetration tests across SDLC phases (pre‑release and production).
  • Perform recon, threat modeling, and attack surface mapping to prioritize test coverage.
  • Identify and validate vulnerabilities including authentication / authorization flaws, injection, XSS, SSRF, deserialization, IDOR, insecure direct object references, logic bugs, misconfigurations, and sensitive data exposure.
  • Test API endpoints (REST / Graph QL) for input validation, rate limiting, broken object‑level authorization (BOLA), and schema / serialization issues.
  • Use both automated scanning and manual exploitation to confirm impact, reproducibility, and exploit chains.

Reporting & Remediation Support

  • Prepare detailed technical reports with PoCs, severity ratings (CVSS / SLA alignment), affected components, and business impact.
  • Provide prioritized remediation guidance with code‑level recommendations and secure patterns.
  • Log all findings in the vulnerability tracking system (e.g., JIRA, Azure DevOps, ServiceNow, or dedicated VM platforms), ensuring accurate metadata (CWE / CVE, CVSS, asset, environment, owner).
  • Track remediation progress, validate fixes, and close findings after re‑test.
  • Tooling & Automation

  • Configure, run, and tune DAST or similar tools; integrate results into CI / CD.
  • Build and maintain custom scripts for repeatable tests and payload generation.
  • Maintain test environments, proxies, and lab infrastructure (containers, mock services).
  • Required Qualifications & Skills

  • Good years in application security or red teaming with hands‑on web / API pen testing.
  • Working knowledge of CVSS scoring, CWE mapping, and SLA‑based remediation workflows in platforms like Tenable, Qualys, or custom trackers.
  • Clear technical writing, stakeholder communication, and ability to translate risk into business impact.
  • Preferred Qualifications

  • Experience embedding security testing in CI / CD (GitHub Actions, GitLab CI, Azure DevOps).
  • Familiarity with IaC scanning (Terraform, Bicep), container security, and runtime protections (RASP / WAF).
  • Experience with mobile API testing and SSO / federation architectures.
  • Salary Range

    CA$100,000 – CA$150,000 per year.

    Senior Level

  • Mid‑Senior level
  • Employment Type

  • Full‑time
  • Job Function

  • Information Technology
  • Industries

  • IT Services and IT Consulting
  • Application Process

    Applicants that meet the qualifications for this position will be contacted within a 2‑week period. We invite you to continue to apply for other opportunities that match your profile.

    #J-18808-Ljbffr

    Créer une alerte emploi pour cette recherche

    Application Engineer • Toronto, ON, CA

    Offres similaires
    Application Security Engineer

    Application Security Engineer

    Tata Consultancy Services • Toronto
    Temps plein
    TCS is an IT services, consulting, and business solutions organization that has been partnering with many of the world’s largest businesses in their transformation journeys for over 55 years.Its co...Voir plus
    Dernière mise à jour : il y a 11 jours • Offre sponsorisée
    Security Engineer

    Security Engineer

    ITCO Solutions, Inc. • richmond hill, on, ca
    Temps plein
    What You Will DoWrite code to integrate services using vendor-supplied APIs.Write code to manage asset inventory.Write code to modify data records. Work with tech leads and project managers to commu...Voir plus
    Dernière mise à jour : il y a 2 heures • Offre sponsorisée • Nouvelle offre
    Senior Application Security Engineer

    Senior Application Security Engineer

    Cognizant • Toronto
    Temps plein
    Job Title - App Security SpecialistLocation - Hybrid- Toronto.Job Summary6-9 years total experience in software development and DevOps, with at least 2 - 3 years hands-on security exposure (secure ...Voir plus
    Dernière mise à jour : il y a 15 jours • Offre sponsorisée
    Senior Security Engineer, Application & Platform Security

    Senior Security Engineer, Application & Platform Security

    Sentry • Toronto
    Temps plein
    Bad software is everywhere, and we’re tired of it.Sentry is on a mission to help developers write better software faster so we can get back to enjoying technology. With more than $217 million in fun...Voir plus
    Dernière mise à jour : il y a plus de 30 jours • Offre sponsorisée
    Security Software Development Engineer

    Security Software Development Engineer

    AMD • Markham
    Temps plein
    What you do at AMD changes everything.At AMD, our mission is to build great products that accelerate next‑generation computing experiences—from AI and data centers, to PCs, gaming and embedded syst...Voir plus
    Dernière mise à jour : il y a 12 jours • Offre sponsorisée
    AI / ML Application Security Engineer

    AI / ML Application Security Engineer

    Sophus IT Solutions • toronto, on, ca
    Temps plein
    Role : AI / ML Application Security Analyst.Conduct comprehensive security assessments of applications and AI / ML systems to identify vulnerabilities and implement robust security measures.Develop and ...Voir plus
    Dernière mise à jour : il y a 2 heures • Offre sponsorisée • Nouvelle offre
    Application Security Engineer (Hybrid)

    Application Security Engineer (Hybrid)

    Homebase • Toronto
    Temps plein
    At Homebase, you’ll join a team that’s bold, fast-moving, and obsessed with helping small businesses thrive.We build with empathy, act with urgency, and take big swings that drive real-world impact...Voir plus
    Dernière mise à jour : il y a plus de 30 jours • Offre sponsorisée
    Application Security Engineer — Offensive Testing & Cloud Security (Hybrid)

    Application Security Engineer — Offensive Testing & Cloud Security (Hybrid)

    Themis Solutions Inc. • Toronto
    Temps plein
    A leading legal technology firm in Toronto seeks an Application Security Engineer to enhance its security team.The ideal candidate will focus on penetration testing and vulnerability remediation, w...Voir plus
    Dernière mise à jour : il y a 1 jour • Offre sponsorisée
    Security Engineer

    Security Engineer

    Galent • Toronto, Canada
    Temps plein
    Strong developer background and hands-on experience with Application security tools.Application Security (SAST, SCA, DAST, WAF, ASPM), or Infrastructure, Container, Cloud security with background i...Voir plus
    Dernière mise à jour : il y a plus de 30 jours • Offre sponsorisée
    Security Engineer II

    Security Engineer II

    PagerDuty • Toronto
    Temps plein
    NYSE : PD) is a global leader in digital operations management.Trusted by nearly half of both the Fortune 500 and the Forbes AI 50, and approximately two-thirds of the Fortune 100, PagerDuty is essen...Voir plus
    Dernière mise à jour : il y a plus de 30 jours • Offre sponsorisée
    Security Engineer II - Product Security

    Security Engineer II - Product Security

    Rippling • Toronto
    Temps plein
    Rippling gives businesses one place to run HR, IT, and Finance.It brings together all of the workforce systems that are normally scattered across a company, like payroll, expenses, benefits, and co...Voir plus
    Dernière mise à jour : il y a 11 jours • Offre sponsorisée
    Lead Application Security Engineer

    Lead Application Security Engineer

    Nasdaq, Inc. • Toronto
    Temps plein
    Lead Information Security Engineer page is loaded## Lead Information Security Engineerlocations : St.John's - 18 Hebron Way : Canada - Montreal - Québec : Canada - Toronto - Ontariotime type : ...Voir plus
    Dernière mise à jour : il y a plus de 30 jours • Offre sponsorisée
    Senior Security Engineer, Application & Platform Security

    Senior Security Engineer, Application & Platform Security

    Sentry.io • Toronto
    Temps plein
    Bad software is everywhere, and we’re tired of it.Sentry is on a mission to help developers write better software faster so we can get back to enjoying technology. With more than $217 million in fun...Voir plus
    Dernière mise à jour : il y a plus de 30 jours • Offre sponsorisée
    Application Security, Lead

    Application Security, Lead

    Interac Corp. • Toronto, Canada
    Temps plein
    Who We Are : • •Every transaction matters.At Interac, we protect both — driving trust, security, and inclusion, so our digital economy thrives. Founded in 1984, Interac connects Canadians through secur...Voir plus
    Dernière mise à jour : il y a 6 jours • Offre sponsorisée
    EMBEDDED SECURITY ENGINEER

    EMBEDDED SECURITY ENGINEER

    Advanced Micro Devices • Markham
    Temps plein
    WHAT YOU DO AT AMD CHANGES EVERYTHING.We care deeply about transforming lives with AMD technology to enrich our industry, our communities, and the world. Our mission is to build great products that ...Voir plus
    Dernière mise à jour : il y a plus de 30 jours • Offre sponsorisée
    AI / ML Application Security Engineer - Sophus IT Solutions

    AI / ML Application Security Engineer - Sophus IT Solutions

    Sophus IT Solutions • toronto, on, ca
    Temps plein
    Role : AI / ML Application Security Analyst.Conduct comprehensive security assessments of applications and AI / ML systems to identify vulnerabilities and implement robust security measures.Develop and ...Voir plus
    Dernière mise à jour : il y a 2 heures • Offre sponsorisée • Nouvelle offre
    Application Security Consultant

    Application Security Consultant

    Forward Security • Toronto
    Temps plein
    MUST RESIDE IN TORONTO, OTTAWA, OR VANCOUVER.As an Application Security Consultant, you will be responsible for performing security assessments on applications and cloud environments.This includes ...Voir plus
    Dernière mise à jour : il y a plus de 30 jours • Offre sponsorisée
    Application Security and identity / Infrastructure Security Engineer (Kubernetes clusters)

    Application Security and identity / Infrastructure Security Engineer (Kubernetes clusters)

    freelance.ca • Toronto, Canada
    Temps plein
    Application Security and identity Engineer / Infrastructure security engineer (Kubernetes clusters).Work Location : hybrid, downtown Toronto, ON. Contract Term : 6 months, highly renewable extended be...Voir plus
    Dernière mise à jour : il y a plus de 30 jours • Offre sponsorisée