Overview :
Our government client in Regina has an immediate need to hire an Application Security Analyst on a 1-year contract (with the option of a 1 yr extension), reference number RC-24-004, for their Regina, SK location.
The position requires regular onsite meetings so candidates must be local to the Regina area or willing to relocate for the duration of the contract.
What you will be doing : .
Performance of application vulnerability assessments and penetration testing.
Utilizing both automated and manual techniques to test security within applications
Responsible for web application and mobile application security testing.
Responsible for security testing of web services and APIs.
Performance of code reviews on code developed by AMS team, when required.
Performance of false positive / negative analysis and providing recommendations to developers.
Responsible for protecting all web applications using WAF.
The resource will be expected to develop strong relationships with teams throughout government and, utilizing strong collaboration and communications skills, work to further secure all of Government’s application assets.
The resource will be required to participate in consultant performance evaluation as deemed appropriate by the Ministry.
What you must have :
Candidate must be a Certified Information Systems Security Professional (CISSP) or a Certified Ethical Hacker.
Candidate should demonstrate achievements in Application and Information Security outlining that experience in the private and / or public sectors.
Experience should clearly indicate success identifying, measuring, and mitigating risks related to application development and implementation of websites and applications.
Demonstrated working experience with web protocols such as, though not limited to, HTTP, HTTPS, and SOAP.
Demonstrated working experience with web technologies such as, though not limited to, HTML, JavaScript, XML, AJAX, JSON, and REST.
Demonstrated working experience with cybersecurity standards including the Open Web Application Security Project (OWASP) Application Security Testing Standard and security testing tools
Demonstrated working experience utilizing vulnerability scanning and analysis as part of a Risk Management Program.