Search jobs > Toronto, ON > Security analyst

Application Security Analyst, Information Security

First National
Toronto, ON, Canada
$45-$65 an hour (estimated)
Full-time

We are hiring an Application Security Analyst, Information Security!

The Role :

We're seeking an Application Security Analyst well-versed in risk analysis, vulnerability assessment methodologies, and information security concepts.

Your role involves supporting security risk assessments for both internally developed and third-party / open-source software, setting up security processes, and educating various application teams within the organization.

You'll be integral in documenting and developing security controls while ensuring compliance with established frameworks.

Reporting To :

Application Security Manager

Full-Time / Part- Time :

Full-time

Posting Date : March 5, 2024

March 5, 2024

Closing Date : April 5, 2024

April 5, 2024

Hours of Work : 8 : 30 5 : 00

8 : 30 5 : 00

Grade : Office Location :

Office Location : Toronto, ON

Toronto, ON

Great location! Steps away from the main public transit station

What we offer :

Highly competitive compensation package which includes, base salary, bonus, benefits, and career advancement opportunities!

Eligibility for benefits is dependent on the terms of employment

What you will do :

  • Analyzing and documenting processes, policies, controls, and standards to comply with security frameworks and regulations.
  • Understand technical and architectural issues from a security perspective and provide recommendations.
  • Performing security reviews and provide insights throughout all phases of software development.
  • Support the Application Security Manager in managing internal and external stakeholders related to Application Security.
  • Managing and coordinating secure code reviews with stakeholders, encompassing Dynamic Application Security Testing (DAST) and Static Application Security Testing (SAST).
  • Conducting application vulnerability assessments for web, mobile, webservices and cloud applications
  • Performing or overseeing manual / automated application Vulnerability Assessment & Penetration Testing, and subsequently managing technical documentation including VAPT / Application Security tracking and reporting
  • Reviewing the configurations to Web Application Firewalls (WAF)
  • Work closely with the application development delivery teams to integrate security controls within the development pipeline ensuring an efficient development process with early security control gates.
  • Assisting the Security Leadership in collaborating with IT Groups to define, develop, communicate, and implement a comprehensive long-term application security roadmap.

This involves creating threat models for web applications and supporting development teams across the agile Software Development Life Cycle (SDLC).

Assisting in the evaluation, selection, onboarding, and management of AppSec vendors and Solutions

The Requirements Needed :

  • Strong grasp of application design and architecture
  • Proficiency in manual and automated penetration testing methods / tools (, Burp Suite, Fortify, Backtrack Kali, Metasploit Framework)
  • Knowledge of programming languages (.Net, C#, JavaScript, etc.), cloud platforms (, Azure), and database technologies in the security domain
  • Familiarity with WAF technologies, security frameworks (OWASP-TOP 10, SANs-TOP 25, CWE), and participation in Bug Bounties & Capture the Flag (CTF) would be beneficial.

Transferable Skills :

  • Excellent verbal communication
  • Excellent written skills for preparing reports and briefings.
  • Excellent analytical reasoning
  • Problem-solving approach

Education :

  • Post-secondary education, University education and Technical Certifications required.
  • Certifications and Skills :
  • Preference will be given to candidates to have CISSP.
  • Good to have Offensive Security Certified Professional (OSCP)

The team you will join :

Founded in 1988, First National is one of Canada’s largest non-bank lenders. We provide residential mortgages exclusively through our mortgage broker channel and service commercial clients through our national origination team of empowered advisors.

At First National, It’s in our Nature is our rallying cry. It underlies our values, beliefs, and how we show up for each other, our clients, our partners and the community.

Our nature defines who we are and guides every decision we make.

First National is proud to be an equal opportunity employer and is committed to diversity and inclusion regardless of race, color, religion, national origin, age, gender identity, physical or mental disability, sexual orientation or any other category protected by law.

First National supports requests for accommodation from applicants with disabilities; please contact Human Resources at .

We would like to thank all applications for their interest, but only candidates selected for an interview will be contacted.

FNLOON

30+ days ago
Related jobs
Toronto Transit Commission (TTC)
Toronto, Ontario

Information Technology Services (20000014) - Information Security Office (30000033). Provides technical expertise, support and services on all Cybersecurity awareness initiatives, this role works closely with various IT/OT and business subject matter experts to ensure appropriate security awareness ...

McCain Foods
Toronto, Ontario

Responsibilities include; ensuring compliance with standards and procedures, serving as the information security subject matter expert for designated business units or functions, participating in the development, implementation and ongoing maintenance of the information security program, and ensurin...

Global Technical Talent
Toronto, Ontario

Senior Info Security Analyst will contribute to the development of mature Governance Oversight & Control practices, through improvement of Risk Identification, Control Design and Operating Effectiveness, and modernization activities, leveraging innovation technology. Stay apprised of Industry Best P...

Toronto Parking Authority
Toronto, Ontario

POSITION SUMMARY   The Security Information Analyst will assist the Toronto Parking Authority with the design, development and implementation of its security awareness plan and security initiatives to help ensure that the best possible measures are in place to maintain secure operations. Securi...

RBC - Royal Bank
Toronto, Ontario

Confidentiality, Cyber Security Management, Decision Making, Detail-Oriented, Encryption Software, Group Problem Solving, High Impact Communication, Information Security Management, Information Technology Security. As a Senior Cyber Security Analyst in the Identity Access Management (IAM) Team, you ...

CB Canada
Toronto, Ontario

IT Security Analyst – PAM (Privileged Access Management), Active Directory. IT Security Analyst - PAM (Privileged Access Management) - Active Directory. On behalf of our client in the Banking Sector, PROCOM is looking for an IT Security Analyst - PAM (Privileged Access Management) - Active Directory...

FCT
Oakville, Ontario

Your 5-7 years’ experience in the security field will include one or more of the following key areas; Vulnerability management, IT Risk management or Security Awareness Training. As a Manager, IT Programs – Information Security:. The Information Security team oversees a robust vulnerability manageme...

Apotex
Toronto, Ontario

The IT Security Analyst works with GIS staff to ensure Apotex information and information systems are secure by verifying the Security Architecture and Program are adhered to and evaluated through the use of security tools, assessments, audits and policy. Contributes to an information security cultu...

Munich Re
Toronto, Ontario

Support adoption of Munich Re’s Information Security Management (ISM) policies and guidelines, providing feedback to the VP ERM and Cluster ISO (Information Security Officer) on adaptions to the IS Strategy, ISM Policy and Guidelines. The Information Security Risk Manager (ISRM), as part of the Ente...

David Joseph & Company
Toronto, Ontario

We are seeking a skilled Application Security Specialist with experience in secure coding practices, threat modelling, Static Application Security Testing (SAST), Software Composition Analysis (SCA), Dynamic Application Security Testing (DAST), and container security. Will provide expertise, guidanc...