Sr. Application Security Specialist (GCS)

RBC - Royal Bank
Vancouver, BC
$45-$65 an hour (estimated)
Full-time

Job Summary

Job Description

WHAT IS THE OPPORTUNITY?

Reporting to the Senior Manager of Application Security Transformation - you would provide technical execution in Application Security for the global RBC business and application development teams across all enterprise information technology groups.

You will be participating in the development of application security best practices, tools, and processes. You will also help execute various application security projects across all RBC lines of business.

This role will also require you to have solid understanding of CI / CD pipelines, DevSecOps and various application security testing techniques such as SCA, OSA, SAST, DAST and IAST.

WHAT WILL YOU DO?

Develop automation & integration capabilities for tools onboarding and security controls enforcement by partnering with Enterprise DevOps team.

Support end users & Review Dynamic application security testing reports to validate findings / false positives and assist developers in the remediation.

Develop metrics to measure Security and Risk posture of RBC applications.

Educate key organizational stakeholders (e.g. developers, security consultants, executives) on application security matters across the organization.

Assist in the development, evaluation, and implementation of application security controls and processes.

Ensure applications are thoroughly tested for security vulnerabilities using industry best practices prior to production release.

Research and keep up to date on application security emerging threats, techniques, tools, and trends.

Work in a diverse environment leveraging other team members' experience and knowledge.

WHAT DO YOU NEED TO SUCCEED?

Must have :

Experience developing and testing apps in any of programming languages : Python, Java (preferred).

Knowledge of Secure Software Development practices, SCA / OSA, SAST, DAST, IAST methods & tools.

Understanding of CI / CD and DevSecOps approaches and experience working with DevSecOps tools.

Solid understanding of security-related frameworks and OWASP Top 10 (Web & API).

Strong written / verbal communications skills and ability to manage client / stakeholder relations.

Nice-to-have :

Understanding of GitHub Actions based pipeline & GitHub Advanced Security tools.

Prior experience of leading Enterprise level Application Security Controls & enforcement.

RBC is committed to supporting flexible work arrangements when and where available. Details to be discussed with Hiring Manager.

What's in it for you?

We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper.

We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.

A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable

Leaders who support your development through coaching and managing opportunities

Ability to make a difference and lasting impact

Work in a dynamic, collaborative, progressive, and high-performing team

A world-class training program in financial services

Flexible work / life balance options

Opportunities to do challenging work

LI-Hybrid

LI-POST

TECHPJ

Job Skills

Application Programming Interface (API) Security, Application Security, Curiosity, DevOps, DevSecOps, GitHub Actions, GitHub Advanced Security, Java, Leadership, Mentorship, Open Web Application Security Project (OWASP), OWASP Top 10, Prioritization, Python (Programming Language), Secure Coding Practices, Technology Leadership

30+ days ago
Related jobs
Royal Bank of Canada>
Vancouver, British Columbia

Application Programming Interface (API), Application Security, Applications Programming, Critical Thinking, DevOps, Group Problem Solving, Information Security, Java, Open Web Application Security Project (OWASP), OWASP Top 10, Prioritization, Python (Programming Language), Secure Coding Practices, ...

RBC - Royal Bank
Vancouver, British Columbia

Application Programming Interface (API) Security, Application Security, Curiosity, DevOps, DevSecOps, GitHub Actions, GitHub Advanced Security, Java, Leadership, Mentorship, Open Web Application Security Project (OWASP), OWASP Top 10, Prioritization, Python (Programming Language), Secure Coding Prac...

0000050007 Royal Bank of Canada
Vancouver, British Columbia

Decision Making, Group Problem Solving, Identity Access Management (IAM), Information Security, Information Technology Security, IT Systems Integration, Negotiation, Security Controls, Security Information, Security Information and Event Management (SIEM), SIEM Tools, Software Development, Software ...

RBC - Royal Bank
Vancouver, British Columbia

Decision Making, Group Problem Solving, Identity Access Management (IAM), Information Security, Information Technology Security, IT Systems Integration, Negotiation, Security Controls, Security Information, Security Information and Event Management (SIEM), SIEM Tools, Software Development, Software ...

S.i. Systems
Vancouver, British Columbia

Sr Data Architect to develop and implement data governance policies and frameworks to ensure data quality, security, and compliance for B2B applications (ServiceNow, NetCracker, Salesforce, Amdocs, BMC Remedy) for our large telecom client -. Develop and implement data governance policies and framewo...

Royal Bank of Canada>
Vancouver, British Columbia

API Gateway, API Specifications, API Testing, Application Programming Interface (API) Security, Atlassian JIRA, CloudBees Jenkins, DevSecOps, Dynamic Application Security Testing (DAST), GitHub Actions, GitHub Issues, IT Security Architecture, IT Systems Integration, Kubernetes, OAuth, OWASP Top 10,...

Promoted
Intuitive.Cloud
Canada

The Senior Cybersecurity Specialist will be responsible for developing and implementing comprehensive cybersecurity strategies and solutions, with a focus on Security Cloud Architecture and Risk Assessment. This requirement is to be part of Intuitive’s Cybersecurity Program and will be part of the C...

Tundra Talent Community
Vancouver, British Columbia

Candidates with physical security experience in addition to cyber security experience may be given preference. Ability to obtain security clearance for a Security Sensitive Position classification. A minimum of 10 years of relevant cyber security and/or associated reliability compliance/audit experi...

Behavox
Canada -
Remote

As part of the Behavox Cyber Security team the Security Incident Response Analyst will monitor, detect, analyze, and mitigate cyber security incidents. Improve and optimization of SIEM security events working on a team dedicated to extraordinary Cyber Security standards. Experience working with Secu...

Swim Recruiting
Vancouver, British Columbia

Permanent Information Security Analyst role with an award winning industry leader with a focus on collaboration and internal development. Permanent Information Security Analyst role  . As a result of investment in technology, our client is looking to add an Information Security Analyst to their...