Talent.com
Integro Softwares Inc
Sr. Application Security EngineerIntegro Softwares Inc • Victoria, BRITISH COLUMBIA
Sr. Application Security Engineer

Sr. Application Security Engineer

Integro Softwares Inc • Victoria, BRITISH COLUMBIA
30+ days ago
Salary
CA$170,000.00–CA$215,000.00 yearly
Job type
  • Full-time
Job description

POSITION ROLE

Contract

POSITION DESCRIPTION

We are seeking an experienced Sr. Application Security Engineer who interfaces with technical and non-technical teams to identity product security risks and develop solutions to eliminate or minimize them. The candidate should have a deep understanding of application security vulnerabilities and mitigation strategies. He or she will drive the creation and maintenance of applications / products security standards, guidelines and procedures along with conducting application penetration testing, performing architecture/design and code reviews, and vulnerability assessments. Analyze software designs and implementations from a security perspective, and identify and resolve security issues. You will include the appropriate security analysis, defences and countermeasures at each phase of the software development lifecycle, to result in robust and reliable software.

The position is based in Victoria (Client Location).

QUALIFICATIONS

  • A minimum of 5 years’ experience leading application security functions in a fast-paced, multi-project and multi-customer IT environment.
  • Bachelor’s degree in Computer Science, IT, Information Security or in a related field.
  • Minimum 5+ years of experience in the field of security in the following areas: security engineering, incident response, system, application and network security, vulnerability management, threat modelling, penetration testing, intrusion detection, firewalls and encryption technologies.
  • Minimum 5+ years of experience in the information security field with exposure to audit, risk management, data privacy, and regulatory and compliance practices.
  • Detailed technical knowledge of techniques, standards and state-of-the art capabilities for authentication and authorization, applied cryptography, security vulnerabilities and remediation.
  • Software development experience in one of the following core languages: Ruby on Rails, SQL, HTML, Java, Javascript and .NET
  • Experience with modern Web Application Frameworks e.g. J2EE/Rails/.Net, Spring Boot, Web Services (SOAP/WSDL or REST/WADL), WCF, Service Oriented Architectures) and of network/web related protocols.
  • Preferred certifications: CISSP, CISM, SANS GIAC.
  • Knowledge and experience of cloud infrastructure security; Azure, AWS, Google Cloud.
  • Knowledge and experience working with various security frameworks (e.g., ISO/IEC 2700x, NIST CSF, COBIT, OWASP) and audit frameworks (SOC 2).
  • Knowledge of Security Information and Event Management (SIEM) tools, network and operating system security features (e.g., Windows, Linux, Ubuntu) and network security technologies (e.g. firewalls, filtering routers, authentication mechanisms, IPSEC VPN, server hardening).
  • Knowledge and experience with microservices and containerization technologies (e.g. Docker, Kubernetes, Rancher).
  • Scripting languages such as Python, Ruby, Perl, Bash and/or PowerShell.
  • Have hands-on experience with tools and technologies used throughout secure SDLC (e.g., Veracode, Blackduck) and in Agile development preferred.
  • Hands on experience with managing security awareness and training such as online training modules, lunch and learns, periodic security communication, and simulated phishing campaigns.
  • Knowledge of security flaws and its resolution as listed in sites like OWASP, SANS, etc.
  • Knowledge of authentication mechanisms like SAML, OAuth, etc.
  • Experience in secure application programming, performing code reviews, and penetration testing, web-based security testing of mobile applications preferred
  • Familiarity with attack vectors and its customer impact.
  • Ability to work in both a collaborative team environment as well as independently when required.
  • Security knowledge on current threats, trends and mitigations.
  • Strong time management and prioritization skills and ability to multi-task across various projects in a high-paced work environment to meet deadlines and manage stakeholder expectations.
  • Knowledge of software design, network architecture, protocols, and standards preferred.
  • Interest in all aspects of security research and development.

PRIMARY RESPONSIBILITIES

  • Implement, test and operate advanced software security techniques in compliance with technical reference architecture
  • Identify, highlight and provide application / API security requirements and recommendations to the engineering and product teams during architecture and design review phase
  • Perform on-going security testing and code review to improve software security
  • Provide engineering designs for new software solutions to help mitigate security vulnerabilities
  • Consult team members on secure coding practices
  • Conduct in-house penetration testing and code review of Prosper applications
  • Provide consultancy to the product development, engineering & operations teams on technical security issues and remediation
  • Take ownership of application vulnerability management process
  • Categorize the vulnerabilities as per the defined process.
  • Ensure that SAST and DAST vulnerability scans run at scheduled time.
  • Implements and configures IDS and related enterprise security systems to help the organization better identify intrusions, attacks, vulnerabilities and recommends appropriate course of action.
  • Maintains an expert-level knowledge of the daily security landscape and serves as a security advisor to Absolute as a whole.
  • Responsible for independent and team-based security audits of all security policies, procedures, and protocols with an emphasis on consistent improvement of controls.
  • Maintains, establishes, and improves vulnerability management, risk assessment, and incident management processes.
  • Interacts with IT, Hosting Operations, Product Development teams to identify areas of risk and solutions for improvement including development, infrastructure, and systems management.
  • Serves as an escalation point for all security incidents reported by users and/or security tools and drives resolution efforts.
  • Lead in the identification of potential vulnerabilities within systems, networks, DBs, applications and recommend suitable controls and countermeasures to mitigate such vulnerabilities.
  • Regularly tests and audits systems within the corporate IT and production environment for vulnerabilities and misconfigurations.
  • Advises IT, Hosting Operations and Application / Product Development teams on secure configuration, installation, maintenance, and upgrades of infrastructure and applications as well as evaluation of new products as it relates to security.
  • Creates, provides, and improves upon documentation and training to internal departments to facilitate secure day-to-day operations.
  • Plays key role in establishing and maintaining compliance programs as needed (e.g., SOC 2, GDPR, FedRAMP).
  • Architects, designs, implements, maintains and operates information system security controls and countermeasures.
  • Conducts internal penetration testing assessments (e.g., network, web applications, wireless networks).
  • Perform as the Enterprise Security Technical Lead in order to properly analyze, contain, eradicate, and recover a security incident(s).
  • Ensure fixes are applied as per the vulnerability policy.
  • Track open issues and follow up with different teams to address them.
  • Maintains current expert knowledge in the field by reviewing relevant materials and journals and maintaining appropriate professional and external contacts.
  • Undertakes special projects or assignments as required.
  • Performs other related duties as required.

Duration

  • 6 Months – Extendable by 1 to 2 Years and more based on performance

COMPETENCIES

Customer Orientation

Effective performers stay close to customers and consumers. They view the organization through the eyes of the customer/consumer and go out of their way to anticipate and meet customer/ consumer needs.

Team Management

Effective performers create and maintain functional work units. They understand the human dynamics of team formation and maintenance. They formulate team roles and actively recruit and select to build effective work groups.

High Standards

Effective performers possess a high inner work standard and shows pride in their work. They consistently strive to ensure work is complete within deadlines and that all work performed is of a high quality.

Organization & Planning

Effective performers have strong organizing and planning skills that allow them to be highly productive and efficient. They manage their time wisely and effectively prioritize multiple competing tasks. They follow through on tasks to ensure changes in technology are communicated effectively.

Results Orientation

Effective performers maintain appropriate focus on outcomes and accomplishments. They are motivated by achievement, and persist until the goal is reached. They convey a sense of urgency to make things happen. They respect the need to balance short- and long-term goals. They are driven by a need for closure.

Communicativeness

Effective performers recognize the value of continuous information exchange and the competitive advantage it brings. They actively seek information from a variety of sources and disseminate it in a variety of ways. They take responsibility for ensuring that their people have the current and accurate information needed for success.

Change Mastery

Effective performers are adaptable. They embrace needed change and modify their behaviour when appropriate to achieve organizational objectives. They are effective in the face of ambiguity. They understand and use change management techniques to help ensure smooth transitions.

Business Thinking

Effective performers see the organization as a series of integrated and interlocking business processes. They understand how their work connects with and affects other areas of the organization.

Relationship Building

Effective performers establish and proactively maintain a broad network of relationships (e.g. colleagues, co-workers, vendors, suppliers, etc.). They value these relationships and work effectively across the organization by maintaining positive working relationships with peers and others.

Create a job alert for this search

Sr. Application Security Engineer • Victoria, BRITISH COLUMBIA

Similar jobs

IVVQ Test Specialist: Shipyard & Field Tests

ThalesVictoria, Capital Regional District, CA
Full-time

A leading defense and security company is seeking an IVVQ Test Specialist based in North Vancouver.This role involves planning and executing test events, writing test plans, and analyzing requireme... Show more

 • Promoted

SHIFT SUPERVISOR

Ontario Trillium FoundationSidney, BC, CA
Full-time

As a Shift Supervisor, you lead your team to deliver exceptional guest experiences.You promote a respectful team environment and delegate tasks to team members with open communication and understan... Show more

 • Promoted

Regional Terminal Operations Director

BC FerriesSidney, BC, CA
Full-time

A leader in maritime transportation seeks a Regional Manager for Terminal Operations.Responsibilities include ensuring safety practices, managing terminal staff, and overseeing operational budgets.... Show more

 • Promoted

Cloud-First IT Systems & Security Administrator

BuyerlinkVictoria, Capital Regional District, CA
Full-time

A technology firm in Victoria, BC, is looking for an IT Support Administrator.This pivotal role will ensure the seamless functioning of the technology infrastructure, focusing on system administrat... Show more

 • Promoted

Naval Systems Integration Expert

Insight GlobalVictoria, Capital Regional District, CA
Full-time

Become a Systems/Integration Specialist with Insight Global, supporting a large naval client in Victoria, BC.This role is centered on technical expertise and complex communications environments.Uti... Show more

 • Promoted

Submarine Operations Training SME-EN

CAEEsquimalt, Capital Regional District, CA
Permanent

The Submarine Operations Subject Matter Expert (SME) provides Royal Canadian Navy (RCN) submarine operations and training expertise to the Training Systems Integration (TSI) team.In this role, you ... Show more

 • Promoted

Assistant Restaurant Manager

SSP AmericaSidney, BC, CA
Full-time

Be among the first 25 applicants.Get AI-powered advice on this job and more exclusive features.Direct message the job poster from SSP America.Strategic Corporate Recruiter | High-Volume Talent Part... Show more

 • Promoted

Cleaner - Part Time

BESTSidney, BC, CA
Part-time

Established in 1956, BEST is a Canadian janitorial company that aims to create a cleaner world by focusing on communities' social, environmental, and economic impact.We have been recognized by Delo... Show more

 • Promoted

Software Tester

Select Source InternationalCentral Saanich, Capital Regional District, CA
Full-time

Location: Saanichton BC V8M 2A5.We are seeking a highly skilled Cloud QA Engineer with strong test automation expertise to ensure the quality, reliability, and scalability of our cloud-based applic... Show more

 • Promoted

Advisor for Marine Insurance in a Hybrid Role

WaypointVancouver, Victoria
Full-time

Become a Marine Insurance Advisor at Navacord, delivering specialized support to yacht and boat owners in a hybrid capacity.Your expertise will ensure clients receive tailored insurance solutions.A... Show more

 • Promoted

Airport Restaurant Manager — Lead Front & Kitchen Ops

SSP AmericaSidney, BC, CA
Full-time

A leading airport restaurant operator in Sidney, British Columbia is seeking an experienced Assistant Restaurant Manager.The role involves managing front of house and kitchen activities in a fast-p... Show more

 • Promoted

Advisor, Personal Marine Insurance

WaypointVancouver, Victoria
Full-time

The Advisor, Personal Marine Insurance is responsible for managing and renewing a portfolio of personal marine insurance policies, delivering expert advice and exceptional service to boat and yacht... Show more

 • Promoted

Senior Systems & Security Specialist

Lighthouse IntegrationsVictoria, Capital Regional District, CA
Full-time

We are a security-first IT services and technology advisory firm based in Victoria, BC.We help growing organizations design stable, secure, and modern technology environments.At Lighthouse, we have... Show more

 • Promoted

Detention Guard - Pender Island RCMP

Commissionaires Victoria, the Islands and YukonSouthern Gulf Islands Electoral Area, BC, CA
Part-time

Our focus is on our customers and our team members.As Canada’s only not-for-profit security company, over 90% of our revenues go directly back to our team members in wages, health & dental benefits... Show more

 • Promoted

Project Lead (Permanent)

Babcock Canada Inc.Victoria, Capital Regional District, Canada
Permanent

Expected Salary: $67,021 to $83,776.To determine final salary, Babcock considers a variety of factors including the successful candidate’s skills and experience and internal equity.The final base s... Show more

 • Promoted

Senior Technical Analyst, Security Operations

Vancouver Island Health AuthorityVictoria, Capital Regional District, CA
Full-time

Senior Technical Analyst, Security Operations - (223980).Royal Jubilee Hospital (RJH) - Victoria, BC V8R 1J8 CA (Primary).Travel between multiple sites may be required.Approximate End Date (For Tem... Show more

 • Promoted

Detector Engineer OOJ - 32622

Hatch Global SearchVictoria, British Columbia, Canada
Full-time

A Detector Engineer is a cybersecurity professional specializing in designing, developing, and maintaining systems and processes to detect malicious activities or unauthorized behaviors within a ne... Show more

Senior Test Specialist - Weapons Systems

NuclearinstVictoria, Capital Regional District, Canada
Permanent

Become a Senior Test Specialist at Babcock in Victoria, BC, concentrating on Weapons systems.Drive testing initiatives and ensure operational effectiveness in national security.As a permanent membe... Show more