Search jobs > Toronto, ON > Cyber security specialist

Specialist, Application Security – Cyber

TEEMA
Old Toronto, ON, Canada
$122K-$163.6K a year
Full-time

Job Title : Senior Specialist, Application Security (Cyber)

Job ID : 70871

Location : Toronto, Ontario

Overview :

Our client, The City of Toronto, is looking for a Senior Application Security Specialist with 5+ years of experience to lead their application security efforts, focusing on DevSecOps practices, container security, threat modeling, and cloud security.

The ideal candidate will play a crucial role in ensuring the security and integrity of their applications throughout the development lifecycle.

To provide strategic and operational guidance to the Manager Application Security as well as the Director Cyber Threat Management in the execution of its mandate to establish and maintain a City-wide cyber program to ensure the City is adequately protected.

What you will be doing :

  • Implement and maintain robust application security practices within our DevSecOps framework. Collaborate with development teams to integrate security into CI / CD pipelines.
  • Perform security assessments, code reviews, and help dev teams in remediation.
  • Conduct threat modeling for new and existing applications and systems.
  • Develop and enforce container security policies and best practices.
  • Implement and manage cloud security solutions including but not limited to CASB, Microsoft Defender products, and container security measures for Docker and Kubernetes to ensure comprehensive protection of cloud data, applications, and infrastructure.
  • Provide security guidance and training to development and operations teams.
  • Stay current with emerging threats and security technologies.
  • Conduct research on different enterprise security solutions.

What you must have :

  • Post-secondary degree in Business or Technology or a related discipline.
  • 5+ years of experience in application security with a strong understanding of application security threats, attack patterns, and emerging security vulnerabilities.

Strong knowledge of common security standards and frameworks (OWASP Top 10, NIST / CSC / ISO 27001, etc.).

  • Strong understanding and hands-on experience of Static Application Security Testing (SAST), secure coding practices, Open-Source Analysis, and infrastructure as a code scanning.
  • Expertise in DevSecOps methodologies and tools with an understanding of GitHub, GitLab, Bitbucket, Artifactory, Jenkins, micro-service, etc.
  • Experience with threat modeling techniques and methodologies.
  • Proficiency in container technologies (Docker, Kubernetes) and their security implications.
  • Able to work at three levels Strategy, design, and hands-on technical.
  • Strong communication and influencing skills for working cross-functionally with teams.
  • Proficient in cloud security and industry-leading best practices for robust data protection.
  • Must have excellent knowledge of different areas of IT operations / processes (change mgmt., release mgmt.) and be able to define / design security processes to meet business requirements.
  • Preferred Certifications (any in the list) : CISA / CISSP / CCSP / CISM / CIA / CEH / SANS GIAC, CSSLP, CAS.

Skills :

  • Ability to work in transformative programs.
  • Ability to lead efficient communication between all project stakeholders, including internal teams and clients.
  • Ability to achieve business objectives through influencing and effectively working with key stakeholders.
  • Excellent written & verbal communication skills (comfortable & confident communicating at all levels including business partners, leadership, and vendors).
  • Excellent problem-solving skills with capability to identify solutions to unusual and complex problems.
  • Keen attention to detail and strong organizational skills.
  • Highly organized, proactive, self-motivated team player who takes initiative and is able to work independently.
  • Ability to work in a fast-paced environment managing multiple priorities with proven time management skills.
  • Strong analytical skills and ability to prioritize and multitask.
  • Ability to prioritize and effectively manage competing priorities and projects.
  • Ability to manage multiple initiatives while adhering to strict deadlines.
  • Tenacious and willing to support the team during peak volumes and workloads with various activities.
  • Able to work extremely well under pressure while maintaining a high level of professionalism.
  • Self-motivated team player who takes initiative and can work independently.
  • Transferable skills, like communication and decision-making, are equally important.
  • Being able to think on your feet and show good judgment are especially valuable in this field. Security pros should always be ready to react to cyber-related incidents quickly.

Salary / Rate Range : $122,000.00 $163,639.00

Other Information :

A normal work week is 35 hours; however, unforeseen situations may require extended hours of work with little or no prior notice.

In case of a cyber incident or breach, rotation shift, continuous extended hours may be required with little or no prior notice.

  • Subject to a police check, background check, psychological assessment, and / or any other checks on a regular basis as the Office of the CISO handles highly sensitive and confidential information.
  • Equity, Diversity and Inclusion : The City is an equal opportunity employer, dedicated to creating a workplace culture of inclusiveness that reflects the diverse residents that we serve.

Learn more about the City’s commitment to employment equity.

Accommodation : The City of Toronto is committed to creating an accessible and inclusive organization. We are committed to providing barrier-free and accessible employment practices in compliance with the Accessibility for Ontarians with Disabilities Act (AODA).

Should you require Code-protected accommodation through any stage of the recruitment process, please make them known when contacted and we will work with you to meet your needs.

Disability-related accommodation during the application process is available upon request. Learn more about the City’s Hiring Policies and Accommodation Process.

J-18808-Ljbffr

5 hours ago
Related jobs
Promoted
Q1 Technologies, Inc.
Toronto, Ontario

Researching emerging threats and trends to proactively update security measures and stay ahead of evolving cybersecurity landscape. Security tool management: Evaluating, implementing, and maintaining security tools and technologies to enhance security posture. Incident response management: Designing...

Promoted
TEEMA
Toronto, Ontario

Our client, The City of Toronto, is looking for a Senior Application Security Specialist with 5+ years of experience to lead their application security efforts, focusing on DevSecOps practices, container security, threat modeling, and cloud security. Senior Specialist, Application Security (Cyber). ...

Promoted
Cyber Crime
Canada

The Senior Specialist, Cyber Security, reporting to the Senior Manager, IT Security is responsible for managing security controls, delivering security consultation, and providing security best practices for Northwestel. The Senior Specialist, Cyber Security must understand the diverse security infra...

Promoted
Cedeksconsulting
Canada

Experience in operating, configuring, and administering cyber security tools such as intrusion prevention systems, security information and event management tools, anti-malware services, and spam filters. Information about and comprehension of the Payment Card Industry Data Security Standard and oth...

Promoted
ProViso Staffing
Toronto, Ontario

Sound knowledge of one or more technology controls or security domains, disciplines, and practices such as but not limited to Vulnerability Management, Data Security, Application Security, Cloud Security, Identity and Access Management, Asset Currency (End of Life/Support), Cyber Threat Management, ...

Promoted
M87 Cyber Security Inc.
Canada

We are always on the lookout for amazing talent who can contribute to our growth and deliver results! M87 Cybersecurity is seeking a Cybersecurity Operations Specialist responsible for developing a thorough understanding of our security systems and programs to secure our infrastructure. Experience i...

The Toronto-Dominion Bank (Canada)
Toronto, Ontario

Security+, CISSP, or other Cybersecurity certifications preferred. The specialist will provide research, evaluation, assessment, operational, reporting and/or analytical support on Technology Controls/Information Security related programs and initiatives. May participate and provide advice/guidance ...

Sobeys
Mississauga, Ontario

In this exciting role, you will be working alongside a team of high performing, 24x7 on-call Cyber Security Operations professionals who are skilled and knowledgeable regarding all facets of Cyber Security and technology. Sobeys is full of exciting opportunities and we are always looking for bright ...

David Joseph & Company
Toronto, Ontario

We are seeking a skilled Application Security Specialist with experience in secure coding practices, threat modelling, Static Application Security Testing (SAST), Software Composition Analysis (SCA), Dynamic Application Security Testing (DAST), and container security. Will provide expertise, guidanc...

David Joseph & Company
Toronto, Ontario

We are seeking a skilled Application Security Specialist with experience in secure coding practices, threat modelling, Static Application Security Testing (SAST), Software Composition Analysis (SCA), Dynamic Application Security Testing (DAST), and container security. Will provide expertise, guidanc...