Join one of Canada’s fastest-growing companies and be part of something extraordinary – welcome to goeasy! At goeasy, our people and culture are at the heart of everything we do, and we’re proud to be recognized for it. We’ve earned prestigious accolades such as Waterstone Canada’s Most Admired Corporate Cultures, Canada’s Top Growing Companies, and the TSX30, highlighting us as one of the top performers on the TSX. We’re also honoured to be named a Greater Toronto Top Employer and recognized by Great Place to Work® as having the Best Workplaces for Women &Most Trusted Executive Teams, and included on TIME Magazine’s 2025 list of Canada’s Best Companies. These honours reflect our commitment to fostering an inclusive, high-performance culture where talent thrives and innovation drives us forward.
As one of Canada’s leading alternative consumer lenders, we’re passionate about helping everyday Canadians create a brighter future. Our vision is to provide a path to a better tomorrow, today. We offer a full range of products, including non-prime leasing, unsecured and secured loans, and point-of-sale financing through easyhome, easyfinancial, and LendCare.
If you're seeking an exciting, high-growth environment where your contributions truly matter, we want to hear from you! Join us, and together, let's create a future of financial empowerment.
The Senior IT Security Advisor, Application Security plays a critical role in protecting and enabling goeasy's technology landscape. As a senior security expert, you'll lead security assessments, influence architecture decisions, and partner with teams across the organization to embed security into every stage of the development and delivery lifecycle.
You'll serve as a trusted advisor to business and technology stakeholders, helping identify and manage security risks across applications, cloud platforms, infrastructure, networks, and strategic technology initiatives. Combining strong technical expertise with a pragmatic, risk-based approach, you'll drive security best practices, mature application security capabilities, and help ensure goeasy continues to deliver innovative solutions securely and confidently.
What will you be doing?
- Lead security risk assessments for applications, infrastructure, cloud, network, and enterprise technology initiatives using ISO 27001, NIST, PCI DSS, SOC 2, and internal security standards to identify, assess, document, and communicate security risks and remediation strategies.
- Conduct security architecture and design reviews to ensure solutions align with organizational security standards, regulatory requirements, and industry best practices.
- Perform threat modelling, vulnerability analysis, and impact assessments to identify risks and recommend appropriate mitigation strategies.
- Partner with engineering, infrastructure, architecture, and business teams to provide security guidance throughout project lifecycles.
- Present security findings, risk recommendations, and remediation plans to technical and non-technical stakeholders.
- Promote Security by Design principles throughout project delivery lifecycles and enterprise technology initiatives.
- Champion Secure Software Development Lifecycle (SSDLC) practices, including secure coding standards, shift-left security, automated testing, and CI/CD integration.
- Manage and mature application security programs, including SAST, SCA, DAST, penetration testing, vulnerability management, and API security.
- Manage third-party application security testing activities, validate findings, and drive remediation efforts based on risk.
- Identify security gaps across the technology landscape and recommend scalable, practical solutions to strengthen goeasy's security posture.
- Act as a trusted advisor on information security, privacy, compliance, and risk management matters.
- Evaluate existing security technologies and processes, recommending improvements that enhance efficiency, effectiveness, and security maturity.
- Support and maintain security controls and compliance initiatives, including PCI DSS, SOC 2, Bill 198, and other regulatory requirements.
What experience do you have?
- Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related field; postgraduate education is considered an asset.
- 8+ years of Information Security experience, including 5+ years specializing in Application Security, Security Architecture, Security Risk Assessments, and Threat Modeling within complex enterprise environments.
- Strong knowledge of secure software development practices (SSDLC), DevSecOps, CI/CD pipelines, secure coding principles, and modern application security frameworks.
- Hands-on experience with application security testing and vulnerability management, including SAST, SCA, DAST, penetration testing, and API security.
- Deep understanding of cloud, infrastructure, network, and web application security, including OWASP Top 10 vulnerabilities and remediation methodologies.
- Experience leading cross-functional security initiatives, influencing technical and business stakeholders, and working within regulated environments such as PCI DSS, SOC 2, SOX, and/or Bill 198.
- Experience with Azure and/or AWS cloud platforms is required; previous Information Security Architect experience, programming/scripting experience (, Java, Python, JavaScript, Go, Apex, or R), and Linux/Unix administration are considered strong assets.
- Professional certifications including CISSP (required). Additional certifications such as CRISC, CSSLP, CCSP, CISM, OSCP, or GPEN are considered assets.
We offer a Flexible Work Program that provides you the ability to work three days onsite per week, from our Mississauga office.
Internal Applicants: please apply through the link and provide written endorsement from your current manager.
$141,570.00 – $154,000.00 CAD (includes base salary and bonus)
We’re committed to attracting and rewarding top talent. Our compensation ranges are thoughtfully designed to reflect market competitiveness, internal equity, and the experience and impact each candidate brings to the role.
At goeasy, we believe transparency fosters trust — and that rewarding performance with fair, competitive pay and meaningful growth opportunities is key to our success.
Should your total compensation expectations fall above the posted range, we still encourage you to apply. If selected for an interview, you’ll have the opportunity to discuss this with our recruitment team, as there may be flexibility based on your background and overall fit. Total compensation includes base salary and bonus.
This posting is for an existing vacancy within our team.