Talent.com
National Bank
Lead Application Security Analyst (Hybrid)National Bank • Montreal, Montreal
Lead Application Security Analyst (Hybrid)

Lead Application Security Analyst (Hybrid)

National Bank • Montreal, Montreal
30+ days ago
Job type
  • Full-time
  • Part-time
  • Permanent
Job description
Attendance Hybrid Job number 32619 Category Senior Professional Status: Permanent Type of Contract Permanent Schedule: Full-Time Full Time / Part Time? Full-Time Posting date 21-Apr-2026 Area(s) of interest: Information technology Location(s): Montreal, Montreal

A career as a DevSecOps lead on the Asset Protection team at National Bank means serving as a specialist in application security, vulnerability management and DevSecOps practises. This position allows you to have a positive impact on our organisation thanks to your expertise in securing application delivery chains and vulnerability management, your experience in integrating security by design and your ability to influence technology practises on a large scale.

On a daily basis, you help protect the Bank's applications, data and clients by working closely with the development, DevOps, architecture and security teams. You work in an environment where collaboration, continuous improvement and automation are at the heart of our work methods.

Your job

  • Support development teams in identifying, prioritising and correcting application vulnerabilities throughout the application lifecycle.
  • Act as a reference person for application security, vulnerability management and DevSecOps practises for delivery teams by supporting security-related technical decisions.
  • Integrate and optimise application security tools in continuous delivery pipelines, particularly for analysing code, dependencies, infrastructures and containers.
  • Design and maintain secure CI/CD pipelines (GitHub Actions, CI GitLab, etc.) and preventive security controls integrated into application delivery workflows.
  • Contribute to the evolution of standards, governance frameworks and practises for application security and vulnerability management in order to increase the organisation's DevSecOps maturity.
  • Explore and promote advanced automation, including the use of artificial intelligence and agentic approaches to improve operational efficiency.

Your team

Vice-President – Strategy, practises and Delivery, we have more specialists who work in an agile, proactive and collaborative manner to seize opportunities, stay on the cutting edge of technology and continuously improve processes.

You are part of a team of 12 colleagues in the Information Technology sector and will report to the Senior Manager – Asset Management. Our team stands out for its high level of technical expertise, delivery quality, operational excellence and a culture of collaboration, continuous learning and employee experience. Our goal is to offer you maximum flexibility to promote your quality of life, thanks to a hybrid work environment and a flexible, adaptable schedule.

The Bank values continuous development and internal mobility. Our personalised training programs, based on on on-the-job learning, help you master your profession and develop new fields of expertise. Tools such as the Data Academy, language training, the Harvard Learning Centre and coaching and mentoring support are available to you at any time.

Prerequisites

  • A bachelor’s degree and 7 years of experience, or a master’s degree and 5 years of experience in software development or application security and vulnerability management.
  • In-depth experience in application security, vulnerability management and DevSecOps practises, including securing the software supply chain.
  • Master application security concepts such as OWASP Top 10, security development cycle, vulnerabilities and risk rating mechanisms
  • Working knowledge of vulnerability management and application security tools, including tenable, Snyk and AQUEC.
  • Experience with cloud environments (e.g. AWS, Azure), infrastructure as code (e.g. Terraform, CloudFormation) and containerisation technologies (e.g. Docker, Kubernetes).
  • Hands-on experience with application security tools integrated into continuous delivery pipelines.

Languages: English, French Reason to require this language: you will need to discuss frequently with our service providers or partners who speak a language other than French.

Skills

Press space or enter keys to toggle section visibility

Amazon Web Services Application Security Docker Vulnerability Assessment Vulnerability Management Initiative Resiliency Kubernetes Terraform Continuous delivery DevSecOps Continuous Integration/Continuous Delivery Pipelines Your benefits In addition to competitive compensation, upon hiring you’ll be eligible for a wide range of flexible benefits to help promote your wellbeing and that of your family such as:
* Health and wellness program, including many options * Flexible group insurance * Generous pension plan * Employee Share Ownership Plan * Employee and family assistance program * Preferential banking services * Involvement in community initiatives * Telemedicine service * Virtual sleep clinic
We have an offer that keeps up with trends as well as your needs and those of your family.
Our dynamic work environments and cutting-edge collaboration tools foster a positive employee experience. We value employees’ ideas. Whether through our surveys or programs, regular feedback and ongoing communication are encouraged.
Making a bold move in a people-first environment We’re a bank on a human scale that stands out for its courage, entrepreneurial culture, and passion for people. Our mission is to have a positive impact on people’s lives. Our core values of partnership, agility, and empowerment inspire us, and inclusion is central to our commitments. We aim, wherever possible, to provide a barrier-free and accessible environment to all employees.
We strive to provide accessibility measures throughout the recruitment process within the limits of our available resources. If you require accommodations, feel free to let us know during our initial conversations. We welcome all candidates! What can you bring to our team?
Join us! Une carrière en tant que ConseillerAs a Senior Legal Advisor in the Legal
Create a job alert for this search

Lead Application Security Analyst (Hybrid) • Montreal, Montreal

Similar jobs

Technical PM – Application Security for Banking (Montreal)

Trigyn TechnologiesMontreal
Full-time

A major IT solutions provider is seeking a Technical Project Manager for a contract position in Montreal.This role involves managing security testing engagements and liaising with various stakehold... Show more

 • Promoted

Cyber Security Analyst

MindlanceMontréal, Montreal (administrative region), Canada
Full-time

This range is provided by Mindlance.Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.Subject Matter Expert - Recruitment at Mindlance.Job Role: I... Show more

 • Promoted

Analyst, Security Governance

AltoMontreal (administrative region), QC, CA
Full-time

At Alto, we are actively contributing to the transformation of Canada's future with our high-speed train project connecting Quebec City and Toronto.With the support of the Government of Canada, thi... Show more

 • Promoted

Security Analyst (SOC)

Bedard ResourcesLaval (administrative region), QC, CA
Full-time

Our client is looking for a Junior Cybersecurity Analyst to assist with the daily management of a simulation platform, support the onboarding of new clients, and contribute to analyses related to a... Show more

 • Promoted

Workday Security Analyst

neteffectsMontreal (administrative region), QC, CA
Full-time

Remote from the UK - to work for an International US-based company.Workday security area – focusing on Workday HR user, domain, business process, and integrations security, privacy, audit, controls... Show more

 • Promoted

SAP Security Architect

Addmore GroupMontreal (administrative region), QC, CA
Full-time

Our client is hiring an SAP Security Architect.Location: Montreal or Greater Toronto Area.Workplace Type: Hybrid – Onsite 4 days/week mandatory.Salary: $117,560 to $154,300 (offers vary commensurat... Show more

 • Promoted

Senior Analyst - Security Operations

Cirque du Soleil Entertainment GroupMontreal (administrative region), QC, CA
Permanent

Senior Analyst – Security Operations.Review security events to detect and prevent potential information security incidents.Analyze threats and identify strategies to contain and prevent them.Partic... Show more

 • Promoted

Application Security Engineer

HireTalent - Staffing & Recruiting FirmMontreal, Montreal (administrative region), CA
Full-time

Information Security Engineer II.Application Security is looking to recertify all third-party connections in compliance with in-transit encryption requirements.We are seeking 2 Cyber Security exper... Show more

 • Promoted

Senior Security Engineer Focused on Detection and Response Frameworks

1PasswordMontreal (administrative region), QC, CA
Full-time

Join as a Senior Security Engineer to strengthen detection and incident response frameworks.Lead initiatives that optimize security measures and enhance organizational resilience in a remote enviro... Show more

 • Promoted

MONTREAL [Hybrid] - Senior Security Analyst L3

QUANTEAM (RAINBOW PARTNERS Group)Montréal, Quebec, Canada
Full-time

MONTREAL [Hybrid] - Senior Security Analyst L3 Get AI-powered advice on this job and more exclusive features.Direct message the job poster from QUANTEAM (RAINBOW PARTNERS Group).As the founding ent... Show more

 • Promoted

Security Program Lead, Cloud & App Risk (Hybrid) - C$86,100 - C$136,100 A Year

Southwestern Ontario Financial Services ProviderLe Plateau, Canada
Full-time

Lead IT security risk management for cloud and application security, conducting assessments and ensuring compliance for a financial services firm.Requires 5+ years of experience. Show more

 • Promoted

SOC Senior Analyst

CynergyIQ GroupMontreal (administrative region), QC, CA
Full-time

You will join a team dedicated to providing incident detection, management, and response services for mid-market and enterprise clients, leveraging advanced detection tools such as XDR solutions an... Show more

 • Promoted

Senior Application Security Specialist

EXFOMontreal
Full-time

A leading telecom solutions provider is seeking an experienced Application Security Specialist in Montreal, Canada.This role focuses on driving application security strategies, performing risk asse... Show more

 • Promoted

Senior Analyst, Security Compliance

P2PMontreal (administrative region), QC, CA
Full-time

Our Krakenites are a world-class team with crypto conviction, united by our desire to discover and unlock the potential of crypto and blockchain technology.Kraken is a mission-focused company roote... Show more

 • Promoted

Remote Security Architect - Cloud & App Security Lead

AGFA HealthCareMontreal (administrative region), QC, CA
Remote
Full-time

A healthcare technology company is seeking an experienced Security Architect responsible for designing and implementing security within their architecture.The role involves collaborating with cross... Show more

 • Promoted

Senior Security Engineer at Confluence Montreal

Confluencemontreal (administrative region), qc, Canada
Full-time

Shape the future of security at Confluence in Montreal as a Senior Security Engineer.Focus on vulnerability remediation and improve security practices across IT infrastructure.In this pivotal role,... Show more

 • Promoted

Information Security Manager, Mergers & Acquisitions

WSP in Canadamontreal (administrative region), qc, Canada
Full-time

What if you could redefine what’s possible? With us, you can.We are the home of ambitious, passionate, and innovative world shapers.With an unmatched breadth and depth of engineering, advisory and ... Show more

 • Promoted

Security Engineer

LanceSoft, Inc.Montreal, Montreal (administrative region), CA
Full-time

Direct message the job poster from LanceSoft, Inc.Needs local as in-person is Mandate for the role.Privileged Access Management Senior Engineer to support implementation, enterprise rollout and ope... Show more