Job descriptionJob Title Senior Full Stack Security Developer
Overview Join our innovative PayEdge Technology team at RBC, where we are building the security foundation for accounts payable and accounts receivable solutions. As a Full Stack Security Developer, you will design, develop, and implement secure application systems that protect critical financial transactions. You will embed security across the technology stack—from architecture and code review to deployment and ongoing threat mitigation—applying advanced security knowledge, best practices, and risk assessment methodologies to ensure compliance with industry standards and regulatory requirements. If you are a security‑mindful developer with a strong technical foundation and proven expertise in secure coding practices, we invite you to help build the future of secure payments.
Responsibilities
Lead application security reviews, threat modeling, and code reviews to identify and mitigate vulnerabilities before they reach production.
Own application security vulnerability management from discovery through remediation and validation.
Design and implement automated security testing frameworks to enforce secure coding practices across the development lifecycle.
Manage security release cycles and coordinate security patches across the organization.
Support compliance and regulatory processes, including PCI certification, penetration testing, and annual security assessments.
Identify and recommend security improvements to strengthen application security posture.
Mentor development and security teams through targeted training and knowledge‑sharing initiatives.
Collaborate across multiple departments and stakeholders to integrate security into agile project workflows.
Champion security best practices as a trusted technical advisor.
Required Qualifications
Bachelor’s degree in Computer Science, Engineering, or related field.
5+ years’ experience with Laravel, PHP, JavaScript, HTML, CSS, and Angular.
5+ years’ experience with Java and Spring Boot.
5+ years’ experience with RDBMS (MySQL, MSSQL), NoSQL (MongoDB), ELK, and data streaming technologies (Kafka).
Expertise in OWASP, static/dynamic analysis, and security tools such as Burp Suite and OWASP Zap.
Strong skill in secure code review and remediation guidance.
Knowledge of API security, authentication/authorization (OAuth2, JWT, OpenID Connect).
Understanding of secrets management and secure configuration practices.
Experience with CI/CD pipelines (Jenkins, GitHub, Vault, security scanning tools).
Familiarity with threat modeling methodologies (Stride, Pasta).
Ability to work in an Agile environment.
Excellent written and verbal communication skills.
Nice‑to‑Have Qualifications
Familiarity with major architectural styles, such as Microservices, React or Event‑driven systems.
Strong knowledge of Microservices architecture and API integration.
Experience using AI‑assisted development tools (GitHub Copilot, Windsurf, Claude Code) to improve productivity and quality.
Ability to design and build AI‑enabled security tools, such as automated vulnerability triage and remediation suggestions; AI‑driven threat modeling assistants; intelligent code analysis and risk‑scoring systems.
Background in penetration testing or red teaming.
Knowledge of Azure and OpenShift container platform.
Knowledge of AI security risk.
CISSP certification.
Benefits
A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable.
Leaders who support your development through coaching and managing opportunities.
Ability to make a difference and lasting impact.
Work in a dynamic, collaborative, progressive, and high‑performing team.
A world‑class training program in financial services.
Flexible work/life balance options.
Opportunities to do challenging work.
#J-18808-Ljbffr