Talent.com
Croesus
Application Security AnalystCroesus • Laval, Canada
Application Security Analyst

Application Security Analyst

Croesus • Laval, Canada
1 day ago
Job type
  • Full-time
Job description

Croesus provides innovative, high-performance, and secure wealth management solutions that include portfolio management systems, portfolio rebalancing tools, and application programming interfaces (APIs). These solutions empower wealth management professionals to improve their productivity, enhance their client relationships, make informed decisions, and maximize the management of their assets under management.


Croesus’s mission is to provide a superior experience to its clients, users, partners, and employees and to positively impact the community. With more than 200 employees in its Montréal, Toronto, and Geneva offices, Croesus has won several industry awards for being a high-quality solution provider and an outstanding employer.


As a member of the information security team, you serve as the strategic bridge between development and cybersecurity. Your role is to integrate security from the earliest stages of software design (“security by design”) and to turn technical constraints into drivers of excellence. As a hands-on expert, you support teams in effectively addressing vulnerabilities and fostering a culture of security. You also serve as the internal point of contact for the security of the artificial intelligence components integrated into our SaaS products.

Main Responsabilities:

Vulnerability Management and Triage

  • Classify vulnerabilities based on actual risk by correlating severity scores with business impact.
  • Support product managers in prioritizing fixes within development backlogs.
  • Oversee remediation using key performance indicators and validate the robustness of fixes.

Secure Architecture and Development

  • Conduct critical code reviews for C#, C++, Python, and web environments.
  • Secure data processing chains.
  • Get involved as early as the design phase through threat modeling. Extend this practice to AI components and agent-based architectures integrated into our products (RAG, autonomous agents, MCP integrations).

Security of AI Components in Products

  • Assess the security of integrations between our products and third-party AI models.
  • Apply the OWASP LLM Top 10 framework during code reviews and threat modeling exercises.
  • Define, in collaboration with development and DevOps teams, the application controls governing the use of generative AI in products: secret management for third-party model APIs, input and output validation, server-side controls on prompts, and checkpoints in CI/CD pipelines.
  • Evolve internal secure development standards for AI components.
  • Assess risks specific to the agent-based architectures integrated into our products: indirect prompt injection (RAG), excessive agency, tool poisoning, and MCP integration security.

Leadership: Security Champions Program

  • Lead the Champions Guild across various functional areas.
  • Organize knowledge transfer through workshops, simulation exercises, and training sessions.
  • Provide personalized technical mentoring to security champions.

Security Automation and Integration

  • Maintain automated security checks in continuous integration and continuous deployment (CI/CD) pipelines.
  • Evaluate, deploy, and refine static and dynamic analysis (SAST, DAST), software composition analysis (SCA), and secret detection tools, ensuring a good balance between coverage, false positive rates, and developer experience.


All internal meetings at Croesus are conducted in French, so a strong proficiency in French is mandatory.

  • Overall experience: Minimum 5 years in information technology.
  • Domain expertise: Minimum 2 years in software development and 3 years in application security.
  • Education: Degree in computer science. A specialization or additional training in security is a major asset
  • Development & Code
  • Advanced proficiency: C#, C++, and Python (AI and data).
  • Web Security: Proficiency with modern development frameworks (TS/JS) and defense against common attacks.
  • Security Methodologies: Static and dynamic analysis, software composition analysis.
  • Automation: Integration of automated security controls into deployment pipelines.
  • Risk Analysis: Translation of technical vulnerabilities into understandable business risks


Why join Croesus ?

  • À la carte vacations
  • Annual salary + Corporate profit-sharing plan
  • Hybrid work, 2 days a week in office (Laval &Montreal offices)
  • Sports program
  • Gym available at our Laval head office
  • Telemedicine + group insurance (super useful for the family 😉 )
  • Group RRSP
  • Proximity to Montmorency & Mcgill metro
  • Ongoing training and development plan
  • Referral bonus
  • Indoor and outdoor parking & electric car recharging
  • Croesus boutique
  • Beautifully renovated and spacious office
  • Complimentary breakfast every morning
  • 2X per month, Happy hours, prepared by our Croesus Life Partner


Are you interested in this challenge? Do you believe you have the qualities and expertise required for this position? Please complete your application today.


Although all applications are carefully analyzed, we will communicate only with those selected. Thank you for your interest in Croesus.

Create a job alert for this search

Application Security Analyst • Laval, Canada

Similar jobs

Contract Security Analyst for Cyber Defense

Fluid - Solutions de Talents/Workforce SolutionsMontreal
Full-time

Strengthen our cybersecurity initiatives as a Security Analyst.Focus on optimizing threat detection systems, endpoint security configuration, and vulnerability management across critical platforms ... Show more

 • Promoted

Technical PM – Application Security for Banking (Montreal)

Trigyn TechnologiesMontreal
Full-time

A major IT solutions provider is seeking a Technical Project Manager for a contract position in Montreal.This role involves managing security testing engagements and liaising with various stakehold... Show more

 • Promoted

Sailpoint Security Analyst – Hybrid, Montréal

CHROME TECHNOLOGIESMontreal, Montreal (administrative region), CA
Full-time

Une entreprise technologique spécialisée à Montréal recherche un Analyste en sécurité spécialisé dans Sailpoint pour rejoindre son équipe.Le poste, en mode hybride, implique la gestion opérationnel... Show more

 • Promoted

Application Security Specialist.

EXFOMontreal
Full-time

EXFO develops smarter network test, monitoring, and analytics solutions for the world’s leading telecommunications service providers, network equipment manufacturers, and web-scale companies—and we... Show more

 • Promoted

Senior Application Security Engineer

Crypto Pro NetworkMontreal (administrative region), QC, CA
Full-time

Web3 through industry-leading blockchain infrastructure.As the leading provider of staking solutions,.Our clients trust Figment for a comprehensive suite of services, including.Backed by a team of ... Show more

 • Promoted

MONTREAL [Hybrid] - CSIRT Security Analyst Level 2 - montréal

QUANTEAM (Groupe RAINBOW PARTNERS)montréal, qc, ca
Full-time

As the founding entity of RAINBOW PARTNERS, Quanteam is a consulting firm specializing in Banking, Finance, and Financial Services.Guided by our core values of closeness, teamwork, diversity, and e... Show more

 • Promoted

Security Analyst (SOC)

Bedard ResourcesLaval (administrative region), QC, CA
Full-time

Our client is looking for a Junior Cybersecurity Analyst to assist with the daily management of a simulation platform, support the onboarding of new clients, and contribute to analyses related to a... Show more

 • Promoted

Lead application security analyst

National BankMontreal, Montreal (administrative region), CA
Full-time

A career as a DevSecOps lead on the Asset Protection team at National Bank means serving as a specialist in application security, vulnerability management and DevSecOps practises.This position allo... Show more

 • Promoted

Security Analyst- PCSIRT L3

CoFoMo Inc.Montreal
Full-time

Responsabilités (FR)Analyser et surveiller les journaux de sécurité provenant de multiples sources et dispositifsDévelopper et valider des cas d’usage liés à la détection des menacesMettre en place... Show more

 • Promoted

Security Analyst

AltanoraMontréal, Canada
Full-time

The Security Analyst is responsible for designing and implementing incident prevention and detection solutions, analyzing and prioritizing vulnerabilities, administering security tools, and support... Show more

 • Promoted

Analyste en Sécurité des Applications chez Wawanesa

Wawanesa InsuranceMontreal (administrative region), QC, CA
Full-time

Devenez Analyste en Sécurité des Applications chez Wawanesa et contribuez à la défense des systèmes d’information.Ce poste hybride requiert des compétences pratiques et une passion pour la sécurité... Show more

 • Promoted

Information Security Analyst

KinaxisMontreal
Full-time

Kinaxis is a global leader in modern supply chain orchestration, empowering complex global supply chains with an AI‑infused platform that delivers full transparency and visibility.With more than 40... Show more

 • Promoted

Lead Application Security Analyst

National Bank of CanadaMontreal (administrative region), QC, CA
Full-time

A career as a DevSecOps lead on the Asset Protection team at National Bank means serving as a specialist in application security, vulnerability management and DevSecOps practises.This position allo... Show more

 • Promoted

Application Security Engineer

HireTalent - Staffing & Recruiting FirmMontreal, Montreal (administrative region), CA
Full-time

Information Security Engineer II.Application Security is looking to recertify all third-party connections in compliance with in-transit encryption requirements.We are seeking 2 Cyber Security exper... Show more

 • Promoted

Security Analyst

Frey Consulting GroupLaval
Full-time

Monitor, triage, and investigate security alerts across platforms including SentinelOne (Vigilance), Field Effect Complete, Microsoft Defender, and ThreatLocker;.Correlate events across multiple to... Show more

 • Promoted

Security Analyst

Prosperity Workforce SolutionsMontreal (administrative region), QC, CA
Temporary

We are seeking a highly skilled.This temporary position will focus on fine-tuning threat detection models, ensuring best practices in endpoint protection, and improving the utilization of our secur... Show more

 • Promoted

Principal Security Analyst - Remote

CyderesMontreal (administrative region), QC, CA
Remote
Full-time

Be among the first 25 applicants.Cyderes (Cyber Defense and Response) is a pure-play, full life-cycle cybersecurity services provider with award-winning managed security services, identity and acce... Show more

 • Promoted

Lead Application Security Manager at Workleap

ShareGateMontreal (administrative region), QC, CA
Full-time

Take the lead as an Application Security Manager at Workleap, focusing on security integration in Microsoft 365 products.Your coding and security skills will be key to our innovative solutions.In t... Show more

 • Promoted

Cyber Security Analyst

Groupe DynamiteMount Royal, Montreal (administrative region), CA
Full-time

GDI) is a Montréal-based, public company of integrated omni-channel brands, designing and distributing accessible, trend-forward fashion for women since 1975.Our mission of "Empowering YOU to be YO... Show more

 • Promoted

Advanced SOC Analyst for Threat Detection

ALTER SOLUTIONSMontreal
Full-time

Enhance cybersecurity defenses as an Advanced SOC Analyst with our team.Lead threat detection and incident response initiatives while working to protect valuable assets.We are seeking a skilled L3 ... Show more