Talent.com
Manulife
Senior Application Security SpecialistManulife • Toronto, Ontario, Canada
Senior Application Security Specialist

Senior Application Security Specialist

Manulife • Toronto, Ontario, Canada
26 days ago
Salary
CA$163.00 daily
Job type
  • Full-time
Job description

Manulife is a leading international financial services provider helping people make decisions easier and lives better. Help shape the future you want to see and discover that better can take you anywhere you want to go.

We are seeking an experienced Senior Application Security Specialist to join our team. The successful candidate will play a critical role in establishing and maintaining our security and risk governance frameworks. This role involves monitoring threats assessing vulnerabilities and ensuring compliance with organizations standards and regulatory requirements.

Position Responsibilities

  • Perform code scanning validation tuning and optimization using SAST DAST and SCA tools (e.g. Snyk Burp Suite SonarQube Veracode and Checkmarx) to ensure accurate prioritized and actionable remediation results.

  • Conduct penetration testing code scanning secrets management (GitGuardian) and threat modeling for business applications to determine risk ratings and prioritize the vulnerabilities discovered along with the organizations remediation timelines.

  • Execute intake triage analysis and reporting procedures for security assessments.

  • Experience working with code repositories such as GitHub and with CI/CD pipelines in Azure DevOps.

  • Coordinate assessment and risk analysis activities evaluate governance processes and recommend improvement opportunities.

  • Supports establishment development and maintenance of risk governance frameworks risk assessment methodologies risk metrics reporting and risk management compliance protocols.

  • Conduct vulnerability assessments and prioritize remediation activities in collaboration with stakeholders.

  • Document findings and collaborate with cross-functional teams to implement corrective actions.

  • Work closely with senior security engineers product partners architects and crossfunctional teams in Agile/DevOps environments.

  • Communicate risk and compliance assessments and recommendations to business units and senior management.

  • Lead and participate in meetings to review outstanding vulnerabilities and clarify business and technical impacts.

  • Develop and report actionable KPIs and KRIs aligned with application security policies and standards.

  • Analyze cyber defense policies for compliance with regulations and organizational standards.

  • Lead meetings to analyze risk indicators and develop executive-level dashboards.

  • Maintain comprehensive documentation of governance processes and contribute to policy updates.

  • Stay updated on evolving cybersecurity threats and contribute to enhancing risk reporting processes.

  • Provide professional advice and take a lead role in process or program execution.

  • Be accountable for own work and contribute to setting standards through expertise in own job discipline that impacts other deliverables.

Required Qualifications

  • Strong understanding of information security controls vulnerability management and risk management frameworks (NIST CSF ISO 27001/27002).

  • Experience working with Cloud technologies (Azure AWS Ali Cloud)

  • Knowledge of cybersecurity principles internal controls and risk management tools.

  • Proficiency in data visualization tools (Tableau Power BI) and statistical data analysis.

  • Handson experience with tools such as JIRA Confluence and Microsoft 365.

  • Experience with cybersecurity assessment frameworks (PTES OWASP OSSTM) and penetration testing.

  • Understanding of legal and regulatory requirements related to cybersecurity and IT governance.

  • Excellent communication skills to effectively convey risk assessments and security recommendations.

  • Knowledge of ticketing and tracking tools such as ServiceNow Security Operations GRC systems like Archer.

  • Understanding of legal and regulatory requirements related to technology risk management Familiarity with cybersecurity governance frameworks and their implementation

  • Knowledge of statistical data analysis and reporting toolsets

  • In-depth knowledge of risk assessment methodologies and risk management frameworks.

  • Proficiency in using risk assessment tools and software.

Preferred Qualifications

  • CISSP CSSLP OSCP GWAPT or equivalent industry-recognized security certifications.

    Cybersecurity Security Monitoring

    Vulnerability Assessment Penetration Testing

    Threat Modeling Security Assessment Security Testing

    Cyber Threat Intelligence

When You Join Our Team

  • Well empower you to learn and grow the career you want.

  • Well recognize and support you in a flexible environment where wellbeing and inclusion are more than just words.

  • As part of our global team well support you in shaping the future you want to see.

The role being advertised is an existing vacancy.

About Manulife and John Hancock

Manulife Financial Corporation is a leading international financial services provider helping people make their decisions easier and lives better. To learn more about us visit is an Equal Opportunity Employer

At Manulife/John Hancock we embrace our diversity. We strive to attract develop and retain a workforce that is as diverse as the customers we serve and to foster an inclusive work environment that embraces the strength of cultures and individuals. We are committed to fair recruitment retention advancement and compensation and we administer all of our practices and programs without discrimination on the basis of race ancestry place of origin colour ethnic origin citizenship religion or religious beliefs creed sex (including pregnancy and pregnancy-related conditions) sexual orientation genetic characteristics veteran status gender identity gender expression age marital status family status disability or any other ground protected by applicable law.

It is our priority to remove barriers to provide equal access to employment. A Human Resources representative will work with applicants who request a reasonable accommodation during the application process. All information shared during the accommodation request process will be stored and used in a manner that is consistent with applicable laws and Manulife/John Hancock policies. To request a reasonable accommodation in the application process contact .

Referenced Salary Location

Toronto Ontario

Working Arrangement

Hybrid

Salary range is expected to be between

$113000.00 CAD - $163000.00 CAD

Employees also have the opportunity to participate in incentive programs and earn incentive compensation tied to business and individual performance. The actual salary will vary depending on local market conditions geography and relevant job-related factors such as knowledge skills qualifications experience and education/training. If you are applying for this role outside of the primary location please contact for the salary range for your location.

Manulife offers eligible employees a wide array of customizable benefits including health dental mental health vision short- and long-term disability life and AD&D insurance coverage adoption/surrogacy and wellness benefits and employee/family assistance plans. We also offer eligible employees various retirement savings plans (including pension and a global share ownership plan with employer matching contributions) and financial education and counseling resources. Our generous paid time off program in Canada includes holidays vacation personal and sick days and we offer the full range of statutory leaves of absence. If you are applying for this role in the U.S. please contact for more information about U.S.-specific paid time off provisions.

We use data and analytics technologies such as artificial intelligence (AI) and automated processing tools to analyze and process the information you provide to us or third parties in the application process. For more information please refer to our personal information collection statement.


Required Experience:

Senior IC


Key Skills
Computer Hardware,Mac Os,Manufacturing & Controls,Root cause Analysis,Windows,Customer Support,Remote Access Software,Operating Systems,Encryption,Remedy,Chemistry,Cerner
Employment Type : Full-Time
Experience: years
Vacancy: 1
Create a job alert for this search

Senior Application Security Specialist • Toronto, Ontario, Canada

Similar jobs

Senior Application Security Engineer - C$192,000 - C$240,000 A Year

BrexToronto County, Canada
Full-time

Seeking a Senior Application Security Engineer to identify and respond to security vulnerabilities across the Brex platform.Responsibilities include code reviews, penetration testing, and developin... Show more

 • Promoted

AWS Security Architect

Venterra Realtyrichmond hill, york region, Canada
Full-time

Hybrid / Corporate Office in Richmond Hill, Ontario.Salary: $130,000 - $170,000; up to 10% discretionary incentive target*.This position is designed for a senior‑level subject matter expert (SME) w... Show more

 • Promoted

Application Security Software Engineer

PointClickCareToronto, ON, CA
Full-time

This range is provided by PointClickCare.Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.PointClickCare is a leading North American healthcare t... Show more

 • Promoted

Senior Application Security Developer - C$146,200 - C$197,800 A Year

ClioNorth York, Canada
Full-time

Develops and implements security tools, remediates vulnerabilities, and provides guidance to teams, ensuring application security. Show more

 • Promoted

Senior Application Security Engineer

CognizantToronto, ON, CA
Full-time

Job Title - App Security Specialist.DevOps, with at least 2 - 3 years hands-on security exposure (secure coding, pipeline security, API security, threat modeling).Seniority level: Mid-Senior level.... Show more

 • Promoted

Application Security, Lead - C$120,000 - C$140,000 A Year

InteracNorth York, Canada
Full-time

Leads application security, builds security strategies, integrates tools, and communicates with stakeholders. Show more

 • Promoted

Intact Senior Security Specialist

IntactToronto, ON, CA
Full-time

Join Intact as a Senior Security Advisor, focusing on Vault management and security architecture.Utilize your expertise in AWS and GCP to drive security strategies.You will manage the deployment an... Show more

 • Promoted

Senior Application Security Engineer

HelloFreshtoronto, on, Canada
Full-time

We're looking for a new teammate to join us on the journey of keeping HelloFresh a trusted name - someone with a passion for security and appetite for new challenges.Security Engineers work in a va... Show more

 • Promoted

Applications Security Architect

Ward Technology TalentToronto, ON, CA
Full-time

Applications Security Architect – CONTRACT – (2-3 days per week).Application Security Architect.Onsite is required once every 2 weeks in GTA by Toronto Airport.Perform security assessments on new p... Show more

 • Promoted

Security Implementation SME - Azure and Palo Alto

Tech Talent InternationalToronto, ON, CA
Full-time

Security Implementation SME - Azure and Palo Alto.Job Openings Security Implementation SME - Azure and Palo Alto.About the job Security Implementation SME - Azure and Palo Alto.Fortune 100/500/1000... Show more

 • Promoted

Senior Application Security Specialist

AIR MILES Reward ProgramToronto, Ontario, Canada
Full-time

The AIR MILES Reward Program is one of Canada’s most recognized loyalty programs, with over 10 million active collector accounts, representing more than half of all Canadian households.AIR MILES co... Show more

 • Promoted

Senior Specialist Application Security - $122,305 - $163,639 A Year

ipss inc.Toronto County, Canada
Full-time

This role provides strategic and operational guidance for application security, enhancing cloud-native security and integrating DevSecOps. Show more

 • Promoted

Senior Security Engineer, Application & Platform Security - $180,000 - $280,000 A Year

SentryNorth York, Canada
Full-time

Senior Security Engineer to secure Sentry's cloud-based applications and Kubernetes platform, driving security solutions, and collaborating with engineering teams. Show more

 • Promoted

Penetration Testing & Application Security Consultant

Rsm Us Llp.Toronto, ON, CA
Full-time

A leading professional services firm in Toronto is seeking a Security Analyst with expertise in web security.The role involves performing security assessments, conducting penetration testing, and c... Show more

 • Promoted

Security Systems Application Specialist

AinsworthToronto
Full-time

Reporting to the Project Manager, you will have the opportunity to execute and lead various security system projects.Your role will encompass estimation, engineering design, programming, commission... Show more

 • Promoted

Lead Application Security Engineer

NasdaqToronto, Ontario, Canada
Full-time

As a Lead, Information Security reporting to Senior Director, Information Security, you'll serve as the primary point of contact for information security across a major cloud-based technology proje... Show more

 • Promoted

Senior Application Security Engineer: Ci/Cd & Tooling - C$146,200 - C$197,800 A Year

Themis Solutions Inc.Toronto County, Canada
Full-time

Develop security tools and advise on best practices at a legal tech company. Show more

 • Promoted

Senior Application Security Engineer - C$131,500 - C$155,000 A Year

Spring FinancialNorth York, Canada
Full-time

Senior Application Security Engineer responsible for leading technical efforts to secure software systems, embedding security best practices, and mentoring engineers.Focuses on secure development l... Show more

 • Promoted

Senior Application Security Engineer - C$140,000 - C$160,000 A Year - Remote

FigmentEast York, Canada
Remote
Full-time

Seeking a Senior Application Security Engineer to conduct security testing, identify vulnerabilities, and develop attack strategies for Web3 blockchain infrastructure.Requires expertise in modern w... Show more

 • Promoted

Application Security Engineer

Segment (Twilio)Toronto, ON, CA
Full-time

Deep conviction that AI and automation should eliminate manual work humans shouldn't be doing anyway.You're excited to replace developer toil and reactive vuln triage with automated systems, guardr... Show more