Talent.com
CMHC - SCHL
Senior Specialist, Security Applications (AppSecOps)CMHC - SCHL • Ottawa
Senior Specialist, Security Applications (AppSecOps)

Senior Specialist, Security Applications (AppSecOps)

CMHC - SCHL • Ottawa
2 hours ago
Job type
  • Full-time
  • Permanent
Job description

Job Requisition ID: 12213

Position Status: Permanent Full Time

Position Type: Hybrid

Office Location: Ottawa (ON); Montreal (QC)

Travel Requirement: Limited

Language Designation: Bilingual

Language Skill Levels (Read/Write/Speak): CBC

Security Requirement: Secret

Salary: Our salaries generally range from $ 104,180.28 to $ 130,225.36 and are based on qualifications and experience.

About CMHC

The work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system.

At CMHC, we hold ourselves accountable for our results and support our colleagues in their achievements. We thrive on collaboration, connecting across CMHC and involving the right people to get our work done. Our leadership style is guided by trust, where our leaders favour an adaptive approach based on the needs of their teams.

Join us and be part of a team that's committed to making a real difference and be part of something meaningful.

What’s in it for you

We’ve got the purpose, the people and the perks you need for a fulfilling career. Here’s the comprehensive and generous benefits you get when you’re a permanent employee:

  • Annual Paid vacation.
  • Annual individual performance incentive.
  • Defined benefit pension plan.
  • Comprehensive group insurance plan to support your well-being from day one.
  • Support towards your personal and professional growth with training, mentorship and more.
  • An inclusive workplace culture and environment.
  • While positions at CMHC require some in-office presence, alternative work arrangements may be considered for Indigenous candidates.

Members of the following employment equity deserving groups will be prioritized for this job: Indigenous Peoples

About the role

Join the Technology and Business Transformation team, in the Bilingual Senior Specialist, Application Security. You'll be responsible for designing, governing, and continuously improving the enterprise Application Security (AppSec) program to ensure that applications and software‑delivered services are designed, built, tested, and operated in alignment with the organization’s risk tolerance, security strategy, and regulatory obligations.

The role provides expert‑level advisory services to senior management, architects, and delivery leadership, and is accountable for the effectiveness and outcomes of application security controls across the full Secure Software Development Lifecycle (SSDLC / SDLC), including controls embedded in Agile and DevSecOps delivery models.

Open to internal employees in a Remote position or with a current Hybrid exception living at more than 125 km from a CMHC office.

What you’ll do:

  • Lead and evolve the enterprise Application Security framework, ensuring security requirements are embedded throughout the software development lifecycle and become a core part of how applications are designed, built, tested, and deployed.
  • Establish governance for Secure SDLC and DevSecOps practices, integrating security controls, automated testing, secure coding standards, and risk management directly into day-to-day development workflows.
  • Drive a secure-by-design and secure-by-default culture by providing standards, patterns, and guidance that enable development teams to proactively build security into applications rather than addressing it after deployment.
  • Partner with engineering, platform, and architecture teams to embed application security requirements into Agile delivery models, CI/CD pipelines, development toolchains, cloud-native environments, and third-party integrations.
  • Provide expert guidance on secure design decisions, vulnerability remediation, risk-based control selection, and the adoption of emerging technologies while balancing security, business needs, and delivery velocity.
  • Define and enforce security assurance activities and quality gates—including SAST, DAST, SCA, penetration testing, and code review practices—as integrated components of the software development process.
  • Act as the senior application security advisor and escalation point for complex vulnerabilities, design-level risks, exception requests, and secure software delivery challenges.

What you should have:

  • A bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or an equivalent combination of education and experience.
  • At least 7-10 years of progressive experience in application security, software security, cybersecurity, secure software engineering, or secure software delivery.
  • A proven experience developing and implementing enterprise application security standards, governance frameworks, and security control requirements.
  • A demonstrated success embedding and operationalizing application security within day-to-day software development practices, ensuring security is integrated throughout the SDLC/SSDLC, Agile, DevOps, and DevSecOps delivery processes.
  • A strong expertise partnering with development teams to bake secure-by-design and secure-by-default principles, secure coding standards, and automated security controls into application design, development, testing, deployment, and CI/CD pipelines.
  • Extensive experience leading application security assurance activities, including secure architecture and design reviews, threat modeling, SAST, DAST, SCA, and penetration testing oversight and remediation validation.
  • A proven ability to assess complex application security risks, prioritize remediation efforts, and provide risk-based guidance to senior leaders, architects, engineers, and delivery teams.
  • Excellent communication, influencing, and stakeholder management skills, with the ability to translate complex technical risks into business-impact terms, drive adoption of secure development practices, and deliver results in complex, evolving environments.

Technical requirements:

  • A deep expertise in application security principles, secure coding practices, and common application attack techniques.
  • A strong understanding of modern development approaches, CI/CD pipelines, and cloud‑native application architectures.
  • The ability to interpret and apply recognized security frameworks and standards (e.g. ISO 27001/27002, NIST, ITSG‑33) in an application security context.

Professional certifications:

One or more relevant security certifications required or strongly preferred, such as:

  • CSSLP (Certified Secure Software Lifecycle Professional).
  • CISSP (Certified Information Systems Security Professional).
  • GIAC application or software security–related certification.
  • Another recognized application security or secure software development certification.
  • Cloud security or DevSecOps‑related certifications are considered an asset.

Posting closing date: Note, the competition will remain active until filled.

Our commitment to diversity, equity, and inclusion

We’re committed to employment equity and encourage women, Indigenous Peoples, persons with disabilities, veterans and persons of all races, ethnicities, religions, abilities, sexual orientations, and gender identities and expressions to apply. We also welcome applications from non-Canadians who are eligible to work in Canada.

CMHC is an inclusive workplace where diversity of thought – and of people – are recognized, valued, and considered essential to achieving our mission.

Learn more about our commitment to diversity and inclusion

What happens after you apply

We know that applying for a new job can be both exciting and daunting, and we appreciate your effort. Learn more about our hiring process. If you are selected for an interview or testing, please advise us if you require an accommodation.

If you applied before and you were not successful don’t worry – we're always posting new positions, so don’t hesitate to give it another shot. We’re excited to see what you bring to the table this time around!

Create a job alert for this search

Senior Specialist, Security Applications (AppSecOps) • Ottawa

Similar jobs

Senior Security Engineer Focused on Detection and Response Frameworks

1PasswordOttawa, ON, CA
Full-time

Join as a Senior Security Engineer to strengthen detection and incident response frameworks.Lead initiatives that optimize security measures and enhance organizational resilience in a remote enviro... Show more

 • Promoted

Remote Security Architect - Cloud & App Security Lead

AGFA HealthCareOttawa, ON, CA
Remote
Full-time

A healthcare technology company is seeking an experienced Security Architect responsible for designing and implementing security within their architecture.The role involves collaborating with cross... Show more

 • Promoted

Senior Solutions Architect, National Security & Defence

Amazon Web Services (AWS)Ottawa, ON, CA
Full-time

Amazon Web Services (AWS) is looking for a highly skilled and motivated Solutions Architect to help design and deliver advanced cloud computing solutions to Canadian National Security & Defence (NS... Show more

 • Promoted

Cyber Security Analyst

Searidge TechnologiesOttawa, ON, CA
Temporary

Fixed-Term Contract (6-months).Searidge Technologies is a global leader in the Air Traffic Control space, boldly forging new paths bringing innovative technology, such as Artificial Intelligence (A... Show more

 • Promoted

Senior Security Operations Engineer

CohereOttawa, ON, CA
Full-time

Our mission is to scale intelligence to serve humanity.We’re training and deploying frontier models for developers and enterprises who are building AI systems to power magical experiences like cont... Show more

 • Promoted

Senior SecOps Engineer - Cloud Security & Automation

CohereOttawa, ON, CA
Full-time

A leading AI research company in Montreal is seeking a Senior Security Operations Engineer to enhance its cloud security efforts.You will manage security protocols, respond to incidents, and work o... Show more

 • Promoted

Senior Security Engineer Enhancing Product Integrity and Safety

AffirmOttawa, ON, CA
Full-time

Become a pivotal force in product security as a Senior Product Security Engineer.Engage in cross-functional collaboration to improve the security of innovative financial products in a remote role.T... Show more

 • Promoted

Senior Threat Detection & Response Engineer

1PasswordOttawa, ON, CA
Full-time

A leading cybersecurity company in Canada seeks a Senior Security Engineer to enhance threat detection and response capabilities.You will design systems for threat detection, lead incident response... Show more

 • Promoted

Strategic Information Security Architect

ColliersOttawa, ON, CA
Full-time

Transform global security architecture as a Strategic Information Security Architect.Spearhead cloud migration security strategies while ensuring systems are secure and compliant.This pivotal role ... Show more

 • Promoted

Senior IT Security Design Specialist

Adga-GroupOttawa, ON, CA
Full-time

Compensation: CAD 110 - CAD 120 - hourly.ADGA Group is a Canadian‑owned defence and security company that provides integrated, mission‑critical technical solutions to Government and industry, speci... Show more

 • Promoted

Remote Cloud Security Architect: DevSecOps & Risk Leader

Intuitive.aiOttawa, ON, CA
Remote
Full-time

A leading cybersecurity solutions company is seeking a Cybersecurity Specialist (GCP) to enhance their Cybersecurity Program.The role involves developing comprehensive security strategies in cloud ... Show more

 • Promoted

Senior Product Manager, Physical Security Systems

House of Commons of Canada Chambre des communes du CanadaOttawa, ON, CA
Full-time

A government organization in Canada is seeking a Senior Product Manager to lead the management and delivery of physical security systems.You will collaborate with stakeholders to define strategies ... Show more

 • Promoted

Renewals Specialist - Cyber Security (Mid-Enterprise)

FortinetOttawa, ON, CA
Full-time

A cybersecurity company located in Canada seeks a Renewal Sales Representative to manage the full Renewal Sales cycle.The ideal candidate will assist customers with license renewals, handle inquiri... Show more

 • Promoted

Security Systems Application Specialist

AinsworthOttawa, ON, CA
Full-time

If you thrive in a team-oriented workplace that challenges your skills, to drive your career development, embraces diversity and rewards innovation, with competitive pay and great employee programs... Show more

 • Promoted

Senior Project Manager - Public Sector & Cyber Security (Secret Clearance)

TecTamminaOttawa, ON, CA
Full-time

A leading consulting firm in Ottawa, Canada is seeking a Project Manager with strong experience in Public Sector projects.The candidate must have government secret clearance and ideally has deliver... Show more

 • Promoted

Senior DevOps Engineer: Cloud, Security & AI-Ready

Nuclear Promise XOttawa, ON, CA
Full-time

A leading nuclear innovation firm in Canada is seeking a Senior DevOps Developer to design and maintain secure cloud infrastructure.The role involves optimizing CI/CD pipelines and managing contain... Show more

 • Promoted

Senior Analyst, Security Compliance

P2POttawa, ON, CA
Full-time

Our Krakenites are a world-class team with crypto conviction, united by our desire to discover and unlock the potential of crypto and blockchain technology.Kraken is a mission-focused company roote... Show more

 • Promoted

Remote Security & DevOps Engineer for SaaS/IoT Cloud

KeycafeOttawa, ON, CA
Remote
Full-time

A leading technology firm in Canada is seeking a passionate Security & DevOps Engineer to enhance its cloud environments and ensure high security across its global IoT platform.You'll manage applic... Show more

 • Promoted

Senior DevSecOps Engineer – Blockchain & Cloud Security

FigmentOttawa, ON, CA
Full-time

A leading blockchain infrastructure provider in Canada seeks a Senior DevOps Engineer to enhance security and scalability in blockchain systems.This remote-first role requires strong expertise in D... Show more

 • Promoted

Security Architect & Strategy Lead (SECOPS)

nugget.aiMississauga, Ottawa, Toronto
Full-time

A leading technology firm is seeking a Lead Security Analyst responsible for securing applications and infrastructure while shaping technology strategy across the organization.The role entails coll... Show more