Talent.com
Marsh
Senior Specialist - IT Security (Dev Sec Ops)Marsh • Montreal (administrative region), QC, Canada
Senior Specialist - IT Security (Dev Sec Ops)

Senior Specialist - IT Security (Dev Sec Ops)

Marsh • Montreal (administrative region), QC, Canada
14 days ago
Salary
CA$126,000.00 yearly
Job type
  • Full-time
Job description

DevSecOps & Secure-SDLC Engineer

Lead initiatives related to DevSecOps and Secure-SDLC.

Enhance the company’s Secure Software development Liability (Secure-Business) (Secure-Business) which in turn will reflect the company’s Application Development Security Policy,

Select and standardize application security tools. This includes vendor/tool assessments and full POC,

Integrate Secure-SDLC requirements and other security policy/requirements into the DevSecOps processes,

Define and enhance application security requirements and standards which must be designed for agile development methods leveraging traditional application architectures as well as cloud architectures and container workloads.

What can you expect?

  • Lead initiatives related to DevSecOps and Secure-SDLC.
  • Enhance the company’s Secure Software development Lifecycle (Secure-SDLC) which in turn will reflect the company’s Application Development Security Policy,
  • Select and standardize application security tools. This includes vendor/tool assessments and full POC,
  • Integrate Secure-SDLC requirements and other security policy/requirements into the DevSecOps processes,
  • Define and enhance application security requirements and standards which must be designed for agile development methods leveraging traditional application architectures as well as cloud architectures and container workloads.

We will count on you to:

  • Advise the application security leadership on best practices and standards around application security tools with main focus on shift-left, create predictable CI/CD pipeline processes, and enable application teams to develop new capabilities securely, and free from security defects, by design
  • Assess security tools and related processes currently used within the various Software Development Life Cycle processes to identify improvements opportunities, and rationalize the tools set
  • Select new application security tools including vendor/tool assessments and conduct full POC to prove that the security solutions/products are fit-for-purpose and fit-for-use
  • Draft documentations for the Secure-SDLC and DevSecOps to illustrate the frameworks and its process guidelines to internal customers ensuring the style is palatable and easy to navigate
  • Assess impact of new publications from the security industry (e.g. NIST 800-XXX, ISO 2700X:2022, etc) on the company’s AppSec programs
  • Research new trends and advise the application security leaderships on impact of the new trends as they relate to currently used tools, tool chain roadmap, efficiency and effectiveness of current processes, etc.
  • Promote secure coding standard and all related processes
  • Promote the priorities set forth by Global Information Security function, and the roadmap set forth by the Global Application Security
  • Automate and integrate security scan and analysis tools into the DevSecOps pipeline

What you need to have:

  • 5 years+ DevSecOps and Secure-SDLC work experience
  • CISSP, CSSLP, cloud security, DevSecOps automation, or similar is required
  • Post‑secondary education or equivalent experience as a DevSecOps Engineer
  • Develop/enhance and implement the Secure‑SDLC framework
  • Design, implement, and rollout DevSecOps automations and tool chain
  • Implement sensors to collect data on key metrics for statistics and reporting
  • Serve as the subject matter expert in Secure‑SDLC and DevSecOps
  • Advise on the processes and standards that are designed to implement a company’s Application Development Security Policy
  • Experience in designing Secure‑SDLC processes and relevant tooling to support the processes
  • Experience in software/application analysis tools like SAST, DAST, SCA, threat modeling, supply‑chain etc.
  • Technical hands‑on experience in automating and integrating security scan and analysis tools into the DevSecOps pipeline.
  • Experience in one or more programming languages
  • Familiarity with security frameworks (OWASP Top 10, SANS Top 25, CWE)

What makes you stand out:

  • Identify application security requirements and brainstorm solutions factoring in industry best practices
  • Assess the tooling and remediation of threats and vulnerabilities within our software/applications, and the hosting environment

Marsh (NYSE: MRSH) is a global leader in risk, reinsurance and capital, people and investments, and management consulting, advising clients in 130 countries. With annual revenue of over $27 billion and more than 95,000 colleagues, Marsh helps build the confidence to thrive through the power of perspective. For more information, visit corporate.marsh.com, or follow us on LinkedIn and X.

Marsh is committed to embracing a diverse, inclusive and flexible work environment. We aim to attract and retain the best people and embrace diversity of age background, disability, ethnic origin, family duties, gender orientation or expression, marital status, nationality, parental status, personal or social status, political affiliation, race, religion and beliefs, sex/gender, sexual orientation or expression, skin color, or any other characteristic protected by applicable law. In accordance with the Accessibility for Ontarians with Disabilities Act, 2005, Marsh will provide a reasonable accommodation to employees and prospective employees to the point of undue hardship upon request and as required in respect of the individual’s particular restrictions and limitations. If you require a specific accommodation because of a disability or medical need, please contact reasonableaccommodations@marsh.com.

Marsh is committed to hybrid work, which includes the flexibility of working remotely and the collaboration, connections and professional development benefits of working together in the office. All Marsh colleagues are expected to be in their local office or working onsite with clients at least three days per week. Office‑based teams will identify at least one “anchor day” per week on which their full team will be together in person.

The applicable base salary range for this role is $126,000 to $176,000.

The base pay offered will be determined on factors such as experience, skills, training, location, certifications, education, and any applicable minimum wage requirements. Decisions will be determined on a case‑by‑case basis. In addition to the base salary, this position may be eligible for performance‑based incentives.

We are excited to offer a competitive total rewards package which includes health and welfare benefits, tuition assistance, retirement programs as well as employee assistance programs.

This is a New position.

#J-18808-Ljbffr
Create a job alert for this search

Senior Specialist - IT Security (Dev Sec Ops) • Montreal (administrative region), QC, Canada

Similar jobs

Senior IT and security Administrator – Malware Protection Specialist

act digitalMontreal (administrative region), QC, CA
Full-time

Senior IT and security Administrator – Malware Protection Specialist.ALTER SOLUTIONS is a consulting and technology expertise company founded in 2006.Our mission is to support our clients with thei... Show more

 • Promoted

IT Security and Operations Leader

Dialogue Technologies Inc.Montreal (administrative region), QC, CA
Full-time

Lead IT security initiatives as an IT Operations & Security Advisor.Focus on advanced support and project management within a flexible hybrid work framework.You will play a crucial role in ensuring... Show more

 • Promoted

Director of IT Security for Directive Consulting

DirectiveMontreal (administrative region), QC, CA
Full-time

Enhance IT security as Director at Directive Consulting.Protect client data and manage risks within a fully remote framework.In this leadership role, you'll report to the Head of Finance and define... Show more

 • Promoted

Senior Security Specialist

CliniaMontreal (administrative region), QC, CA
Full-time

Senior Security Specialist – Clinia.Secure the systems that power digital health.At Clinia, we build the search and data infrastructure that powers digital health.We move with purpose, solve comple... Show more

 • Promoted

SAP Security & IT Compliance Specialist

BRPMontreal (administrative region), QC, CA
Full-time

The SAP Security & Compliance Specialist is responsible for maintaining the integrity, confidentiality, and availability of BRP’s SAP Security landscape while ensuring continuous compliance with co... Show more

 • Promoted

IT Security and Operations Advisor

Portage Ventures GP Inc.Montreal (administrative region), QC, CA
Full-time

Become an IT Security and Operations Advisor at Dialogue, Canada’s foremost virtual health provider.Leverage your skills in operational efficiency and security management while working in a hybrid ... Show more

 • Promoted

Senior IT Infrastructure Administrator, Security

Confluencemontreal (administrative region), qc, Canada
Full-time

Confluence is a global investment data technology organization operating across multiple countries.The Senior Infrastructure Security Engineer works within the IT Infrastructure team and partners c... Show more

 • Promoted

Master Security Specialist

Ericssonmontreal (administrative region), qc, Canada
Full-time

Investigate, support, and/or lead the coordination of product security vulnerabilities, incidents, and urgent security situations in collaboration with Customer Security Directors, customer units, ... Show more

 • Promoted

Remote Director of IT Security Role

DirectiveMontreal (administrative region), QC, CA
Remote
Full-time

Shape Directive Consulting's cybersecurity landscape as the Director of IT Security.This fully remote position emphasizes strategic oversight of information security across multiple regions.As the ... Show more

 • Promoted

Cyber Operations Specialist in Defense

Canadian Armed Forces | Forces armées canadiennesMontreal (administrative region), QC, CA
Full-time

Protect national interests as a Cyber Operator.Conduct critical cyber operations while analyzing vulnerabilities and ensuring secure military communications for various forces.In this impactful rol... Show more

 • Promoted

Senior Analyst - Security Operations

Cirque du Soleil Entertainment GroupMontreal (administrative region), QC, CA
Permanent

Senior Analyst – Security Operations.Review security events to detect and prevent potential information security incidents.Analyze threats and identify strategies to contain and prevent them.Partic... Show more

 • Promoted

Voldex Security and IT Operations Manager

VoldexMontreal (administrative region), QC, CA
Full-time

Join Voldex as a Security and IT Operations Manager to enhance our device management and security processes in a dynamic gaming company.Drive secure and efficient environments for our remote teams.... Show more

 • Promoted

Information Security Manager, Mergers & Acquisitions

WSP in Canadalaval (administrative region), qc, Canada
Full-time

What if you could redefine what’s possible? With us, you can.We are the home of ambitious, passionate, and innovative world shapers.With an unmatched breadth and depth of engineering, advisory and ... Show more

 • Promoted

IT Security & Strategy Leader

Global Partner SolutionsDorval, QC, CA
Full-time

A leading organization in technology and cybersecurity is seeking an IT Manager to provide strategic and operational leadership for its IT systems.The successful candidate will implement cybersecur... Show more

 • Promoted

CyberSecurity Specialist - Cybersecurity Framework, Policies and Standards-EN

CAEMontreal (administrative region), QC, CA
Full-time

Our Mission and Work Environment.Our Technology & Product Development teams transform bold ideas into immersive, world‑class solutions.From VR/AR and flight simulation to other cutting‑edge technol... Show more

 • Promoted

Canada IT Senior Manager: Strategy, Security & Operations

Brunelmontreal (administrative region), qc, Canada
Full-time

Une entreprise internationale de gestion de main-d'œuvre recherche un(e) Gestionnaire principal(e), TI pour diriger la stratégie et les opérations TI au Canada.Le candidat idéal aura plus de 10 ans... Show more

 • Promoted

Senior Security Architecture Specialist (Hybrid)

Morgan StanleyMontreal (administrative region), QC, CA
Full-time

We're seeking someone to join our team as a Senior Security Architecture Specialist in Cyber to be responsible for the security design tooling standards across the firm - translating compliance obl... Show more

 • Promoted

Senior Application Security Specialist

EXFOMontreal (administrative region), QC, CA
Full-time

A leading telecom solutions provider is seeking an experienced Application Security Specialist in Montreal, Canada.This role focuses on driving application security strategies, performing risk asse... Show more

 • Promoted

Senior Director of Infrastructure & Security

Longbow-Advantagemontreal (administrative region), qc, Canada
Full-time

Become the Senior Director of Infrastructure and Security at Longbow Advantage, working remotely with some meetings in Montreal.Steer both security and cloud infrastructure strategy to safeguard se... Show more

 • Promoted

IT Admin & Cybersecurity Specialist

GenAIzMontreal, Montreal (administrative region), CA
Full-time

IT Admin & Cybersecurity Specialist.GenAIz is a cutting‑edge technology company specializing in developing solutions for the Life Sciences industry.We’re looking for an experienced IT Admin and Cyb... Show more