Talent.com
Loblaw Companies Limited
Director, Application Security and Vulnerability ManagementLoblaw Companies Limited • Brampton, Peel Region, Canada
Director, Application Security and Vulnerability Management

Director, Application Security and Vulnerability Management

Loblaw Companies Limited • Brampton, Peel Region, Canada
8 days ago
Salary
CA$128,000.00 yearly
Job type
  • Permanent
Job description

Come make your difference in communities across Canada, where authenticity, trust and making connections is valued – as we shape the future of Canadian retail, together. Our unique position as one of the country's largest employers, coupled with our commitment to positively impact the lives of all Canadians, provides our colleagues a range of opportunities and experiences to help Canadians Live Life Well®.

At Loblaw Companies Limited, we succeed through collaboration and commitment and set a high bar for ourselves and those around us. Whether you are just starting your career, re-entering the workforce, or looking for a new job, this is where you belong.

Come make your difference in communities across Canada, where authenticity, trust and making connections are valued - as we shape the future of Canadian retail, together. Our unique position as one of the country's largest employers, coupled with our commitment to positively impact the lives of all Canadians, provides our colleagues a range of opportunities and experiences to help Canadians Live Life Well®.

At Loblaw Companies Limited, we succeed through collaboration and commitment and set a high bar for ourselves and those around us. Whether you are just starting your career, re-entering the workforce, or looking for a new challenge, this is where you belong.

Does leading application security and vulnerability management across one of Canada's largest and most complex technology ecosystems excite you? Loblaw Technology supports corporate offices, stores, pharmacies, distribution centres, digital commerce, SaaS platforms, APIs, and multi-cloud environments. This role will lead the strategy, engineering, and operating model that helps teams build secure software and remediate risk at enterprise scale.

Come lead a team that values diverse ideas, embeds practical security into engineering workflows, and develops our talent from within. You will help modernize application security and vulnerability management, enable secure innovation, and make a measurable difference to customers, colleagues, and business operations.

What You'll Do

  • Lead Loblaw's enterprise Application Security and Vulnerability Management strategy, architecture, engineering, and operations across applications, APIs, cloud workloads, endpoints, servers, containers, and infrastructure.
  • Own the secure SDLC and DevSecOps control model, integrating SAST, DAST, SCA, API security, secret detection, container scanning, and infrastructure-as-code scanning into GitLab Ultimate and enterprise CI/CD workflows.
  • Establish risk-based security gates at commit, merge, build, test, and release stages, with clear thresholds, exception governance, developer guidance, and remediation requirements.
  • Build an application-level DAST and API Security coverage model that maps business applications to repositories, microservices, deployed URLs, environments, API specifications, authentication flows, and accountable owners.
  • Lead the enterprise vulnerability management lifecycle, including asset discovery, scan coverage, validation, deduplication, risk prioritization, remediation service levels, exceptions, retesting, and verified closure.
  • Create a unified exposure view that connects vulnerabilities to internet exposure, attack paths, identities, business services, and asset criticality, giving engineering teams and executives clear, actionable risk information.
  • Own the roadmap and reliable operation of platforms such as GitLab Ultimate, Cortex Cloud / Prisma Cloud, Qualys, API security, attack surface management, and exposure management capabilities.
  • Establish security patterns for AI-enabled software, generative AI, models, agents, and AI-assisted development; address prompt injection, sensitive-data leakage, insecure tool use, and model or agent supply-chain risk.
  • Partner with product, development, SRE, cloud, infrastructure, identity, network, data, privacy, SOC, risk, and audit teams to threat model designs, remediate vulnerabilities, respond to events, and provide control evidence.
  • Lead and develop application security engineers, vulnerability analysts, product owners, and platform specialists; manage budgets, vendors, services, roadmaps, automation, runbooks, succession, and two-deep coverage.

What You'll Bring

  • Proven progressive experience in application security, product security, vulnerability management, cloud security, DevSecOps, or cybersecurity engineering, including leading technical teams or major programs.
  • Demonstrated success leading application security and vulnerability management in a large, complex enterprise, ideally within retail, healthcare, financial services, telecommunications, or another regulated environment.
  • Deep expertise in secure SDLC and DevSecOps, including threat modeling, SAST, DAST, SCA, API security, secret detection, container and Kubernetes security, infrastructure-as-code scanning, and CI/CD controls.
  • Proven experience operating enterprise vulnerability management, including asset and scan governance, finding validation, risk prioritization, remediation SLAs, exceptions, retesting, and executive reporting.
  • Strong understanding of application and API architectures, microservices, authentication flows, cloud-native services, containers, serverless platforms, and software supply-chain risk across AWS, Azure, GCP, and OCI.
  • Experience with platforms such as GitLab Ultimate, Qualys, Cortex Cloud / Prisma Cloud, Veracode, Invicti, Snyk, Checkmarx, API security, attack surface management, or exposure management tools.
  • Experience securing AI/ML, generative AI and agentic applications, AI code assistants, and model or agent supply chains, including prompt injection, data leakage, insecure tool use, and vulnerable dependencies.
  • Ability to apply CVE, CWE, CVSS, EPSS, known-exploited vulnerability data, threat intelligence, asset criticality, and attack-path context to focus remediation on the risks that matter most.
  • Excellent executive communication, stakeholder, financial, and vendor leadership skills, with the ability to translate technical exposure into clear decisions and accountable remediation plans.
  • Bachelor's or Master's degree in Computer Science, Software Engineering, Information Security, Engineering, or a related field. CISSP, CSSLP, CISM, CCSP, GIAC GWEB/GWAPT, OSWE, cloud security, or GitLab credentials are strong assets.

What Loblaw Offers You

We offer flexibility and balance, and an environment that sets you up for success no matter where your workspace is located.

Here, you will find a great team to help you achieve your goals as you help us achieve ours!

Work in our fast-paced, exciting Technology environment, helping our stores, colleagues, and customers every day.

Loblaw colleagues also enjoy:

  • Work Perks Program
  • On-site GoodLife Fitness, Basketball & Volleyball courts, Ice Rink
  • Groceries delivered to work via PC Express, Dry Cleaning services (1PCC Office)
  • Tuition Reimbursement & Online Learning
  • Pension & Benefits
  • Paid Vacation

Loblaw recognizes Canada's diversity as a source of national pride and strength. We have made it a priority to reflect our nation's evolving diversity in the products we sell, the people we hire, and the culture we create in our organization. At Loblaw, we celebrate diversity and strive to build a culture of inclusion where differences are embraced, valued, and supported.

We are committed to being an equal opportunity employer and encourage people from all backgrounds and identities to apply. Accommodation in the recruitment, assessment, and hiring process is available upon request for applicants with disabilities.

We thank all candidates for their interest, but please note, only those who meet the minimum requirements will be contacted.

www.Loblaw.ca/careers

Our commitment to Sustainability and Social Impact is integral to how we do business. Our CORE Values - Care, Ownership, Respect, and Excellence - guide our decisions and come to life through our Blue Culture.

Our commitment to Sustainability and Social Impact is an essential part of the way we do business, and we focus our attention on areas where we can have the greatest impact. Our approach to sustainability and social impact is based on three pillars – Environment, Sourcing and Community – and we are constantly looking for ways to demonstrate leadership in these important areas. Our CORE Values – Care, Ownership, Respect and Excellence – guide all our decision-making and come to life through our Blue Culture. We offer our colleagues progressive careers, comprehensive training, flexibility, and other competitive benefits – these are some of the many reasons why we are one of Canada’s Top Employers, Canada’s Best Diversity Employers, Canada’s Greenest Employers & Canada’s Top Employers for Young People.

If you are unsure whether your experience matches every requirement above, we encourage you to apply anyway. We are looking for varied perspectives which include diverse experiences that we can add to our team.

We have a long-standing focus on diversity, equity and inclusion because we know it will make our company a better place to work and shop.

We are committed to creating accessible environments for our colleagues, candidates and customers.

Requests for accommodation due to a disability (which may be visible or invisible, temporary or permanent) can be made at any stage of application and employment.

We encourage candidates to make their accommodation needs known so that we can provide equitable opportunities.

Please Note:
Candidates who are 18 years or older are required to complete a criminal background check. Details will be provided through the application process.

Hiring Range / Échelle salariale à l’embauche :$128,000.00 - $176,000.00 / 128.000,00$ - 176.000,00$ (per year / par an)A candidate’s experience and knowledge as well as the geographical region in which the position is located may be factored into the pay a candidate receives for this position. This posting is for an existing vacancy. The Company uses artificial intelligence for the purpose of screening, assessing and/or selecting applicants for this position. / L’expérience et les connaissances d’un candidat ainsi que la région géographique dans laquelle le poste est situé peuvent être prises en compte dans la rémunération qu’un candidat reçoit pour ce poste. Cette offre d’emploi concerne un poste vacant existant. L’entreprise utilise l’intelligence artificielle dans le but de filtrer, d’évaluer et/ou de sélectionner les candidats à ce poste.

#EN #SS #LTnA #ON

#J-18808-Ljbffr
Create a job alert for this search

Director, Application Security and Vulnerability Management • Brampton, Peel Region, Canada

Similar jobs

Sr. Director, Infrastructure Automation & Compliance

MCKESSONMISSISSAUGA, Ontario, Canada
Full-time

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare.We are known for delivering insights, products, and services that make quality care more accessibl... Show more

 • Promoted

Director Of Information Security Strategy (Hybrid) - C$84,000 - C$115,000 A Year

Healthcare Solutions ProviderBrampton, Canada
Full-time

Seeking a Director of Information Security Strategy to lead initiatives, develop policies, and manage risks for a healthcare solutions provider. Show more

 • Promoted

Strategic Information Security Architect

ColliersMississauga, Peel Region, CA
Full-time

Transform global security architecture as a Strategic Information Security Architect.Spearhead cloud migration security strategies while ensuring systems are secure and compliant.This pivotal role ... Show more

 • Promoted

Sr. Director, Network Security Engineering - $150,800 - $251,300 A Year

McKessonMississauga, Canada
Full-time

McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare.We are known for delivering insights, products, and services that make quality care more accessibl... Show more

 • Promoted

Senior It Director, Strategy, Security & Ops - $120,000 - $160,000 A Year

Leading Educational InstitutionMississauga, Canada
Full-time

Oversees IT strategy, security, and operations for an educational institution, requiring strong leadership and project management skills. Show more

 • Promoted

Lead Application Security Analyst at Purolator

Purolator Inc.Mississauga, Peel Region, CA
Full-time

Join Purolator as a Lead Application Security Analyst, focusing on integrating security in application development.Help teams secure their software and APIs against evolving threats.In this key rol... Show more

 • Promoted

Softchoice Microsoft Security Solutions Leader

Softchoiceoakville, on, Canada
Full-time

Be a driving force at Softchoice as a Microsoft Security Solutions Leader.Empower organizations with innovative security solutions through effective team leadership and direct customer engagement.I... Show more

 • Promoted

Strategic IT Leader: Cloud, Security & DC Solutions

Merit ServicesVaughan
Full-time +1

A leading IT services company in York Region, Vaughan is seeking a seasoned professional for network implementation and administration.This role entails managing network operations, collaborating w... Show more

 • Promoted

Associate Director, Application Risk And Compliance - $175,000 - $195,000 A Year

New York UniversityMississauga, Canada
Full-time

Provides strategic oversight and defines validation and risk management frameworks for NYU's enterprise application ecosystem, ensuring security, data privacy, and integrity. Show more

 • Promoted

Director Technology Networking & Operations

Longo'sVaughan, Ontario, Canada
Permanent

We are looking for a Director, Technology - Networking & Operations, who is passionate about food and enjoys working in a fast paced, customer service centric, team environment!.Description The Dir... Show more

 • Promoted

Remote Security Architect - Cloud & App Security Lead

AGFA HealthCareMississauga, Peel Region, CA
Remote
Full-time

A healthcare technology company is seeking an experienced Security Architect responsible for designing and implementing security within their architecture.The role involves collaborating with cross... Show more

 • Promoted

Director Infrastructure Operations - $160,000 - $175,000 A Year

Onico SolutionsVaughan, Canada
Full-time

Director of Infrastructure Operations to lead and inspire a team of DevOps engineers, focusing on service availability, automation, and resilient systems.Responsibilities include technical evolutio... Show more

 • Promoted

Strategic App Risk & Compliance Director - $175,000 - $195,000 A Year

Prestigious Academic InstitutionMississauga, Canada
Full-time

Lead application risk and compliance, ensuring security and data privacy within an academic institution's application ecosystem. Show more

 • Promoted

Manager of Cybersecurity Operations Center

Bell CyberMississauga, Peel Region, CA
Full-time

Take charge of the Cyber Intelligence Center as SOC Manager, ensuring 24/7 incident response and team excellence.Your strong technical background will drive our cybersecurity operations forward.We ... Show more

 • Promoted

Senior Director, Virtual Workspace Platforms

ScotiabankMississauga, Peel region, Canada
Full-time

Empower the future of virtual work at Scotiabank as the Senior Director of Virtual Workspace Platforms.Lead the strategic evolution of services including Citrix and Windows 365 Cloud PC with a focu... Show more

 • Promoted

Sr. Director Analyst, Enterprise Architecture (Remote Canada)

GartnerMississauga, Peel region, Canada
Remote
Full-time

Director Analyst, Enterprise Architecture (Remote Canada).Be among the first 25 applicants.Gartner Analysts are industry thought leaders who create must‑have insights, market predictions and best p... Show more

 • Promoted

Director of Engineering — Platform & Reliability (Remote)

CliniaMississauga, Peel Region, CA
Remote
Full-time

A tech-driven health company in Canada is seeking a Director of Engineering to lead an engineering team of 25.You will manage delivery, ensure platform reliability, and set engineering standards wh... Show more

 • Promoted

Director, Enterprise Risk Management – It Security & Cyber Risk

Sagen MI Canada Inc.Oakville, Canada
Full-time

Director, Enterprise Risk Management – IT Security & Cyber RiskJob DescriptionSagen is Canada's leading private mortgage insurance company making home ownership more accessible to first tim... Show more

 • Promoted

Director of IT Security for Directive Consulting

DirectiveMississauga, Peel Region, CA
Full-time

Enhance IT security as Director at Directive Consulting.Protect client data and manage risks within a fully remote framework.In this leadership role, you'll report to the Head of Finance and define... Show more

 • Promoted

It Security Leader: Strategy, Policy & Risk | Hybrid - C$84,000 - C$105,000 A Year

Health Solutions ProviderBrampton, Canada
Full-time

Manager of IT Security to lead information security strategy, policy, and risk management.Focus on compliance and stakeholder collaboration in a hybrid work model. Show more