Search jobs > Toronto, ON > Application engineer

Senior Application Security Engineer

theScore
Toronto, ON
Full-time

About the Role & Team

As part of the theScore team, you will be working with a team of smart, friendly, and dedicated Engineers, Product Managers and Designers determined to deliver some of the best apps the market has to offer.

We want you to be challenged and to get the full experience of what it is like to work at theScore! We are looking for a Senior Application Security Engineer to join our Application Security team.

Our team takes a hands-on approach to solving complex security problems in conjunction with writing policies and procedures.

You will work cross-functionally across the entire engineering organization. You will share your unique expertise with the team and be able to grow and expand that expertise.

We have a wide variety of security challenges, and we are looking for someone who is excited to tackle them. Come join us and help us build the best sports apps in the world!

About the Work

  • Collaborate with release and change management, SRE, Engineering, and compliance teams
  • Work with security / internal / external / state auditors to demonstrate compliance
  • Maintain a working knowledge of OWASP top 10 and MITRE top 25 CWE
  • Develop standards for security tooling focused on the application layer (SAST, DAST, SCA, MAST, RASP)
  • Build / implement secure artifact workflows in the SDLC to ensure governance and compliance standards are being met
  • Create technical approaches to implementing Application Security control technologies
  • Contribute to theScore’s Application Security program to support our continued growth
  • Define and report on security metrics, their delivery, and improvements
  • Work with service teams to conduct threat models of theScore’s internal and customer facing applications
  • Assist service teams in understanding and remediating security findings (code bashing)
  • Other duties as required.

About You

  • 5+ years of Application Security or DevOps experience
  • 5+ years of GCP or AWS experience
  • Experience with software supply chain security (SBOMs, Artifact Signing, Attestations)
  • Programming experience in Python or Go
  • Experience with implementing security tooling in CI / CD
  • Experience creating complex CI / CD workflows (building for multiple architectures, local caching, making automated source code changes based on workflow output)
  • Experience supporting RESTful APIs and securing containerized workloads (GKE, EKS)
  • Experience working in regulated environments (PCI-DSS, SOC 2, etc.)
  • Experience leading technical projects and seeing them through to completion
  • Excellent communication skills and a history of working well with other teams
  • Optional : Experience maintaining Kubernetes clusters, or managing Kubernetes deployments

What We Offer

  • Competitive compensation package.
  • Fun, relaxed work environment.
  • Education and conference reimbursements.
  • Parental leave top
  • Opportunities for career progression and mentoring others.

LI-REMOTE

Candidates residing in Ontario requiring special accommodation can email

23 days ago
Related jobs
Amazon
Toronto, Ontario

Amazon is seeking a talented and seasoned Senior Applications Security Engineer to focus on securing the ecosystem that powers Amazon Customer Service (CS). As a senior security engineer, you will help define short-term and long-term security strategy. Perform security reviews including secure desig...

BMO
Canada, Canada

The Application Security Testing Engineer reports to the Lead of DevSecOps and assists with the security testing activities for BMO based applications. Assists with the execution of highly technical/analytical security assessments of custom web applications, mid-tier application services, API securi...

ClickUp
Canada

We're looking for a Security Engineer, AppSec for an engineering-focused security team. The security team at ClickUp works to build and share technology including defensive security features and functionality, secure infrastructure and operational tools, security response tooling and processes, and ...

0000050007 Royal Bank of Canada
Toronto, Ontario

Cloud Software, Communication, Cross-Departmental Collaboration, Cyber Operations, Cyber Security Management, Decision Making, Detail-Oriented, Group Problem Solving, High Impact Communication, Information Security Management, Information Technology Security, Network Security Operations, Security Au...

Procom
Toronto, Ontario

On behalf of our client in the Banking Sector, PROCOM is looking for a Data Security Engineer. Data Security Engineer - Job Description. Data Security Engineer - Mandatory Skills. Data Security Engineer - Preferred Skills. ...

Scotiabank
Toronto, Ontario

Senior Engineer contributes to the overall success of the Security Platform Engineering (SPE) team in Canada and Globally, ensuring specific individual goals, plans, initiatives are executed / delivered in support of the team’s business strategies and objectives. Be technical leader to a talented gr...

Deloitte
Toronto, Ontario

Reporting to the Manager for Application Security, this Senior Consultant is self-motivated, energetic, driven for success and results oriented. Senior Consultants also provide application security experience and demonstrate leadership capabilities by delivering key messages to clients and managemen...

Manulife
Toronto, Ontario

Advanced knowledge of security systems, access controls, network security, security platform administration, security incident response, security architecture, risk management and security governance framework. As a Senior CyberArk Security Engineer, you will be the mastermind behind the fortress, d...

Deloitte
Toronto, Ontario

Senior Consultants play a significant role throughout project lifecycles where they lead and deliver application security for Oracle Cloud ERP, HCM, SCM and business process controls assessments, and implementations with minimal oversight. Our Application Security specialists design and configure ro...

Ansys
Toronto, Ontario

Join the Ansys Customer Excellence team to partner with our customers to engineer what's ahead, solve their real-world engineering problems, deploy Ansys software in their design workflows, and grow Ansys’ business. As a hands-on subject matter expert, you will use expert-level engineering knowledge...