Talent.com
Application Security Engineer
Application Security EngineerTata Consultancy Services • Toronto, ON, CA
Application Security Engineer

Application Security Engineer

Tata Consultancy Services • Toronto, ON, CA
4 days ago
Job type
  • Full-time
Job description

About TCS

TCS is an IT services, consulting, and business solutions organization that has been partnering with many of the world’s largest businesses in their transformation journeys for over 55 years. Its consulting‑led, cognitive‑powered portfolio of business, technology, and engineering services and solutions is delivered through its unique Location Independent Agile delivery model, recognized as a benchmark of excellence in software development. A part of the Tata group, India's largest multinational business group, TCS operates in 55 countries and employs over 607,000 highly skilled individuals, including more than 10,000 in Canada.

Equal Opportunity & Inclusion

TCS is an equal opportunity employer, and embraces diversity in race, nationality, ethnicity, gender, age, physical ability, neurodiversity, and sexual orientation, to create a workforce that reflects the societies we operate in. Our continued commitment to Culture and Diversity is reflected in our people stories across our workforce and implemented through equitable workplace policies and processes.

Additional Information

Note : TCS does not use artificial intelligence tools for candidate screening or evaluation.

Tata Consultancy Services Canada Inc. is committed to meeting the accessibility needs of all individuals in accordance with the Accessibility for Ontarians with Disabilities Act (AODA) and the Ontario Human Rights Code (OHRC). Should you require accommodations during the recruitment and selection process, please inform Human Resources.

Job Summary

The Application Security Engineer will perform end‑to‑end penetration testing on web applications and APIs to identify security vulnerabilities, assess risk, and drive remediation. The role includes planning and executing manual and automated tests, producing clear and actionable reports, collaborating with engineering teams to fix issues, and ensuring all findings are logged and tracked through closure in the vulnerability management system.

Key Responsibilities

Penetration Testing & Assessment

  • Plan, scope, and execute web application and API penetration tests across SDLC phases (pre‑release and production).
  • Perform recon, threat modeling, and attack surface mapping to prioritize test coverage.
  • Identify and validate vulnerabilities including authentication / authorization flaws, injection, XSS, SSRF, deserialization, IDOR, insecure direct object references, logic bugs, misconfigurations, and sensitive data exposure.
  • Test API endpoints (REST / Graph QL) for input validation, rate limiting, broken object‑level authorization (BOLA), and schema / serialization issues.
  • Use both automated scanning and manual exploitation to confirm impact, reproducibility, and exploit chains.

Reporting & Remediation Support

  • Prepare detailed technical reports with PoCs, severity ratings (CVSS / SLA alignment), affected components, and business impact.
  • Provide prioritized remediation guidance with code‑level recommendations and secure patterns.
  • Log all findings in the vulnerability tracking system (e.g., JIRA, Azure DevOps, ServiceNow, or dedicated VM platforms), ensuring accurate metadata (CWE / CVE, CVSS, asset, environment, owner).
  • Track remediation progress, validate fixes, and close findings after re‑test.
  • Tooling & Automation

  • Configure, run, and tune DAST or similar tools; integrate results into CI / CD.
  • Build and maintain custom scripts for repeatable tests and payload generation.
  • Maintain test environments, proxies, and lab infrastructure (containers, mock services).
  • Required Qualifications & Skills

  • Good years in application security or red teaming with hands‑on web / API pen testing.
  • Working knowledge of CVSS scoring, CWE mapping, and SLA‑based remediation workflows in platforms like Tenable, Qualys, or custom trackers.
  • Clear technical writing, stakeholder communication, and ability to translate risk into business impact.
  • Preferred Qualifications

  • Experience embedding security testing in CI / CD (GitHub Actions, GitLab CI, Azure DevOps).
  • Familiarity with IaC scanning (Terraform, Bicep), container security, and runtime protections (RASP / WAF).
  • Experience with mobile API testing and SSO / federation architectures.
  • Salary Range

    CA$100,000 – CA$150,000 per year.

    Senior Level

  • Mid‑Senior level
  • Employment Type

  • Full‑time
  • Job Function

  • Information Technology
  • Industries

  • IT Services and IT Consulting
  • Application Process

    Applicants that meet the qualifications for this position will be contacted within a 2‑week period. We invite you to continue to apply for other opportunities that match your profile.

    #J-18808-Ljbffr

    Create a job alert for this search

    Application Engineer • Toronto, ON, CA

    Similar jobs
    Application Security Engineer

    Application Security Engineer

    Tata Consultancy Services • Toronto
    Full-time
    TCS is an IT services, consulting, and business solutions organization that has been partnering with many of the world’s largest businesses in their transformation journeys for over 55 years.Its co...Show more
    Last updated: 11 days ago • Promoted
    Application Security Lead

    Application Security Lead

    Compunnel, Inc. • Toronto, Canada
    Full-time
    The Application Security Lead is responsible for integrating, optimizing, and managing security tools within the DevSecOps pipeline. The role will triage application security findings, drive remedia...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer

    Security Engineer

    Chad Management Group • Toronto, ON, Canada
    Full-time
    Conduct thorough investigations and offer guidance on the most current security-related risks, threats, and vulnerabilities. This will involve managing security incidents, overseeing external securi...Show more
    Last updated: 30+ days ago • Promoted
    Senior Security Engineer, Application & Platform Security

    Senior Security Engineer, Application & Platform Security

    Sentry • Toronto
    Full-time
    Bad software is everywhere, and we’re tired of it.Sentry is on a mission to help developers write better software faster so we can get back to enjoying technology. With more than $217 million in fun...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer

    Security Engineer

    Foundant Technologies, Inc. • Toronto, Canada
    Full-time
    About SmartSimple, Foundant & Giving Data At.SmartSimple, Foundant Technologies, & GivingData , we empower mission-driven organizations to manage their data, workflows, and impact with our comprehe...Show more
    Last updated: 26 days ago • Promoted
    Application Security Engineer — Shape Secure, Scalable Apps

    Application Security Engineer — Shape Secure, Scalable Apps

    Homebase • Toronto
    Full-time
    A technology company in Toronto is seeking a hands-on Application Security Engineer to build and grow its Application Security program. This role involves designing controls against vulnerabilities,...Show more
    Last updated: 30+ days ago • Promoted
    Application Engineer

    Application Engineer

    Litmus Automation • Toronto, ON, Canada
    Full-time
    Litmus is a growth-stage software company that is transforming the way companies harness the power of machine data to improve operations. Our software is enabling the next wave of digital transforma...Show more
    Last updated: 30+ days ago • Promoted
    Application Security Engineer (Hybrid)

    Application Security Engineer (Hybrid)

    Homebase • Toronto
    Full-time
    At Homebase, you’ll join a team that’s bold, fast-moving, and obsessed with helping small businesses thrive.We build with empathy, act with urgency, and take big swings that drive real-world impact...Show more
    Last updated: 30+ days ago • Promoted
    Application Security Engineer — Offensive Testing & Cloud Security (Hybrid)

    Application Security Engineer — Offensive Testing & Cloud Security (Hybrid)

    Themis Solutions Inc. • Toronto
    Full-time
    A leading legal technology firm in Toronto seeks an Application Security Engineer to enhance its security team.The ideal candidate will focus on penetration testing and vulnerability remediation, w...Show more
    Last updated: 1 day ago • Promoted
    Security Engineer

    Security Engineer

    Galent • Toronto, Canada
    Full-time
    Strong developer background and hands-on experience with Application security tools.Application Security (SAST, SCA, DAST, WAF, ASPM), or Infrastructure, Container, Cloud security with background i...Show more
    Last updated: 30+ days ago • Promoted
    Security Engineer II

    Security Engineer II

    PagerDuty • Toronto
    Full-time
    NYSE : PD) is a global leader in digital operations management.Trusted by nearly half of both the Fortune 500 and the Forbes AI 50, and approximately two-thirds of the Fortune 100, PagerDuty is essen...Show more
    Last updated: 30+ days ago • Promoted
    Application Security Architect

    Application Security Architect

    Phreesia, Inc. • Toronto, Canada
    Full-time
    Application Security Architect page is loaded## Application Security Architectlocations : .Posted 15 Days Agojob requisition id : . R4513 • •Job Description : • • • •Security Architect - I • • to join us in buil...Show more
    Last updated: 26 days ago • Promoted
    Lead Application Security Engineer

    Lead Application Security Engineer

    Nasdaq, Inc. • Toronto
    Full-time
    Lead Information Security Engineer page is loaded## Lead Information Security Engineerlocations : St.John's - 18 Hebron Way : Canada - Montreal - Québec : Canada - Toronto - Ontariotime type : ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Security Engineer, Application & Platform Security

    Senior Security Engineer, Application & Platform Security

    Sentry.io • Toronto
    Full-time
    Bad software is everywhere, and we’re tired of it.Sentry is on a mission to help developers write better software faster so we can get back to enjoying technology. With more than $217 million in fun...Show more
    Last updated: 30+ days ago • Promoted
    Application Security, Lead

    Application Security, Lead

    Interac Corp. • Toronto, Canada
    Full-time
    Who We Are : • •Every transaction matters.At Interac, we protect both — driving trust, security, and inclusion, so our digital economy thrives. Founded in 1984, Interac connects Canadians through secur...Show more
    Last updated: 5 days ago • Promoted
    Application Security Developer

    Application Security Developer

    Queer Tech • Toronto
    Full-time
    Clio is the global leader in legal AI technology, empowering legal professionals and law firms of every size to work smarter, faster, and more securely. We are transforming the legal experience for ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Application Security Specialist

    Senior Application Security Specialist

    AIR MILES Reward Program • Toronto, Canada
    Full-time
    The AIR MILES Reward Program is one of Canada’s most recognized loyalty programs, with over 10 million active collector accounts, representing more than half of all Canadian households.AIR MILES co...Show more
    Last updated: 30+ days ago • Promoted
    Application Security and identity / Infrastructure Security Engineer (Kubernetes clusters)

    Application Security and identity / Infrastructure Security Engineer (Kubernetes clusters)

    freelance.ca • Toronto, Canada
    Full-time
    Application Security and identity Engineer / Infrastructure security engineer (Kubernetes clusters).Work Location : hybrid, downtown Toronto, ON. Contract Term : 6 months, highly renewable extended be...Show more
    Last updated: 30+ days ago • Promoted