Application Security Analyst- 1670

Randstad Canada

Toronto

Hybrid

CAD 90,000 - 130,000

Full time

14 days+
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Remote-first schedule
Quarterly alignment sessions
Geographical autonomy

Job summary

Randstad Canada is seeking a talented Application Security Analyst to drive enterprise DevSecOps in a global security program. You will integrate automated security tools into CI/CD pipelines, mentor developers, and align security with engineering priorities.

The role emphasizes building a development-first security culture, reducing friction, and delivering secure software from day one across international geographies. Hybrid work with occasional onsite quarterly.

Qualifications

  • 3+ years of dedicated Cyber Application Security experience.
  • 2+ years in IT system design or application development.
  • Experience with modern AppSec testing infrastructure.
  • Familiar with OWASP Top 10 and SANS Top 25 controls.
  • Active cybersecurity designation (CISSP, CEH or equivalent) preferred.

Responsibilities

  • Operate and tune automated app security testing platforms (SAST/DAST/MAST/SCA).
  • Translate findings into remediation blueprints for software teams.
  • Tune tools, reduce false positives, and upgrade security rules.
  • Automate security tasks with custom scripts and tools.
  • Develop program metrics and security guidance for DevSecOps.

Skills

C++
Java
DOTNET
SAST
DAST
SCA
MAST
OWASP Top 10
SANS Top 25
Automation scripting
CI/CD tooling

Education

University or College diploma in Computer Science or Systems Engineering

Tools

SAST
DAST
SCA
MAST
Docker/Kubernetes
AWS

Job description

Our client, is seeking a talented and proactive Application Security Analyst to join their Global Cyber Security division.

In this critical technical role, you will act as a key accelerator for the organization's enterprise-wide DevSecOps transformation. You will lead the evaluation, custom tuning, and integration of automated application security tools and compliance guardrails directly inside global CI/CD pipelines. This position requires an analyst who bridges the gap between deep cyber security auditing and modern application engineering; you will work shoulder-to-shoulder with developers, cloud engineers, and DevOps squads across major international operating geographies. Your mission is to foster a development-first security culture, ensuring software is built securely from day one without creating operational friction.

Duration: 8-Month Contract (August 10, 2026 – April 9, 2027)

Work Arrangement: Hybrid — primarily remote; optional onsite attendance 1–2 times per quarter at the corporate hub.

Hours: Monday–Friday, 9:00 a.m.–5:00 p.m. (Standard 37.5-hour work week)

Advantages
  • Global Modernization Scope: Own and orchestrate the security tooling roadmap for distributed development clusters across major international operating regions.
  • True DevSecOps Sandbox: Move away from passive spreadsheet auditing—use your development background to automate redundant workflows, write custom infrastructure scripts, and configure serverless security checks.
  • High Executive Visibility: Elevate your professional profile by designing program-level Key Performance Indicators (KPIs) and Key Risk Indicators (KRIs) delivered directly to senior cyber security leadership.
  • Workplace Flexibility: Enjoy a modern, remote-first schedule that offers maximum geographical autonomy, paired with structured quarterly alignment sessions.
Responsibilities
  • Pipeline Security Engineering: Assist with the running, deployment, and configuration of automated application security testing platforms, including SAST, SCA, MAST, and DAST engines.
  • Vulnerability Remediation Consulting: Analyze raw scanning results and penetration testing reports, translate vulnerabilities into actionable fixes, and provide remediation blueprints to active software delivery pods.
  • Platform Custom Tuning: Continuously evaluate tool accuracy, eliminate false positives, and execute software upgrades and rule-set tuning based on emerging threat profiles and system bugs.
  • Process Automation: Build custom scripts and internal tooling to automate repetitive security tasks, removing administrative overhead and accelerating code promotion metrics.Program Strategy, Metrics & Documentation
  • Security Metrics & Reporting: Develop, track, and aggregate program metrics (KPIs and KRIs) for the macro vulnerability management initiative, packaging data into professional reports for executive leadership.
  • AppSec Compliance Blueprints: Assist in authoring global application security guidelines, threat-modeling templates, standard operating procedures, and technical documentation.
  • Developer Advisory & Training: Act as an internal security evangelist, educating software engineering teams on OWASP Top 10 (Web, Mobile, API) and SANS Top 25 code vulnerabilities.
  • Production Operations Support: Provide tier-3 diagnostic support for live web and mobile platforms, resolving security incidents and triaging threat escalations.
Qualifications
  • Experience: Minimum 3+ years of dedicated, professional Cyber Application Security experience, coupled with 2+ years of prior practical experience in IT System Design / Application Development.
  • Software Engineering Foundation: Strong structural background (2+ years) reading, writing, or debugging applications written in C++, Java, or .NET stacks.
  • AppSec Platform Mastery: 1+ years of direct experience administering and configuring Application Security testing infrastructure (SAST/DAST/SCA/MAST tools).
  • Automation Engineering: 1+ years of demonstrated success designing automated infrastructure configurations or writing utility scripts to stitch development tools together.
  • Framework Mastery: In-depth technical command of OWASP Top 10 vulnerabilities (spanning Web architectures, Mobile frameworks, and REST/SOAP APIs) alongside SANS Top 25 controls.
  • Education & Core Certification: University or College diploma in Computer Science, Systems Engineering, or a related technical discipline. An active cybersecurity designation (such as CISSP, CEH, or equivalent) is required.
  • Soft Skills: Outstanding communication skills with the ability to articulate highly technical security threats to non-technical business partners; a proactive problem-solver who can create high-fidelity technical diagrams (such as Visio workflows) and excels in fast-paced Agile sprint environments.
Nice-to-Haves
  • Holding advanced validation credentials, including GWAPT, GWEB, CASE, or CSSLP certifications.
  • Direct experience engineering secure CI/CD pipelines, container environments (Docker/Kubernetes), microservices architectures, and Amazon Web Services (AWS) environments (1+ years).
  • Prior experience in business process engineering, software procurement lifecycles, and managing enterprise application integrations.
Summary

If you are a tech-savvy Application Security Analyst who pairs an absolute command of modern AppSec testing tools (SAST/DAST) with the software engineering background (Java/.NET/C++) and pipeline automation depth needed to drive a global DevSecOps transformation, this 8-month hybrid contract is an exceptional professional platform. Bring your risk remediation precision, scripting agility, and collaborative team-first drive to our client's elite cyber security group today!

Randstad Canada is committed to fostering a workforce reflective of all peoples of Canada. As a result, we are committed to developing and implementing strategies to increase the equity, diversity and inclusion within the workplace by examining our internal policies, practices, and systems throughout the entire lifecycle of our workforce, including its recruitment, retention and advancement for all employees. In addition to our deep commitment to respecting human rights, we are dedicated to positive actions to affect change to ensure everyone has full participation in the workforce free from any barriers, systemic or otherwise, especially equity-seeking groups who are usually underrepresented in Canada's workforce, including those who identify as women or non-binary/gender non-conforming; Indigenous or Aboriginal Peoples; persons with disabilities (visible or invisible) and; members of visible minorities, racialized groups and the LGBTQ2+ community.

Randstad Canada is committed to creating and maintaining an inclusive and accessible workplace for all its candidates and employees by supporting their accessibility and accommodation needs throughout the employment lifecycle. We ask that all job applications please identify any accommodation requirements by sending an email to accessibility@randstad.ca to ensure their ability to fully participate in the interview process.

This posting is for existing and upcoming vacancies.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Application Specialist
Senior Cloud Application Specialist

Randstad Canada • Toronto

On-site
CAD 120,000 - 160,000
Intermediate Security Specialist
Intermediate Security Specialist

Randstad Canada • Toronto

On-site
CAD 90,000 - 120,000
Senior Application Security Analyst
Senior Application Security Analyst

Purolator Inc. • Mississauga

On-site
CAD 110,000 - 140,000
Remote-First DevSecOps AppSec Analyst
Remote-First DevSecOps AppSec Analyst

Randstad Canada • Toronto

Hybrid
CAD 90,000 - 130,000
Remote-first schedule
Quarterly alignment sessions
Geographical autonomy
Senior Transportation Engineer
Senior Transportation Engineer

Englobe • City of Moncton

Hybrid
CAD 90,000 - 115,000
Application Security Consultant - SCA (Global Security)
Application Security Consultant - SCA (Global Security)

RBC • Toronto

Hybrid
CAD 90,000 - 120,000
Total Rewards
Stock options
Flexible work-life balance
+2
Technical Lead/Manager, Application Development
Technical Lead/Manager, Application Development

Randstad Canada • Mississauga

On-site
CAD 110,000 - 140,000
Bonus up to 20%
Professional growth opportunities
Collaborative team
Senior Software Developer - Application Security
Senior Software Developer - Application Security

Scotiabank • Toronto

On-site
CAD 120,000 - 170,000
DEI & Allyship
Accessible workplace
Upskilling & tuition
+2
Project Manager – HYBRID Randstad Canada
Project Manager – HYBRID Randstad Canada

Project Management Institute - Southern Alberta Chapter (PMI-SAC) • Calgary

Hybrid
CAD 90,000 - 120,000
Hybrid work model
On-site Calgary office
Senior Security Specialist - Cloud (Global Security)
Senior Security Specialist - Cloud (Global Security)

Jobgether • Toronto

Hybrid
CAD 120,000 - 180,000
Bonuses
Stock options
Training budget
+2