Enable job alerts via email!

Director, Application Security

Natural Factors

Toronto

Hybrid

CAD 120,000 - 180,000

Full time

4 days ago
Be an early applicant

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

A leading company is seeking a Director of Application Security to lead their Cloud & Application Security team. The role involves driving DevSecOps practices, integrating security into the SDLC, and collaborating with various stakeholders to enhance application security. Candidates should have a strong background in Information Security leadership with a focus on application and cloud security.

Benefits

Inclusive culture emphasizing Diversity, Equity, Inclusion & Allyship
Upskilling opportunities through courses and development programs
Competitive rewards and flexible vacation
Community engagement activities like hackathons and contests

Qualifications

  • 10+ years in Information Security leadership in a global organization.
  • 7+ years in operations or equivalent roles.
  • 5+ years with Regulatory, Compliance, Risk, and Audit functions.

Responsibilities

  • Establish and drive the DevSecOps practice aligned with security standards.
  • Maintain services such as Application Release Assessment and Web/API Assessment.
  • Integrate security into the SDLC and promote developer adoption of security tools.

Skills

Interpersonal skills
Communication skills
Planning
Organizational skills
Adaptability

Education

University degree in Computer Engineering or Computer Science

Tools

Security software products

Job description

Join a purpose-driven, high-performing team committed to results within an inclusive culture.

We are seeking a Director, Application Security to join our Cloud & Application Security Product and Architecture team. The ideal candidate will have strong stakeholder engagement skills to support CIO teams in assessments such as SAST, DAST, MAST, SCA / SBoM, CNAPP, CWPP, CSPM, and IaC Security. These assessments are used as input for TRA or Change Management processes prior to production release. The incumbent will lead the DevSecOps transformation, develop the target state vision, and guide the team in executing the plan collaboratively with product teams, engineers, architects, operations, and control functions.

Key Responsibilities include:

  1. Establish and drive the Bank's DevSecOps practice aligned with security standards and regulatory requirements.
  2. Maintain and deliver services such as Application Release Assessment, Web/API Assessment, Static Code Assessment, Software Composition Assessment, Mobile Security, Secure Development Training, and Cloud Workload Protection.
  3. Integrate security into the SDLC and promote developer adoption of security tools.
  4. Develop KPIs/KRIs and reports to measure service coverage and security risk profile, facilitating cross-functional collaboration.
  5. Define and report on product status, metrics, achievements, next steps, and risks using a data-driven approach.
  6. Foster collaboration among senior executives, platform teams, product managers, and security experts.
  7. Work with CIO teams and stakeholders to define timelines, strategies, funding, and secure buy-in.

Qualifications include:

  • University degree in Computer Engineering, Computer Science, or related field, with 10+ years in Information Security leadership in a global organization.
  • 7+ years in operations or equivalent roles.
  • 5+ years working with Regulatory, Compliance, Risk, and Audit functions.
  • Strong understanding of application and cloud security, solution and infrastructure architecture.
  • Experience with security software products and the security industry.
  • Excellent interpersonal and communication skills.
  • Strong planning, organizational skills, and experience managing complex processes.
  • Willingness to learn, adapt, and demonstrate resilience.
  • Deep knowledge of Application and Cloud Security domains like SAST, DAST, MAST, OSSS, API Security, RAST / IAST, CNAPP, CWPP, CSPM, IaC Security.
  • Experience in security training and awareness for developer communities.

What’s in it for you?

  • Inclusive culture emphasizing Diversity, Equity, Inclusion & Allyship.
  • Accessible environment with accommodations available.
  • Upskilling opportunities through courses, development programs, and tuition assistance.
  • Competitive rewards, bonuses, flexible vacation, and benefits starting Day 1.
  • Community engagement activities like hackathons, contests, and social programs.

Work arrangement: Hybrid (LI-Hybrid)

Scotiabank, guided by our purpose "for every future," is committed to diversity and inclusion. We value each individual's skills and experiences and provide accommodations during recruitment if needed. Candidates should apply directly online. Only shortlisted candidates will be contacted.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Director, Application Security

Canada Life

Toronto

On-site

CAD 92,000 - 171,000

Today
Be an early applicant

Manager, Oracle Application Security

Deloitte Canada

Toronto

Hybrid

CAD 84,000 - 175,000

3 days ago
Be an early applicant

Director, Application Security

Scotiabank

Toronto

On-site

CAD 90,000 - 160,000

30 days ago

Senior Specialist Application Security

ipss inc.

Toronto

On-site

CAD 122,000 - 164,000

9 days ago

Senior Specialist Application Security

TES The Employment Solution

Toronto

On-site

CAD 122,000 - 164,000

8 days ago

Senior Specialist, Application Security (12 month Contract)

Loblaw Companies Limited

Brampton

On-site

CAD 90,000 - 130,000

4 days ago
Be an early applicant