Security Advisor Specialist - Web Application Protection

Intact Financial Corporation

Toronto

Hybrid

CAD 119,000 - 145,000

Full time

6 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Flexible work arrangements
Hybrid work model
Employee share plan

Job summary

Intact Financial Corporation is seeking a Security Advisor Specialist to join our growing team. You will identify security events, design, implement, and optimize CDN and WAF security controls across enterprise environments.

You will develop, tune, and enforce security policies aligned with OWASP Top 10 and integrate changes into CI/CD pipelines using Terraform and automation. You will monitor security telemetry, investigate incidents, and maintain clear documentation for WAF architecture,

Qualifications

  • University degree in information security, computer science, or related field or equivalent experience.
  • Minimum five years of IT security experience in enterprise/web applications.
  • Extensive experience with CDN and WAF platforms in complex environments.

Responsibilities

  • Identify security events and risks that need monitoring, measurement and reporting.
  • Design, implement, and optimize CDN and WAF controls across enterprise environments.
  • Develop and tune security rules aligned with OWASP Top 10 and industry best practices.
  • Configure bot protection, DoS/DDoS mitigation while balancing security and performance.
  • Protect web apps and APIs against attacks and emergent threats.
  • Manage CDN/WAF as code using Terraform with reusable modules.
  • Integrate CDN/WAF changes into CI/CD pipelines with versioning and reviews.
  • Develop automated tests and scripts for security policies and operations.
  • Monitor WAF logs and telemetry, tune policies, minimize false positives.
  • Document WAF architecture, policies, and procedures.

Skills

Security events monitoring
CDN/WAF security
OWASP Top 10
Terraform IaC
Python scripting
Networking fundamentals
Incident response
Policy development
Communication skills

Education

Bachelor's degree in information security

Tools

Terraform
CI/CD pipelines

Job description

Our employees are at the heart of everything we do. Together, we help people, businesses, and society prosper in good times and be resilient in bad times. Our employee promise represents Intact’s commitment to you in exchange for living our Values, striving to do your best work, being open to change and investing in your career. In return, we promise to provide support, opportunities and performance-led financial rewards at a workplace where you can shape the future, win as a team and grow with us. Pay at Intact is about much more than just salary. Flexible work arrangements and a hybrid work model Possibility to purchase up to 5 extra days off per year Multiple benefits offered to support physical and mental wellbeing, including telemedicine, Wellness account and much more Share plan & other savings: up to 12% of salary or even more (ask how you could earn guaranteed income for life) Salary range (but not limited to): 118,700 - 145,100 Annual bonus target, based on the base salary, with a potential payout of up to double the target (subject to personal and company performance): 15% As part of our commitment to Win As A Team, we share our success with employees through our annual bonus plan and Employee Share Purchase Plan (ESPP) – with Intact matching 50% of your net shares. Our pension offerings provide flexibility and long-term security for our employees beyond their careers. We are one of the few companies offering the opportunity to receive guaranteed income for life via our defined benefit pension plan. Salary for the candidate will be determined taking into consideration a number of factors including: experience, skills, qualifications, anticipated contribution to role, internal equity, etc. The salary range presented above is based on a 35-hour workweek and would represent a majority of different candidate profiles. However, we encourage candidates who may fall outside of this range to apply as well.

About the role

We’re looking for a Security Advisor Specialist to join our growing team!

What you'll do here:
  • Identify security events and risks that need to be monitored, measured, and reported.
  • Design, implement, and continuously optimize CDN and WAF security controls across enterprise environments.
  • Develop, maintain, and tune security rules aligned with industry best practices, including the OWASP Top 10.
  • Configure and enhance bot protection, DoS, and DDoS mitigation capabilities while balancing security, performance, and availability.
  • Protect web applications and APIs against common attacks and emerging threats.
  • Manage CDN and WAF configurations as Infrastructure as Code using Terraform, including reusable modules and secure configuration standards.
  • Integrate CDN and WAF changes into CI/CD pipelines with version control, peer review, automated validation, and controlled deployments.
  • Develop automated tests and scripts for security policies, configuration changes, operational tasks, and reporting.
  • Monitor WAF logs and security telemetry, investigate attack patterns, tune policies, and minimize false positives.
  • Detect configuration drift, support incident response, and maintain clear documentation for WAF architecture, policies, and operational procedures.
What you bring to the table:
  • University degree in information security, computer science, or a related field, or an equivalent combination of education and experience.
  • Minimum five years of relevant experience in information technology, including hands-on experience supporting enterprise web and application security.
  • Extensive experience administering and supporting enterprise-grade CDN and WAF platforms in complex environments.
  • Deep understanding of networking fundamentals and protocols, including TCP/IP, HTTP/S, DNS, TLS, routing, load balancing, reverse proxies, caching, and traffic flows across distributed environments.
  • Strong understanding of web traffic, application architectures, APIs, and common attack techniques.
  • Proven ability to develop, document, and enforce security policies, standards, and procedures.
  • Experience managing security policies throughout their lifecycle, including requirements gathering, implementation, testing, approvals, exception management, reviews, and retirement.
  • Strong Terraform expertise, with experience creating and maintaining reusable modules, managing environments through version control, and applying Infrastructure as Code practices to security services.
  • Proficiency in scripting and automation using Python, Bash, or similar languages.
  • Ability to interpret security events and technical data, troubleshoot complex production issues, identify root causes, and communicate practical recommendations to technical and business stakeholders.
  • Strong collaboration skills, sound judgment, and a commitment to ethical security practices.
  • Security certification would be an asset.

For candidates located in Quebec, bilingualism is required considering the necessity to interact on a regular basis with English-speaking colleagues across the country No Canadian work experience required however must be eligible to work in Canada #LI-Hybrid Il s'agit d'un nouveau rôle au sein de notre équipe en pleine croissance | This role is a new member of our growing team.

We are an equal opportunity employer

At Intact, our Value of respect is founded on seeing diversity as a strength. We strive to create an accessible workplace where employees feel valued, included and encouraged to share their unique perspectives. We encourage applications from individuals who are members of equity-deserving groups, including but not limited to women, Indigenous peoples, persons with disabilities, Black people, and members of the 2SLGBTQI+ community. As part of Intact’s commitment to reconciliation, we acknowledge that we work, meet and travel across the land currently called Canada, originally inhabited by First Nations, Metis and Inuit people. This history extends through many centuries and continues to evolve today. We have policies to ensure equal access and participation for people with disabilities, including providing workplace adjustments (accommodations). A copy of applicable policies is available on request. If we can provide a specific adjustment to make the recruitment process more accessible for you, please let us know when we reach out about a job opportunity. We’ll work with you to meet your needs.

Learn more about our recruitment process and your candidate journey here.

Please note that Intact does not provide sponsorship or other support for immigration-related matters including but not limited to employer-specific closed work permits.

Candidates must be eligible to work in Canada from the anticipated start date and throughout their employment and are solely responsible for maintaining their work eligibility.

If you are an employee of Intact or belairdirect, please apply for this role on Internal Career Site.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Advisor Specialist - Web Application Protection
Security Advisor Specialist - Web Application Protection

Intact FC • Vancouver

Hybrid
CAD 119,000 - 145,000
Hybrid work model
5 extra days off per year
Wellbeing benefits like telemedicine
+2
Security Advisor Specialist - Web Application Protection
Security Advisor Specialist - Web Application Protection

Socket.dev • Toronto

Hybrid
CAD 119,000 - 145,000
Hybrid work model
Up to 5 extra days off per year
Telemedicine and Wellness account
+2
Security Analyst II - Pen Tests
Security Analyst II - Pen Tests

Socket.dev • Toronto

Hybrid
CAD 81,000 - 99,000
Flexible work arrangements
Hybrid work model
Up to 5 extra days off per year
+2
Security Analyst II - Pen Tests
Security Analyst II - Pen Tests

Intact FC • Vancouver

Hybrid
CAD 81,000 - 99,000
Hybrid work model
Up to 5 extra days off per year
Telemedicine and Wellness account
+1
Director, Broker & Third-Party Security
Director, Broker & Third-Party Security

Intact • Toronto

Hybrid
CAD 162,000 - 198,000
Security Analyst I - Pen Tests
Security Analyst I - Pen Tests

Intact Financial Corporation • Vancouver

Hybrid
CAD 64,000 - 78,000
Hybrid work model
Equal opportunity employer
Security Specialist - IAM
Security Specialist - IAM

Intact • Saint-Hyacinthe

Hybrid
CAD 119,000 - 145,000
Hybrid work model
Flexible time off
Telemedicine
+3
Security Analyst II - Pen Tests
Security Analyst II - Pen Tests

Intact • Toronto

Hybrid
CAD 81,000 - 99,000
Flexible hybrid work
Extra days off (up to 5) per year
Wellbeing benefits and telemedicine
+1
Security Analyst I - Pen Tests
Security Analyst I - Pen Tests

Socket.dev • Vancouver

Hybrid
CAD 64,000 - 78,000
Flexible/hybrid work
Extra days off
Wellbeing benefits
+2
Director, Broker & Third-Party Security
Director, Broker & Third-Party Security

Intact Financial Corporation • Toronto

Hybrid
CAD 162,000 - 198,000
Hybrid work model
5 extra days off per year
Wellbeing benefits incl telemedicine
+2