Senior Application Security Engineer

Nutrien

Calgary

On-site

CAD 120,000 - 160,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Nutrien is seeking a Senior Application Security Engineer to advance security across the SDLC. You will lead vulnerability management across code, infrastructure, and applications, mentor teammates, and partner with development, DevOps, and cyber security to drive risk-based remediation.

You will apply ISO/NIST/PCI frameworks, develop security metrics, and influence engineering decisions. This senior role requires strong technical depth and leadership continuity for ongoing initiatives.

Qualifications

  • 6–8 years of related experience in application security and vulnerability management.
  • Strong knowledge of security frameworks (ISO 27001-2, NIST, PCI DSS, OWASP).
  • Hands-on with vulnerability management tools (Qualys, Tenable, Snyk, TruffleHog Pro).
  • Experience in Agile environments and cloud/container security.

Responsibilities

  • Lead vulnerability management activities and prioritize remediation.
  • Collaborate with DevOps and engineering to secure SDLC.
  • Mentor team members and drive consistent security practices.
  • Develop metrics and dashboards for risk reporting.
  • Apply risk frameworks to guide remediation priorities.

Skills

Vulnerability management lifecycle
Risk-based prioritization
Application security
Cloud concepts
Agile development
Security frameworks
Communication with leadership
AI in app development
Container environments
Penetration testing

Education

Bachelor’s degree in Computer Science, Information Systems, Engineering, Business, or a related field

Tools

Qualys
Tenable
Snyk
TruffleHog Pro

Job description

Nutrien is a leading provider of crop inputs and services, and our business results make a positive impact on the world. Our purpose, Feeding the Future, is the reason we come to work each day. We’re guided by our culture of care and our core values: We put safety first. We act with integrity. We are stronger together. We deliver with excellence.

Through the collective expertise of our nearly 26,000 employees, we operate a world-class network of production, distribution, and ag retail facilities. We efficiently serve growers' needs and strive to provide a more profitable, sustainable, and secure future for all stakeholders. Help us raise the expectation of what an agriculture company can be and grow your career with Nutrien.

This Sr. Level role is to help development teams build and run software more securely without slowing them down. This role is part of the application security team and works across application development, DevOps, and cyber security to help teams work through vulnerabilities, improve day-to-day security practices, and make better decisions about where to focus on the cyber risk areas. It is also a senior role on the team, so there is an expectation to mentor others, provide practical guidance, and step in when leadership support is needed.

The value of the role is that it helps turn security from something teams react to into something that is built into how they work. For the team, that means clearer direction, stronger technical support, and better follow-through on the issues that matter most. For the business, it means reducing avoidable risk, improving consistency across application security work, and giving leadership confidence that security issues are being managed in a practical and accountable way.

The Role:

The Senior Application Security Engineer is a senior technical role responsible for advancing security across the software development lifecycle (SDLC). Working closely with application development, DevOps, cyber security, and IT teams, this position leads the identification, assessment, prioritization, and remediation of vulnerabilities across code, infrastructure, and applications, while providing technical direction on secure development practices, automation, and risk reduction.

This role serves as a trusted technical leader and escalation point for application and vulnerability management matters, partnering across teams to drive remediation, influence technical decisions, and support consistent execution across multiple initiatives. The successful candidate will bring strong technical depth, sound judgment, and a strong application development background, along with the ability to provide leadership continuity and decision support when the manager is out of office.

What You'll Do:

  • Build strong relationships across application development, DevOps, cyber security, and IT teams to influence secure development outcomes and provide expert technical guidance
  • Lead vulnerability management activities, including prioritization, risk evaluation, progress tracking, and stakeholder communication
  • Monitor emerging business, technology, and cyber security trends and translate insights into practical improvements for development teams
  • Partner with engineering and DevOps teams to evaluate, implement, and optimize vulnerability management capabilities across people, process, and technology
  • Own and enhance key components of vulnerability management and application security solutions in complex enterprise environments
  • Conduct and oversee targeted vulnerability assessments to identify control gaps and evaluate the effectiveness of existing safeguards
  • Apply security and risk frameworks such as ISO 27001-2, PCI DSS, NIST CSF 20, ITIL, COBIT, CVSSv4, OWASP, and MITRE ATT&CK to guide technical decisions and remediation priorities
  • Provide hands‑on expertise with vulnerability management and prioritization platforms, driving adoption of risk‑based remediation practices
  • Perform root cause analysis on vulnerabilities and work with development and platform teams to determine practical, effective solutions
  • Assess exploitability and business impact in organizational context and recommend remediation strategies that balance risk reduction with operational needs
  • Bring broad cyber security expertise spanning vulnerability management, privacy, incident response, governance, risk and compliance, enterprise security strategy, and security architecture
  • Lead and coordinate cyber security initiatives by shaping plans, driving execution, and communicating status to technical stakeholders and leadership
  • Mentor other team members by sharing technical guidance, supporting development, and helping build consistency across the team’s application security work

What You'll Bring:

  • Bachelor’s degree in Computer Science, Information Systems, Engineering, Business, or a related field is preferred
  • Minimum 6-8 years of related experience
  • Strong understanding of the vulnerability management lifecycle, governance, and risk-based prioritization in enterprise environments
  • Deep familiarity with application security and risk frameworks, including ISO 27001-2, ISO 31000, PCI DSS, OWASP ASVS, NIST frameworks, ITIL, COBIT, CVSSv4, and MITRE ATT&CK
  • Hands‑on experience with vulnerability management tools such as Qualys, Tenable, Snyk, and TruffleHog Pro
  • Experience working in Agile development environments
  • Strong understanding of operating systems (Windows, Unix, and MacOS), cloud concepts (including secure build images, ephemeral workloads, and cloud patching), and networking fundamentals
  • Strong application development background, with broad understanding of full-stack application development and mobile development across iOS and Android
  • Experience developing metrics, dashboards, and risk reporting for technical teams and leadership
  • Experience with API security scanning and application security testing approaches
  • Ability to communicate complex technical issues clearly and succinctly to engineers, senior leaders, and business stakeholders
  • Broad knowledge of cyber security practices including secure configuration management, data protection and privacy, security monitoring, incident response, governance, risk and compliance, patch management, and enterprise security architecture
  • Strong written and verbal communication skills with the ability to influence senior management, technical subject matter experts, and cross‑functional stakeholders
  • Demonstrated ability to examine issues strategically and analytically, balancing technical depth with practical business outcomes
  • Advanced understanding of the use of AI in application development
  • Experience working in cloud and container environments
  • Penetration testing and application security experience
  • Automation and scripting experience, such as Python or Bash

The estimated salary that Indeed, Glassdoor and LinkedIn lists does not represent Nutrien's compensation structure. Nutrien is an equal opportunity employer. We evaluate qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, and other legally protected characteristics.

This job will remain posted until filled. In accordance with Nutrien policies, you will be required to undergo a background check, and may be required to undergo a substance test. While we appreciate all applications we receive, only candidates under consideration will be contacted. Applicants must meet minimum age requirements, as permitted by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Application Security Engineer
Senior Application Security Engineer

Nutrien • Saskatoon

On-site
CAD 110,000 - 150,000
Sr. Security Architect
Sr. Security Architect

Nutrien • Calgary

On-site
CAD 120,000 - 170,000
Cybersecurity Engineer
Cybersecurity Engineer

Nutrien • Calgary

On-site
CAD 80,000 - 120,000
Sr Analyst, Cybersecurity, Industrial Controls
Sr Analyst, Cybersecurity, Industrial Controls

Nutrien Ag Solutions Limited • Saskatoon

On-site
CAD 85,000 - 120,000
Purpose-Driven Work
Excellent Benefits
Grow Your Career
+2
Senior Cybersecurity Recovery Architect
Senior Cybersecurity Recovery Architect

Nutrien • Calgary

On-site
CAD 120,000 - 180,000
Purpose-Driven Work
Benefits
Career Growth
+2
Sr Analyst, Global HRIS
Sr Analyst, Global HRIS

Nutrien Ag Solutions Limited • Calgary

On-site
CAD 110,000 - 140,000
Sr Analyst, Cybersecurity, Industrial Controls
Sr Analyst, Cybersecurity, Industrial Controls

Nutrien • Saskatoon

On-site
CAD 85,000 - 110,000
Comprehensive medical, dental, and vision coverage
Tuition assistance for future education
Employee Assistance Programs
Senior Cybersecurity Recovery Architect
Senior Cybersecurity Recovery Architect

Nutrien • Saskatoon

On-site
CAD 140,000 - 200,000
Medical coverage
Dental coverage
Vision coverage
+4
Specialist, Automation & Monitoring
Specialist, Automation & Monitoring

Nutrien • Saskatoon

On-site
CAD 75,000 - 95,000
Comprehensive medical, dental, and vision coverage
Tuition assistance for further education
Employee Assistance Programs
Mine Engineering Manager
Mine Engineering Manager

PCS INC • Lanigan

On-site
CAD 120,000 - 180,000