Get AI-powered advice on this job and more exclusive features.
Direct message the job poster from PEOPLE FORCE CONSULTING INC
Sr. Technical Recruiter || Hiring For Dayforce or UKG Consultant -Anywhere in Canada
Senior IT Security Advisor - Application Security
Location: Hybrid - 3 days in Mississauga Office
Contract to Hire
Job Summary
The Senior IT Security Advisor - Application Security is responsible for leading efforts to identify and mitigate security vulnerabilities within the client application portfolio. This role requires a deep understanding of application security, risk management, and the ability to work collaboratively with cross-functional teams to enhance our security posture.
Key Accountabilities
- Integrate security pipelines into the development process, implementing the “Shift-left” and “Fail the Build” methodologies.
- Implement Static Application Security Testing (SAST), Software Composition Analysis (SCA), Dynamic Application Security Testing (DAST), and Penetration Testing (PT) activities.
- Manage and prioritize vulnerabilities, collaborating with IT departments to address them based on risk levels.
- Protect APIs by leveraging technology to understand and mitigate vulnerabilities, including scanning and alerting on API attacks.
- Provide advisory services to new and existing projects and inculcate the Security by Design culture.
- Identify, assess, and document security risks within projects, supporting the definition of strategies to mitigate them effectively to comply with security standards.
- Identify security weaknesses, vulnerabilities, and gaps in the existing technology stack and recommend remediation strategies.
- Conduct comprehensive security assessments on initiatives of various sizes.
- Advise business on information security and privacy matters.
- Evaluate existing security solutions and propose enhancements to streamline processes.
- Maintain a solid understanding of web application development.
- Extensive knowledge of the OWASP Top 10 and web application exploitation techniques, and their respective countermeasures.
- Experience implementing ISO 27001/NIST/PCI-DSS controls or performing threat analysis for IT projects, including security scanning, assessments, and pentesting.
- Knowledge and experience with CICD pipelines, DevOps, DevSecOps, and secure code development.
- Experience performing and coordinating security tests: vulnerability scans, web application penetration tests, infrastructure penetration tests, network segmentation tests.
- Proficient in reviewing architecture and solution design documentation to identify and assess potential risks.
- Review Technical Design documents and perform risk assessments to complete Security Design documents.
- Strong experience leading complex projects from start to finish and providing security advice to ensure risks are identified and mitigated.
- Able to reason about security decisions and communicate ideas clearly to both engineers and business teams.
- Excellent relationship management with key stakeholders across various departments.
- Coach and mentor developers, engineers, and security staff to enhance their efficiency and effectiveness.
- Develop the application security process to its full potential and maintain its trajectory to maturity.
- Mature the security in development process.
- Provide leadership in the Application Security domain.
- Maintain compliance with Bill 198, SOC2, and PCI DSS controls.
- Manage and enhance security processes and technologies to identify, deter, investigate, and remediate security events.
- Manage relationships and negotiate with key vendors.
- Inculcate the Security by Design culture with all IT teams.
- Develop documentation to support technical issues and training.
Qualifications and Skills:
- Bachelor’s degree in computer science, information technology, or cybersecurity; postgraduate degree preferred.
- At least five years in a security domain, preferably Application Security or Risk Management.
- Proficiency with security testing tools such as Veracode, Tenable, and Azure.
- Experience as an Information Security Architect is highly advantageous.
- Knowledge of Azure Data Lakes, Windows SQL, and PostgreSQL is beneficial.
- Experience working in PCI DSS and SOC 2 compliant environments.
- Knowledge of Canadian privacy laws; familiarity with UK GDPR and US regulations is a plus.
Seniority level
Employment type
Job function
Industries
- IT Services and IT Consulting
Referrals increase your chances of interviewing at PEOPLE FORCE CONSULTING INC by 2x
Sign in to set job alerts for “Senior Application Security Engineer” roles.
We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.