Enable job alerts via email!

Senior IT Security Advisor (Application Security)

goeasy Ltd.

Mississauga

Hybrid

CAD 90,000 - 120,000

Full time

Yesterday
Be an early applicant

Job summary

A leading financial services company in Mississauga is looking for a Senior IT Security Advisor (Application Security) to lead efforts in identifying and mitigating security vulnerabilities within their application portfolio. The ideal candidate will have a strong understanding of web application security, experience with CI/CD pipelines, and relevant certifications such as CISSP. This role offers a flexible work program with three days onsite per week.

Qualifications

  • Minimum of five years in security domains, preferably Application Security / Risk Management.
  • Proficient with OWASP Top 10 and exploitation techniques.
  • Certifications such as CISSP required; CISM, CIPP, GPEN preferred.

Responsibilities

  • Integrate security pipelines into the development process.
  • Manage and execute SAST, SCA, DAST, and Penetration Testing activities.
  • Prioritize vulnerabilities and collaborate with IT teams.

Skills

Web application security understanding
Communication skills
Vulnerability scanning
DevSecOps knowledge
Risk mitigation advising

Education

Bachelor’s degree in a relevant field
Postgraduate degree preferred

Tools

Java
Python
JavaScript
R
Go
UNIX/Linux systems

Job description

Senior IT Security Advisor (Application Security)

Join one of Canada's fastest-growing companies as a Senior IT Security Advisor (Application Security) at goeasy Ltd.

At goeasy , our culture and people are at the core of our success. Recognized for our outstanding workplace environment and growth, we are committed to fostering an inclusive, innovative, and high-performance culture. We provide a range of financial products and services to help Canadians build a brighter future.

As the Senior IT Security Advisor, you will lead efforts to identify and mitigate security vulnerabilities within goeasy’s application portfolio, working collaboratively across teams to strengthen our security posture.

Responsibilities

  • Integrate security pipelines into the development process, implementing "Shift-left" and "Fail the Build" methodologies.
  • Manage and execute SAST, SCA, DAST, and Penetration Testing activities.
  • Prioritize vulnerabilities and collaborate with IT teams to address risks.
  • Secure APIs through vulnerability scanning and attack mitigation.
  • Advise on security by design and support project risk assessments.
  • Identify and recommend remediation for security weaknesses in the technology stack.
  • Conduct security assessments for various projects and initiatives.
  • Provide guidance on information security and privacy matters.
  • Evaluate and enhance existing security solutions.

Required Experience

  • Strong understanding of web application security, OWASP Top 10, and exploitation techniques.
  • Experience with CI / CD pipelines, DevSecOps, and secure coding practices.
  • Ability to perform vulnerability scans and penetration tests.
  • Experience reviewing architecture and security documentation.
  • Proven ability to lead security projects and advise on risk mitigation.
  • Excellent communication skills to liaise with technical and business teams.
  • Bachelor’s degree in a relevant field; postgraduate degree preferred.
  • Minimum of five years in security domains, preferably Application Security / Risk Management.
  • Certifications such as CISSP (required), and others like CISM, CIPP, GPEN are preferred.
  • Experience coding in Java, Python, JavaScript, R, or Go; familiarity with UNIX / Linux systems.
  • We offer a flexible work program with three days onsite per week at our Mississauga office.

    J-18808-Ljbffr

    Get your free, confidential resume review.
    or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.