Senior Specialist, Security Applications (AppSec)

Canada Mortgage and Housing Corporation

Ottawa

Hybrid

CAD 104,000 - 130,000

Full time

40 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Annual Paid vacation
Performance incentive
Group insurance

Job summary

Canada Mortgage and Housing Corporation (CMHC) is seeking a Senior Specialist, Security Applications to lead and mature the enterprise AppSec program. You will design, govern, and continuously improve security controls across SSDLC/SDLC, aligning with risk tolerance and regulatory obligations.

You will provide expert advisory services to executives, architects, and delivery leaders, ensuring secure software delivery within Agile and DevSecOps environments.

Qualifications

  • Bachelor’s degree in Computer Science, IT, Cybersecurity or related field, or equivalent experience.
  • 7–10 years in application security or secure software delivery.
  • Experience developing enterprise app security standards and governance.
  • Ability to embed secure practices across SDLC/SSDLC, Agile, DevOps and DevSecOps.
  • Proven ability to guide secure-by-design and secure-by-default principles.
  • Experience with secure architecture reviews, threat modeling, and testing.
  • Strong communication and stakeholder management skills.

Responsibilities

  • Lead and evolve enterprise AppSec framework so security is embedded in the SDLC/SSDLC.
  • Govern Secure SDLC and DevSecOps practices with automated testing and secure coding standards.
  • Promote secure-by-design and secure-by-default culture across development teams.
  • Partner with engineering and architecture to embed requirements into Agile, CI/CD, and cloud environments.
  • Provide guidance on secure design decisions and remediation of vulnerabilities.
  • Define and enforce security assurance activities and quality gates.
  • Act as escalation point for complex vulnerabilities and secure delivery challenges.

Skills

Application Security
Secure SDLC
DevSecOps
Governance & Risk
Threat modeling
SAST/DAST

Education

Bachelor's degree in Computer Science or related

Tools

CI/CD tooling
SAST tools
DAST tools

Job description

Senior Specialist, Security Applications (AppSec)

Job Requisition ID: 12213

Position Status:Permanent Full Time

Position Type:Hybrid

Travel Requirement:Limited

Language Skill Levels (Read/Write/Speak):CBC

Security Requirement:Secret

Salary:Our salaries generally range from $104,180.28to $130,225.36and are based on qualifications and experience.

About CMHC

The work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system.

At CMHC, we hold ourselves accountable for our results and support our colleagues in their achievements. We thrive on collaboration, connecting across CMHC and involving the right people to get our work done. Our leadership style is guided by trust, where our leaders favour an adaptive approach based on the needs of their teams.

Join us and be part of a team that's committed to making a real difference and be part of something meaningful.

What’s in it for you

We’ve got the purpose, the people and the perks you need for a fulfilling career. Here’s the comprehensive and generous benefits you get when you’re a permanent employee:

  • Annual Paid vacation.
  • Annual individual performance incentive.
  • Comprehensive group insurance plan to support your well-being from day one.
  • Support towards your personal and professional growth with training, mentorship and more.
  • An inclusive workplace culture and environment.
  • While positions at CMHC require some in-office presence, alternative work arrangements may be considered for Indigenous candidates.

Members of the following employment equity deserving groups will be prioritized for this job: Indigenous Peoples

About the role

Join the Technology and Business Transformation team, in the Bilingual Senior Specialist, Application Security. You'll be responsible for designing, governing, and continuously improving the enterprise Application Security (AppSec) program to ensure that applications and software‑delivered services are designed, built, tested, and operated in alignment with the organization’s risk tolerance, security strategy, and regulatory obligations.

The role provides expert‑level advisory services to senior management, architects, and delivery leadership, and is accountable for the effectiveness and outcomes of application security controls across the full Secure Software Development Lifecycle (SSDLC / SDLC), including controls embedded in Agile and DevSecOps delivery models.

Open to internal employees in a Remote position or with a current Hybrid exception living at more than 125 km from a CMHC office.

What you’ll do:

  • Lead and evolve the enterprise Application Security framework, ensuring security requirements are embedded throughout the software development lifecycle and become a core part of how applications are designed, built, tested, and deployed.
  • Establish governance for Secure SDLC and DevSecOps practices, integrating security controls, automated testing, secure coding standards, and risk management directly into day‑to‑day development workflows.
  • Drive a secure‑by‑design and secure‑by‑default culture by providing standards, patterns, and guidance that enable development teams to proactively build security into applications rather than addressing it after deployment.
  • Partner with engineering, platform, and architecture teams to embed application security requirements into Agile delivery models, CI/CD pipelines, development toolchains, cloud‑native environments, and third‑party integrations.
  • Provide expert guidance on secure design decisions, vulnerability remediation, risk‑based control selection, and the adoption of emerging technologies while balancing security, business needs, and delivery velocity.
  • Define and enforce security assurance activities and quality gates—including SAST, DAST, SCA, penetration testing, and code review practices—as integrated components of the software development process.
  • Act as the senior application security advisor and escalation point for complex vulnerabilities, design‑level risks, exception requests, and secure software delivery challenges.

What you should have:

  • A bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or an equivalent combination of education and experience.
  • At least 7-10 years of progressive experience in application security, software security, cybersecurity, secure software engineering, or secure software delivery.
  • A proven experience developing and implementing enterprise application security standards, governance frameworks, and security control requirements.
  • A demonstrated success embedding and operationalizing application security within day‑to‑day software development practices, ensuring security is integrated throughout the SDLC/SSDLC, Agile, DevOps, and DevSecOps delivery processes.
  • A strong expertise partnering with development teams to bake secure‑by‑design and secure‑by‑default principles, secure coding standards, and automated security controls into application design, development, testing, deployment, and CI/CD pipelines.
  • Extensive experience leading application security assurance activities, including secure architecture and design reviews, threat modeling, SAST, DAST, SCA, and penetration testing oversight and remediation validation.
  • A proven ability to assess complex application security risks, prioritize remediation efforts, and provide risk‑based guidance to senior leaders, architects, engineers, and delivery teams.
  • Excellent communication, influencing, and stakeholder management skills, with the ability to translate complex technical risks into business‑impact terms, drive adoption of secure development practices, and deliver results in complex, evolving environments.

Technical requirements:

  • A deep expertise in application security principles, secure coding practices, and common application attack techniques.
  • A strong understanding of modern development approaches, CI/CD pipelines, and cloud‑native application architectures.
  • The ability to interpret and apply recognized security frameworks and standards (e.g. ISO 27001/27002, NIST, ITSG‑33) in an application security context.

Professional certifications:

One or more relevant security certifications required or strongly preferred, such as:

  • CSSLP (Certified Secure Software Lifecycle Professional).
  • CISSP (Certified Information Systems Security Professional).
  • GIAC application or software security–related certification.
  • Another recognized application security or secure software development certification.
  • Cloud security or DevSecOps‑related certifications are considered an asset.

Posting closing date: Note, the competition will remain active until filled.

Our commitment to diversity, equity, and inclusion

We’re committed to employment equity and encourage women, Indigenous Peoples, persons with disabilities, veterans and persons of all races, ethnicities, religions, abilities, sexual orientations, and gender identities and expressions to apply. We also welcome applications from non-Canadians who are eligible to work in Canada.

CMHC is an inclusive workplace where diversity of thought – and of people – are recognized, valued, and considered essential to achieving our mission.

We know that applying for a new job can be both exciting and daunting, and we appreciate your effort. If you are selected for an interview or testing, please advise us if you require an accommodation.

If you applied before and you were not successful don’t worry – we're always posting new positions, so don’t hesitate to give it another shot. We’re excited to see what you bring to the table this time around!

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Specialist, Security Applications (AppSecOps)
Senior Specialist, Security Applications (AppSecOps)

Canada Mortgage and Housing Corporation • Ottawa

Hybrid
CAD 104,000 - 130,000
Annual paid vacation
Performance incentive
Group insurance plan
+3
Senior Specialist, Security Applications (AppSecOps)
Senior Specialist, Security Applications (AppSecOps)

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) • Ottawa

Hybrid
CAD 104,000 - 131,000
Defined benefit pension plan
Comprehensive group insurance plan
Support towards personal and professional growth
Specialist, IT Security Risk Management
Specialist, IT Security Risk Management

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) • Ottawa

Hybrid
CAD 87,000 - 109,000
Accrued vacation
Annual performance bonus
Group insurance coverage
+3
Senior Specialist, Software Engineering (Full Stack Developer)
Senior Specialist, Software Engineering (Full Stack Developer)

Canada Mortgage and Housing Corporation • Ottawa

Hybrid
CAD 104,000 - 130,000
Annual vacation
Performance incentive
Group insurance
+2
Senior Specialist, Software Engineering
Senior Specialist, Software Engineering

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) • Ottawa

Hybrid
CAD 104,000 - 130,000
Annual vacation
Performance incentive
Defined benefit pension
+1
Specialist, IT Security Risk Management
Specialist, IT Security Risk Management

Canada Mortgage and Housing Corporation • Ottawa

On-site
CAD 87,000 - 109,000
Annual performance bonus
Group insurance coverage
Training and mentorship
+1
Advisor, Software Engineering
Advisor, Software Engineering

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) • Ottawa

Hybrid
CAD 129,175 - 161,469
Annual paid vacation
Performance incentive
Defined benefit pension
+4
Bilingual Advisor, Software Engineering
Bilingual Advisor, Software Engineering

Canada Mortgage and Housing Corporation • Ottawa

Hybrid
CAD 129,000 - 161,000
Annual Paid Vacation
Performance Incentive
Group Insurance Plan
+2
Senior Specialist, Software Engineering (CI/CD & Automation Engineering)
Senior Specialist, Software Engineering (CI/CD & Automation Engineering)

Canada Mortgage and Housing Corporation • Montreal (administrative region)

Hybrid
CAD 104,000 - 130,000
Annual paid vacation
Performance incentive
Group insurance plan
+2
Specialist, Identity & Access Management
Specialist, Identity & Access Management

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) • Ottawa

Hybrid
CAD 86,000 - 109,000
Annual Paid vacation
Annual individual performance incentive
Defined benefit pension plan
+3