Procom is currently looking for a Senior Specialist, Security Applications (AppSec) for our client in the public sectorTHIS IS A PERMANENT ROLE WITH A CROWN CORPORATIONLOCATION: HYBRID (3 DAYS PER WEEK IN OFFICE, OPTION OF LOCATION IN THE OTTAWA OR MONTREAL AREA)CLEARANCE: SECRET (MUST BE ELIGIBLE)LANGUAGE: ENGLISHREFERENCES: 2RESUMES DUE: ASAPWhat you should have:A bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or an equivalent combination of education and experience.At least 7-10 years of progressive experience in application security, software security, cybersecurity, secure software engineering, or secure software delivery.A proven experience developing and implementing enterprise application security standards, governance frameworks, and security control requirements.A demonstrated success embedding and operationalizing application security within day-to-day software development practices, ensuring security is integrated throughout the SDLC/SSDLC, Agile, DevOps, and DevSecOps delivery processes.A strong expertise partnering with development teams to bake secure-by-design and secure-by-default principles, secure coding standards, and automated security controls into application design, development, testing, deployment, and CI/CD pipelines.Extensive experience leading application security assurance activities, including secure architecture and design reviews, threat modeling, SAST, DAST, SCA, and penetration testing oversight and remediation validation.A proven ability to assess complex application security risks, prioritize remediation efforts, and provide risk-based guidance to senior leaders, architects, engineers, and delivery teams.Excellent communication, influencing, and stakeholder management skills, with the ability to translate complex technical risks into business-impact terms, drive adoption of secure development practices, and deliver results in complex, evolving environments.Technical requirements:A deep expertise in application security principles, secure coding practices, and common application attack techniques.A strong understanding of modern development approaches, CI/CD pipelines, and cloud native application architectures.The ability to interpret and apply recognized security frameworks and standards (e.g. ISO 27001/27002, NIST, ITSG33) in an application security context.Professional certifications:One or more relevant security certifications required or strongly preferred, such as:CSSLP (Certified Secure Software Lifecycle Professional).CISSP (Certified Information Systems Security Professional).GIAC application or software security–related certification.Another recognized application security or secure software development certification.Cloud security or DevSecOps related certifications are considered an asset.***IF YOU ARE INTERESTED IN THIS POSITION, PLEASE SEND AN UPDATED RESUME IN WORD FORMAT WITH THE DETAILED INFORMATON THAT IS LISTED UNDER THE EXPERIENCE AND LIST THE PROESSIONAL AND TECHNICAL SKILLS THAT YOU HAVE WORKED WITH***STATEMENT OF WORKJoin the Technology and Business Transformation team, in the Bilingual Senior Specialist, Application Security. You'll be responsible for designing, governing, and continuously improving the enterprise Application Security (AppSec) program to ensure that applications and software delivered services are designed, built, tested, and operated in alignment with the organization’s risk tolerance, security strategy, and regulatory obligations.The role provides expert level advisory services to senior management, architects, and delivery leadership, and is accountable for the effectiveness and outcomes of application security controls across the full Secure Software Development Lifecycle (SSDLC / SDLC), including controls embedded in Agile and DevSecOps delivery models.What you’ll do:Lead and evolve the enterprise Application Security framework, ensuring security requirements are embedded throughout the software development lifecycle and become a core part of how applications are designed, built, tested, and deployed.Establish governance for Secure SDLC and DevSecOps practices, integrating security controls, automated testing, secure coding standards, and risk management directly into day-to-day development workflows.Drive a secure-by-design and secure-by-default culture by providing standards, patterns, and guidance that enable development teams to proactively build security into applications rather than addressing it after deployment.Partner with engineering, platform, and architecture teams to embed application security requirements into Agile delivery models, CI/CD pipelines, development toolchains, cloud-native environments, and third-party integrations.Provide expert guidance on secure design decisions, vulnerability remediation, risk-based control selection, and the adoption of emerging technologies while balancing security, business needs, and delivery velocity.Define and enforce security assurance activities and quality gates—including SAST, DAST, SCA, penetration testing, and code review practices—as integrated components of the software development process.Act as the senior application security advisor and escalation point for complex vulnerabilities, design-level risks, exception requests, and secure software delivery challenges.