Specialist, Identity and Access Management

Procom

Ottawa

Hybrid

CAD 110,000 - 160,000

Full time

12 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Procom is seeking a Senior Specialist, Application Security (AppSec) for a Crown Corporation role in a hybrid work environment, with the Ottawa or Montreal area as the base. The candidate must be eligible for SECRET clearance and bring extensive AppSec experience.

The position focuses on designing, governing, and continuously improving the enterprise AppSec program, ensuring security is integrated throughout SSDLC/SDLC, Agile, DevOps, and DevSecOps delivery models.

Qualifications

  • Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related discipline, or equivalent experience.
  • 7–10 years of progressive experience in application security, software security, cybersecurity, secure software engineering, or secure software delivery.
  • Experience developing and implementing enterprise application security standards, governance frameworks, and security control requirements.
  • Experience embedding AppSec in SDLC/SSDLC, Agile, DevOps, and DevSecOps delivery processes.

Responsibilities

  • Lead and evolve the enterprise Application Security framework across the software development lifecycle.
  • Establish governance for Secure SDLC and DevSecOps practices with automated testing and secure coding standards.
  • Embed secure-by-design and secure-by-default principles into development workflows.
  • Partner with engineering and architecture teams to integrate AppSec in Agile, CI/CD, cloud-native environments, and third‑party integrations.
  • Provide guidance on secure design decisions, vulnerability remediation, and risk-based control selection.
  • Define and enforce security assurance activities, including SAST, DAST, SCA, penetration testing, and code reviews.

Skills

Application security
Secure SDLC
DevSecOps
Threat modeling
SAST
DAST
SCA
Penetration testing
Cloud native
CI/CD
Secure coding
Communication
Risk management
Secure-by-design

Education

Bachelor's degree in CS/IT/Cybersecurity

Job description

Procom is currently looking for a Senior Specialist, Security Applications (AppSec) for our client in the public sectorTHIS IS A PERMANENT ROLE WITH A CROWN CORPORATIONLOCATION: HYBRID (3 DAYS PER WEEK IN OFFICE, OPTION OF LOCATION IN THE OTTAWA OR MONTREAL AREA)CLEARANCE: SECRET (MUST BE ELIGIBLE)LANGUAGE: ENGLISHREFERENCES: 2RESUMES DUE: ASAPWhat you should have:A bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or an equivalent combination of education and experience.At least 7-10 years of progressive experience in application security, software security, cybersecurity, secure software engineering, or secure software delivery.A proven experience developing and implementing enterprise application security standards, governance frameworks, and security control requirements.A demonstrated success embedding and operationalizing application security within day-to-day software development practices, ensuring security is integrated throughout the SDLC/SSDLC, Agile, DevOps, and DevSecOps delivery processes.A strong expertise partnering with development teams to bake secure-by-design and secure-by-default principles, secure coding standards, and automated security controls into application design, development, testing, deployment, and CI/CD pipelines.Extensive experience leading application security assurance activities, including secure architecture and design reviews, threat modeling, SAST, DAST, SCA, and penetration testing oversight and remediation validation.A proven ability to assess complex application security risks, prioritize remediation efforts, and provide risk-based guidance to senior leaders, architects, engineers, and delivery teams.Excellent communication, influencing, and stakeholder management skills, with the ability to translate complex technical risks into business-impact terms, drive adoption of secure development practices, and deliver results in complex, evolving environments.Technical requirements:A deep expertise in application security principles, secure coding practices, and common application attack techniques.A strong understanding of modern development approaches, CI/CD pipelines, and cloud native application architectures.The ability to interpret and apply recognized security frameworks and standards (e.g. ISO 27001/27002, NIST, ITSG33) in an application security context.Professional certifications:One or more relevant security certifications required or strongly preferred, such as:CSSLP (Certified Secure Software Lifecycle Professional).CISSP (Certified Information Systems Security Professional).GIAC application or software security–related certification.Another recognized application security or secure software development certification.Cloud security or DevSecOps related certifications are considered an asset.***IF YOU ARE INTERESTED IN THIS POSITION, PLEASE SEND AN UPDATED RESUME IN WORD FORMAT WITH THE DETAILED INFORMATON THAT IS LISTED UNDER THE EXPERIENCE AND LIST THE PROESSIONAL AND TECHNICAL SKILLS THAT YOU HAVE WORKED WITH***STATEMENT OF WORKJoin the Technology and Business Transformation team, in the Bilingual Senior Specialist, Application Security. You'll be responsible for designing, governing, and continuously improving the enterprise Application Security (AppSec) program to ensure that applications and software delivered services are designed, built, tested, and operated in alignment with the organization’s risk tolerance, security strategy, and regulatory obligations.The role provides expert level advisory services to senior management, architects, and delivery leadership, and is accountable for the effectiveness and outcomes of application security controls across the full Secure Software Development Lifecycle (SSDLC / SDLC), including controls embedded in Agile and DevSecOps delivery models.What you’ll do:Lead and evolve the enterprise Application Security framework, ensuring security requirements are embedded throughout the software development lifecycle and become a core part of how applications are designed, built, tested, and deployed.Establish governance for Secure SDLC and DevSecOps practices, integrating security controls, automated testing, secure coding standards, and risk management directly into day-to-day development workflows.Drive a secure-by-design and secure-by-default culture by providing standards, patterns, and guidance that enable development teams to proactively build security into applications rather than addressing it after deployment.Partner with engineering, platform, and architecture teams to embed application security requirements into Agile delivery models, CI/CD pipelines, development toolchains, cloud-native environments, and third-party integrations.Provide expert guidance on secure design decisions, vulnerability remediation, risk-based control selection, and the adoption of emerging technologies while balancing security, business needs, and delivery velocity.Define and enforce security assurance activities and quality gates—including SAST, DAST, SCA, penetration testing, and code review practices—as integrated components of the software development process.Act as the senior application security advisor and escalation point for complex vulnerabilities, design-level risks, exception requests, and secure software delivery challenges.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

AppSec Lead - Secure SDLC & DevSecOps (Hybrid)
AppSec Lead - Secure SDLC & DevSecOps (Hybrid)

Canada Mortgage and Housing Corporation • Ottawa

Hybrid
CAD 104,000 - 130,000
Senior Specialist, Security Applications (AppSecOps)
Senior Specialist, Security Applications (AppSecOps)

Canada Mortgage and Housing Corporation (CMHC) Société canadienne d'hypothèques et de logement(SCHL) • Ottawa

On-site
CAD 104,180 - 130,225
Defined benefit pension plan
Comprehensive group insurance plan
Support towards personal and professional growth
Senior Information Security Analyst
Senior Information Security Analyst

TD Bank Group • Toronto

Hybrid
CAD 90,000 - 130,000
Senior Specialist, Security Applications (AppSec)
Senior Specialist, Security Applications (AppSec)

Canada Mortgage and Housing Corporation • Ottawa

Hybrid
CAD 104,000 - 130,000
Senior Vulnerability Manager
Senior Vulnerability Manager

CoFoMo Inc. • Montreal (administrative region)

Hybrid
CAD 120,000 - 170,000
Hybrid work model
RQ08587 - Security Specialist - Senior
RQ08587 - Security Specialist - Senior

Rubicon Path • Toronto

On-site
CAD 90,000 - 130,000
IT Application Security Manager
IT Application Security Manager

Randstad Digital • Toronto

Hybrid
CAD 100,000 - 140,000
RQ08438 - Security Specialist - Penetration Testing - Senior
RQ08438 - Security Specialist - Penetration Testing - Senior

Rubicon Path • Toronto

On-site
CAD 90,000 - 120,000
Executive Information Security Governance and Policy Consultant
Executive Information Security Governance and Policy Consultant

Nexasphere • Ottawa

Hybrid
CAD 130,000 - 190,000
Senior Cybersecurity Specialist
Senior Cybersecurity Specialist

STACK IT Recruitment • Burlington

On-site
CAD 154,000 - 181,000
Paid vacation and personal days
Annual bonus