Application Security Consultant - SCA (Global Security)

rbc

Toronto

On-site

GBP 68,000 - 91,000

Full time

5 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

RBC is seeking an Intermediate Developer to join the Application Security team as a bridge between security and development. You will provide hands-on security expertise with a focus on Software Composition Analysis and secure coding practices across enterprise projects.

You will support application teams, triage SCA results, and drive security improvements while continuing to grow your development skills in a collaborative environment.

Qualifications

  • Familiarity with application security best practices.
  • Experience with SCA tools or open-source dependency management.
  • 2+ years of professional experience developing consuming REST APIs.
  • Basic understanding of open-source security.
  • Strong proficiency in at least one primary language: Python, Java, JavaScript, or .NET.
  • Solid understanding of HTTP, API design patterns and RESTful principles.
  • Experience with relational databases and SQL.
  • Hands-on experience with CI/CD tools (Jenkins, GitHub Actions, GitLab CI).
  • Experience with Threat Modelling and Risk Assessment activities.
  • Understanding of agile methodology (Scrum, Kanban).
  • Experience with data visualization or analytics tools.
  • Knowledge of software design patterns and SOLID principles.
  • Knowledge of OWASP, SANS, or other security frameworks.
  • Willingness to learn and grow in application security specialization.

Responsibilities

  • Support end users of application security testing tools, managing tickets.
  • Triage SCA scan results and communicate needs to application teams.
  • Act as primary contact for application teams bridging security and development.
  • Drive security practices and improve enterprise security posture.
  • Educate stakeholders on application security and open source vulnerabilities.
  • Integrate application security processes and tools into development pipelines.
  • Participate in and lead application security assessment activities.
  • Contribute to design/implementation of testing workflows and troubleshoot configurations.
  • Design and develop RESTful APIs following security standards.
  • Write clean, maintainable code for data processing and analysis.
  • Leverage open source packages responsibly, aware of security implications.
  • Collaborate with senior developers and security consultants to deliver solutions.
  • Participate in code reviews and improve security/development practices.

Job description

Job Description
What is the opportunity?

We are seeking a talented Intermediate Developer to join our Application Security team and serve as a bridge between security and development. You will provide technical execution and expertise in application security, with a specialization in Software Composition Analysis (SCA) in the area of open-source security. Working across the enterprise, you will support application teams, drive security best practices, and improve RBC's overall security posture through the design and implementation of application security initiatives. You will balance strategic security responsibilities with hands-on development work, leveraging both your strong development skills and security expertise to deliver impact across the organization. This is an excellent opportunity to grow your expertise in application security while building on your strong development foundation.

We're Looking For
  • Someone curious about application security and open-source vulnerabilities
  • A developer with solid fundamentals who's ready to grow into security
  • A collaborator who can bridge technical and security conversations
  • Someone comfortable learning new tools and frameworks on the job
What will you do?
  • Support end users of application security testing tools, managing tickets through a ticketing platform
  • Prioritize and triage SCA scan results, communicating needs and recommendations to application teams
  • Act as a primary point of contact for application teams, bridging security and development functions
  • Drive security practices and improve security posture across the enterprise by working with application development teams
  • Educate key organizational stakeholders (developers, security consultants) on application security matters and open source vulnerabilities
  • Assist in the integration of application security processes and tools into existing enterprise development processes and pipelines
  • Participate in and lead a range of application security assessment activities
  • Contribute to the design and implementation of application security testing workflows and troubleshoot tool configurations and resolve scanning issues
  • Design and develop RESTful APIs following best practices, security standards, and industry guidelines
  • Write clean, maintainable code for data processing, manipulation, and analysis
  • Leverage open source packages and libraries responsibly, understanding their security implications and vulnerabilities
  • Collaborate with senior developers, security consultants, and cross-functional teams to deliver quality solutions and advance security initiatives
  • Participate in code reviews and contribute to continuous improvement of security and development practices
  • Debug and troubleshoot applications to resolve security and functional issues efficiently
  • Document code and maintain technical documentation including security considerations
  • Contribute to the full software development lifecycle from design through deployment, with security integration
  • Proactively solve problems to ensure application development teams can effectively use the latest application security testing tools
  • Research and keep up to date on application security emerging threats, techniques, tools, and trends
  • Participate in system design discussions and architectural decisions with a security lens
  • Learn from and mentor with senior security and development team members to continuously improve your security expertise
  • Work in a diverse environment leveraging team members' experience and knowledge
What do you need to succeed?
Must-have
  • Familiarity with or interest in application security best practices; exposure to secure coding principles
  • Experience supporting or working with SCA tools, or demonstrated interest in application security and dependency management
  • 2+ years of professional experience developing and consuming REST APIs and applications
  • Basic understanding of open-source security; experience managing or evaluating dependencies (will expand expertise on the job)
  • Strong proficiency in at least one primary language: Python, Java, JavaScript, or .NET
  • Solid understanding of HTTP protocols, API design patterns, and RESTful principles
  • Experience working with relational databases and SQL
  • Hands-on experience with CI/CD tools and pipelines (Jenkins, GitHub Actions, GitLab CI) and understanding of DevOps and DevSecOps approaches
  • Experience with Threat Modelling and Risk Assessment activities
  • Understanding of agile methodology (Scrum, Kanban)
  • Experience with data visualization or analytics tools
  • Knowledge of software design patterns and SOLID principles
  • Knowledge of OWASP, SANS, or other security-related frameworks
  • Passion for or demonstrated interest in application security and secure coding practices
  • Willingness to learn and grow in application security specialization
  • Strong ability to manage client and stakeholder relations
  • Strong problem-solving skills and attention to detail
  • Ability to work collaboratively in an
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Application Security Specialist: SCA & Secure DevOps
Application Security Specialist: SCA & Secure DevOps

rbc • Toronto

On-site
GBP 68,000 - 91,000
Application Security Specialist
Application Security Specialist

Experis - ManpowerGroup • Greater London

On-site
GBP 75,000 - 110,000
Competitive salary
Annual bonus
Car allowance
+7
Application Security (AppSec) Engineer
Application Security (AppSec) Engineer

AND Digital • London

On-site
GBP 60,000 - 80,000
Security Assurance Lead
Security Assurance Lead

Motability Operations Ltd • Greater London

On-site
GBP 70,000 - 100,000
Technical Security Consultant
Technical Security Consultant

Barclay Simpson • City Of London

On-site
GBP 75,000 - 110,000
Senior Application Security Specialist
Senior Application Security Specialist

Sanderson • Greater London

Hybrid
GBP 67,000 - 89,000
Application Security Consultant
Application Security Consultant

Vastbouw • Greater London

On-site
GBP 70,000 - 110,000
Senior Application Security Analyst
Senior Application Security Analyst

Global Relay • Greater London

On-site
GBP 90,000 - 130,000
Technical Security Consultant
Technical Security Consultant

Barclay Simpson • Greater London

On-site
GBP 80,000 - 110,000
Senior DevSecOps Architect
Senior DevSecOps Architect

JPMorgan Chase & Co. • Greater London

On-site
GBP 120,000 - 180,000