This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
Are you an Application Security Analyst with experience developing security requirements and designing and implementing security solutions? Our Government client is seeking someone with the skillset for an initial 6 months with the option to extend the contract term by an additional 1 year and 6 months at the client's sole discretion
Job Responsibility
Leads the evaluation, selection, and implementation of SAST, DAST, and SCA tooling, including integration into CI/CD pipelines and development of detailed remediation runbooks for scan findings
Works with DevSecOps to develop and maintain secure coding standards, guidelines, and training materials for development teams
Conducts application security assessments, threat modeling sessions, and architecture reviews for new and existing applications
Champions security culture by embedding into Agile development teams as a security subject matter expert
Documents designs as well as produces technical reports in support of security initiatives
Triages and prioritizes application security vulnerabilities, working with development teams on remediation strategies
Develops and maintains security testing automation to enable continuous assurance of application security posture
Leads and completes security risk reviews on software, SaaS, third party and written code
Monitors emerging AI and ML security threats, application security threats, vulnerabilities and attack techniques and proposes new solutions to emergent risks in these areas
Develops technical security requirements and provides guidance to projects during the solution design phase
Collaborates and coordinates with application, operations and product teams to provide guidance on the development of secure product designs that meet security requirements
Mentors and upskills team members on application security best practices and tooling
Proactively identifies risks and issues and proposes solutions to remove barriers
Performs validation and tuning of security testing tools to provide accurate and actionable results that drive improvements to overall security posture
Performs security monitoring of solutions and participates as a subject matter expert in security incident response scenarios
Performs other related duties as required
Requirements
Bachelor's degree in Technology, Engineering, Computer Science, or a related field
A minimum of 8-10 years of experience in progressively senior technical roles with responsibility focused on information security processes, products and projects
Very strong knowledge in secure software engineering
Experience with securing cloud environments (MS Azure)
Must have excellent customer-service, listening, communication and problem-solving skills
Must be able to implement programs and solutions to measure and sustain the security posture of large complex environments
Ability to communicate complex security issues and develop security user stories in language that non-technical stake holders can understand
Experience with Agile methods (Scrum) and DevSecOps practices is a definite asset