This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
We are looking for an Application Security Analyst (AppSec) to join the Information Security Protection and Analysis team of a major financial institution. This is a re-opened position with an adjusted scope focusing on automation and developer empowerment. In this role, you will apply strong technical expertise to influence secure development practices across the enterprise. You will work closely with development, DevOps, and security teams to integrate security into every stage of the SDLC and enhance AppSec tooling capabilities. This is a long-term contract (until March 31, 2027) with potential for renewal. The position is remote, with occasional in-person meetings required in Quebec City or Montreal.
Job Responsibility:
Integrate, configure, and maintain Application Security tools such as SAST, DAST, SCA, and container scanning
Automate security testing processes and maintain AST tool infrastructure
Support development teams in adopting and integrating AppSec tools into their SDLC
Use automated tooling to detect vulnerabilities and act as a technical security expert to assist teams in remediation
Conduct manual code reviews for security compliance purposes
Document and update standards and guides in a fast-evolving application security landscape
Create and maintain processes helping developers integrate and use security tools
Recommend corrective actions through clearly structured guides and procedures
Guide development teams on designing applications with a security-first mindset
Support threat modeling exercises and document access models
Ensure alignment with security frameworks such as NIST and ISO 27001
Requirements:
Strong understanding of the SDLC, DevOps practices, and CI/CD pipelines
Hands‑on experience with AppSec tooling including SAST, DAST, SCA, container scanning, secrets detection, and IaC scanning
Ability to write and maintain scripts in Python, Bash, or PowerShell to automate security tasks
Knowledge of web technologies such as JavaScript or TypeScript
Knowledge of backend stacks such as .NET or Java
Strong knowledge of common vulnerability types and recommended remediations, specifically OWASP Top 10
Familiarity with threat modeling and Agile methodologies
Strong analytical thinking and ability to communicate complex security concepts to technical and non‑technical audiences
Experience integrating security into cloud environments is an asset
Experience with Snyk mandatory
Mandatory bilingualism (French and English) for frequent interactions with English-speaking partners and suppliers
Nice to have:
Experience integrating security into cloud environments is an asset
What we offer:
Benefit from a stable contract of over one year
Work in a remote environment with occasional travel to Montreal or Quebec City
Play a key role in improving the cybersecurity maturity of a large organization
Collaborate in an environment where ideas are openly shared