Contract: 6 months with a possibility of extension
Typical Day in Role:
Product Execution & Planning
- Support the execution of the AppSec capability roadmap by defining implementable technical deliverables (stories, tasks) and maintaining a delivery-ready backlog.
- Define technical onboarding plans for applications and pipelines (prerequisites, connectivity, scanning modes, rollout waves etc).
- Work directly with engineering, DevOps, platform, and security teams to implement and operationalize AppSec capabilities in real delivery environments.
- Participate in Agile ceremonies and technical refinement to align scope, effort, and delivery sequencing.
- Lead working sessions to resolve implementation blockers (connectivity, authentication, proxying, build configuration, repository and pipeline patterns).
Stakeholder Engagement
- Collaborate with compliance, risk, and governance teams to ensure alignment with enterprise security goals.
- Develop and deliver training materials to educate internal teams on enablement & integrations.
- Support vendor and platform onboarding activities from a technical standpoint (access patterns, integration methods, operational readiness).
Secure SDLC & DevSecOps Enablement
- Support integration of application security controls and tooling into DevOps pipelines and developer workflows across diverse deployment environments to enable secure-by-design and secure-by-default software delivery.
- Define and implement SDLC processes and best practices used across engineering and security DevOps teams.
- Support AppSec SLAs using DevOps skill sets to solution and resolve across the application stack.
Technical Enablement
- Implement, configure, and integrate AppSec tools into CI/CD and developer workflows (e.g., SAST, DAST, SCA, secrets detection), including proof-of-concepts and rollout support.
- Troubleshoot and resolve integration issues across pipelines and application stacks (build tooling, credentials, network and proxy, scanning configuration).
- Improve efficacy by tuning policies and rulesets, reducing false positives, and strengthening vulnerability triage workflows.
- Create and maintain reference implementations, templates, and runbooks to scale onboarding and reduce manual effort.
- Help identify gaps in AppSec processes and coverage and propose practical improvements (secure design reviews, threat modeling touchpoints, shift-left controls).
- Assist in audits by producing implementation evidence and documentation of security controls (process, coverage metrics, operational KPIs
Candidate Requirements/Must Have Skills:
- 8-9 years of experience in an IT-related field with at least 3 years in DevSecOps engineering teams within Agile and up-to-date Software Development Life Cycle (SDLC) environments.
- 3+ years of domain expertise in Application Security (AppSec), including hands-on experience deploying and managing enterprise vendor security platforms (such as SCA, SBOM, SAST, DAST, MAST, API Security, and CNAPP).
- 3+ years of systems architecture and engineering experience designing and troubleshooting CI/CD pipelines (such as Jenkins, BitBucket, Azure DevOps, GitHub Actions). Strong proficiency with software build tools (such as Maven, Gradle) and package managers (such as npm).
- 3+ years of experience authoring, reviewing, and maintaining comprehensive technical documentation and architectural designs for complex, enterprise-scale platforms and solutions.
Nice-To-Have Skills:
- Experience within FI/ banking an asset
- 3+ years of hands-on experience with containerization and orchestration technologies,
specifically Docker and Kubernetes (k8s), including cluster architecture, performance tuning, and optimizing container workloads. Infrastructure as Code (IaC) experience preferred.
- 3+ years of robust cloud infrastructure (such as Azure, GCP, AWS) and system administration experience across Linux and Windows ecosystems, with deep knowledge of network troubleshooting, firewalls, routing, and proxy configurations.
- 3+ years of software development and scripting experience (such as Python, PowerShell, Bash, Java, C#, or .NET), with a strong focus on building, integrating, and consuming APIs across diverse architectures.
Soft Skills Required:
- Excellent written, presentation, and verbal communication skills to be able to work well with technical peers and business stakeholders at different levels within the organization
- Strong decision making, forward thinking and creative problem-solving skills to anticipate and respond quickly to technological/market influences
- Ability to work as part of a team, as well as work independently or with minimal direction
- Exceptional analytical and problem-solving abilities, paired with strong organizational, time-management, and cross-team communication skills.
Education:
- Post-secondary degree in a technical field such as computer science, computer engineering or related IT field preferred
FP Inc. is committed to creating an inclusive environment where all team members and clients feel like they belong. In accordance with the requirements set out in the Employment Standards Act, FP Inc. hereby declares that AI is utilized in the screening process for this position. The hourly compensation range for this role is $70/hr -$86/hr. We seek applicants with a wide range of abilities, and we provide an accessible candidate experience. We advocate for you and welcome anyone regardless of race, colour, religion, national origin, sex, physical or mental disability, or age.
#J-18808-Ljbffr
📌 Product Manager - AppSec, DevSecOps (Toronto)
🏢 FP
📍 Toronto