30 Jul
|
Artech
|
Toronto
Job Title: Application Security SME Location: Toronto, Ontario Duration: 06-12 Months Job Description: The ideal candidate will have deep expertise in up-to-date application architectures, secure coding practices, security testing methodologies, and the ability to partner effectively with development, engineering, Dev
Ops, and risk teams to embed security throughout the software delivery lifecycle.
Required Skills & Qualifications Bachelors degree in Computer Science, Information Security, Engineering, or related field 8 years of experience in application security, secure software engineering, cybersecurity architecture, or related roles Proven experience implementing and managing application security programs in enterprise environments Strong understanding of Secure SDLC / SSDLC, Dev
SecOps principles, OWASP Top 10, API Security Top 10, and common software and web application vulnerabilities Hands-on experience with application security testing tools such as Checkmarx, Fortify, Veracode, Sonar
Qube, Burp Suite, App
Scan, Acunetix, Snyk, Black Duck, Mend/White
Source Experience in threat modeling methodologies (e.g., STRIDE) Strong knowledge of authentication, authorization, encryption, secrets management, and secure design principles Experience working with cloud platforms such as Azure, AWS, or GCP Strong verbal and written communication skills with the ability to work across technical and non-technical stakeholders Preferred Skills & Qualifications Experience in highly regulated industries such as Banking, Financial Services, Insurance (BFSI), healthcare, or public sector Familiarity with security requirements related to standards/frameworks such as NIST,
ISO 27001, PCI-DSS, SOC 2, OSFI guidance (for Canada-based roles) Experience with CI/CD platforms such as Azure Dev
Ops, Jenkins, Git
Hub Actions, or Git
Lab Exposure to container security, Kubernetes security, and cloud workload protection Familiarity with red team / blue team collaboration for application-layer attack simulation and response readiness Day-to-Day Responsibilities Act as the Subject Matter Expert (SME) for application security across enterprise platforms and development teams Define and enhance the organizations application security strategy, standards, and control frameworks Provide expert guidance on secure design, secure coding, threat mitigation, and vulnerability management Partner with engineering and architecture teams to embed security-by-design principles into applications and digital initiatives Drive implementation and maturity of the Secure Software Development Lifecycle (SSDLC) Integrate security controls and testing into CI/CD pipelines and Dev
SecOps workflows Perform application architecture and design reviews to identify security risks and recommend remediation strategies Lead threat modeling sessions for web, mobile, API, and cloud-native applications Lead or support application security assessments, including SAST, DAST, SCA, API Security Testing, and manual security reviews Collaborate with cloud and platform engineering teams to secure application workloads in Azure, AWS, or GCP Ensure application security practices align with internal security policies and external standards/regulations For immediate consideration please click APPLY to begin the screening process with Alex.
📌 Hiring Application Security SME in Toronto, Ontario
🏢 Artech
📍 Toronto