30 Jul
|
407 ETR
|
Vaughan
Title: Application Security Analyst Department: Information Technology Location: 6300 Steeles Ave West, Woodbridge Total Potential Compensation: $95,000-$115,000 Position Summary: As an Application Security Analyst , you willbe responsible forsupporting and operating core security capabilities across 407 ETRs digital environment, with a primary focus on application security.
This includes promoting secure-by-design practices throughout the SDLC and supporting the integration and operation of security tooling and automation, such as SAST, DAST, SCA, ASPM, and penetration testing services.
You will work closely with Architecture, Dev
Ops, QA, Product teams, and external partnerstoembed security controls into requirements, design, development, testing, and release activities, andtrackand manage security vulnerabilities through remediation.
Thisrole also contributes to improving the overall cyber and technology risk posture, with measurable improvements reflected in the Technology and Cyber Risk Indices (TRI/SRI).
Hours of work are onsite, Monday to Friday, 7.5 hours daily, or asrequired.
After-hours support and on-call duties may berequiredfor priority releases or security incidents.
Position Responsibilities: App
Sec Strategy & SDLC Integration Embed security requirements andnonfunctional controls into epics, features, and user stories;maintainsecurity traceability throughout the lifecycle.
Lead threat modeling at design time for current and changed services (web, mobile, APIs, microservices) and ensure mitigations are implemented prior to coding.
Define and operate SDLC security gates (precommit, build, test, deployment) with policydriven thresholds (e.g., fail on Critical/High) and exceptions governance.
Dev
SecOps
Tooling & Automation Implement and tune SAST, DAST, SCA and ASPM integrations within CI/CD, ensuring coverage, accuracy, and developerfriendly feedback loops; coordinate PTaaS cycles aligned to release schedules Partner with Dev
Ops to secure build pipelines, artifacts, and environments (e.g.,IaCscanning, container image hardening,
secrets management, SBOM generation and validation) Work with platform teams to evolve pipelines consistent with the 407 ETR Dev
Ops framework andfuturestateCI/CD models Findings Management & Risk Reporting Operate a unified findings intake (ASPM as system of record) for automated tool outputs and manual assessments; triage, prioritize, and track remediation to closure Apply a risk based SLA model (severity, exploitability, asset criticality) and escalate overdue items; publish weekly triage outcomes and monthly KPIs.
Report App
Sec posture using TRI/SRI aligned metrics (e.g., unresolvedcriticals, meantimetoremediate, coverage, policy conformance) Secure Engineering Enablement Provide secure coding guidance , sample patterns, and remediation support for developers; deliver targeted training and office hours Collaborate on architecture reviews , pentest scoping, and change risk assessments for web and mobile (using established changetype workflow) Contribute to App
Sec policies/standards and improve documentation (playbooks, runbooks, definition of done security criteria) Additional
Technical Experience Experience with Data Loss Prevention (DLP) technologies and controls, including policy configuration, monitoring, and incident investigation, isrequired Experience with Single Sign-On (SSO) integrations and identity federation protocols is an asset.
Compliance & Vendor Management Ensure controls align with PCI DSS Secure SDLC , ISO 27001/27002 , and NISTDev
SecOpsguidance (e.g., SP 800 204D) ; support internal/external audits and evidence collection Manage App
Sec vendor relationships and deliverables per the Application Security Managed Service scope (ASPM,PTaaS,
continuous monitoring) Note: This job description is not intended to be all-inclusive.
The employee may perform other related duties, as assigned, to meet the ongoing needs of the organization.
Qualifications Minimum5+ years of experience in IT Security, with strong hands-on experience in Security Operations.
College Diploma or University Degree in Computer Science, Engineering, or related field. EDR platforms (e.g., endpoint containment, alert triage, investigation). NDR technologies and network-based threat detection.
Security Incident Response and Investigation.
Strong understanding of attacker techniques and defensive controls (MITRE ATT&CK;).
Experience working in regulated or audit-driven environments.
Strong understanding of authentication, authorization, MFA, RBAC, and privileged access concepts. SSO Authentication: Experience implementing and supporting SSO solutions for secure user access across enterprise applications.
Preferred Qualifications Knowledge of standing up a mature Application Security framework Experience with enterprise SOC tooling including SIEM, EDR, NDR, SOAR.
Experience operating security controls in hybrid (onprem and cloud) environments.
Familiarity with Security Risk Index (SRI), cyber risk metrics, or risk-based reporting.
Knowledge of network architecture and segmentation concepts.
We are actively seeking to fill this role as it is a current vacancy.
About 407 ETR Highway 407 ETR is an all-electronic open-access toll highway located in the Greater Toronto Area in Ontario, Canada.
The highway spans 108 kilometres from Burlington in the west to Pickering in the east. 407 International Inc. is the sole shareholder of 407 ETR and is owned by: Cintra Global S.E., a subsidiary of Ferrovial S.A. (48.29%) Canada Pension Plan Investment Board (CPP Investments) and other institutional investors with non-controlling interests (44.20%) Public Sector Pension Investment Board (PSP Investments) (7.51%) Learn more at Note:
📌 Application Security Analyst (Vaughan)
🏢 407 ETR
📍 Vaughan