Senior Specialist, Security Applications (AppSecOps) (Ottawa)

Senior Specialist, Security Applications (AppSecOps) (Ottawa)

05 Aug
|
CMHC - SCHL
|
Ottawa

05 Aug

CMHC - SCHL

Ottawa

Job Requisition ID: 12213 Position Status: Permanent Full Time Position Type: Hybrid Office Location: Ottawa (ON); Montreal (QC) Travel Requirement: Limited Language Designation: Bilingual Language Skill Levels (Read/Write/Speak): CBC Security Requirement: Secret Salary: Our salaries generally range from $104,180.28to $130,225.36and are based on qualifications and experience.

About CMHC The work you do and the work we do together matters.

We come to work every day with a common purpose: to contribute to a well-functioning housing system.

At CMHC, we hold ourselves accountable for our results and support our colleagues in their achievements.

We thrive on collaboration, connecting across CMHC and involving the right people to get our work done.

Our leadership style is guided by trust , where our leaders favour an adaptive approach based on the needs of their teams.

Join us and be part of a team that''s committed to making a real difference and be part of something meaningful.

Whats in it for you Weve got the purpose, the people and the perks you need for a fulfilling career.

Heres the comprehensive and generous benefits you get when youre a permanent employee: Annual Paid vacation.

Annual individual performance incentive.

Defined benefit pension plan.

Comprehensive group insurance plan to support your well-being from day one.

Support towards your personal and professional growth with training, mentorship and more.

An inclusive workplace culture and workplace.

While positions at CMHC require some in-office presence, alternative work arrangements may be considered for Indigenous candidates.

Members of the following employment equity deserving groups will be prioritized for this job: Indigenous Peoples About the role Join the Technology and Business Transformation team, in the Bilingual Senior Specialist, Application Security.

You''ll be responsible for designing, governing, and continuously improving the enterprise Application Security (App

Sec) program to ensure that applications and softwaredelivered services are designed, built, tested, and operated in alignment with the organizations risk tolerance, security strategy, and regulatory obligations.

The role provides expertlevel advisory services to senior management, architects, and delivery leadership, and is accountable for the effectiveness and outcomes of application security controls across the full Secure Software Development Lifecycle (SSDLC / SDLC), including controls embedded in Agile and Dev

SecOps delivery models.

Open to internal employees in a Remote position or with a current Hybrid exception living at more than 125 km from a CMHC office.

What youll do: Lead and evolve the enterprise Application Security framework,



ensuring security requirements are embedded throughout the software development lifecycle and become a core part of how applications are designed, built, tested, and deployed.

Establish governance for Secure SDLC and Dev

SecOps practices, integrating security controls, automated testing, secure coding standards, and risk management directly into day-to-day development workflows.

Drive a secure-by-design and secure-by-default culture by providing standards, patterns, and guidance that enable development teams to proactively build security into applications rather than addressing it after deployment.

Partner with engineering, platform, and architecture teams to embed application security requirements into Agile delivery models, CI/CD pipelines, development toolchains, cloud-native environments, and third-party integrations.

Provide expert guidance on secure design decisions, vulnerability remediation, risk-based control selection, and the adoption of emerging technologies while balancing security, business needs, and delivery velocity.

Define and enforce security assurance activities and quality gatesincluding SAST, DAST, SCA, penetration testing, and code review practicesas integrated components of the software development process.

Act as the senior application security advisor and escalation point for complex vulnerabilities, design-level risks, exception requests, and secure software delivery challenges.

What you should have: A bachelors degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or an equivalent combination of education and experience.

At least 7-10 years of progressive experience in application security, software security, cybersecurity, secure software engineering, or secure software delivery. A proven experience developing and implementing enterprise application security standards, governance frameworks, and security control requirements. A demonstrated success embedding and operationalizing application security within day-to-day software development practices, ensuring security is integrated throughout the SDLC/SSDLC, Agile, Dev

Ops, and Dev

SecOps delivery processes. A strong expertise partnering with development teams to bake secure-by-design and secure-by-default principles, secure coding standards, and automated security controls into application design, development, testing, deployment,



and CI/CD pipelines.

Extensive experience leading application security assurance activities, including secure architecture and design reviews, threat modeling, SAST, DAST, SCA, and penetration testing oversight and remediation validation. A proven ability to assess complex application security risks, prioritize remediation efforts, and provide risk-based guidance to senior leaders, architects, engineers, and delivery teams.

Excellent communication, influencing, and stakeholder management skills, with the ability to translate complex technical risks into business-impact terms, drive adoption of secure development practices, and deliver results in complex, evolving environments.

Technical requirements: A deep expertise in application security principles, secure coding practices, and common application attack techniques. A strong understanding of modern development approaches, CI/CD pipelines, and cloudnative application architectures.

The ability to interpret and apply recognized security frameworks and standards (e.g. ISO 27001/27002, NIST, ITSG33) in an application security context.

Professional certifications: One or more relevant security certifications required or strongly preferred, such as: CSSLP (Certified Secure Software Lifecycle Professional). CISSP (Certified Information Systems Security Professional). GIAC application or software securityrelated certification.

Another recognized application security or secure software development certification.

Cloud security or Dev

SecOpsrelated certifications are considered an asset.

Posting closing date: Note, the competition will remain active until filled.

Our commitment to diversity, equity, and inclusion Were committed to employment equity and encourage women, Indigenous Peoples, persons with disabilities, veterans and persons of all races, ethnicities, religions, abilities, sexual orientations, and gender identities and expressions to apply.

We also welcome applications from non-Canadians who are eligible to work in Canada. CMHC is an inclusive workplace where diversity of thought and of people are recognized, valued, and considered essential to achieving our mission.

Learn more about our commitment to diversity and inclusion What happens after you apply We know that applying for a new job can be both exciting and daunting, and we appreciate your effort.

Learn more about our hiring process .

If you are selected for an interview or testing, please advise us if you require an accommodation.

If you applied before and you were not successful dont worry we''re always posting new positions, so dont hesitate to give it another shot.

Were excited to see what you bring to the table this time around!

📌 Senior Specialist, Security Applications (AppSecOps) (Ottawa)
🏢 CMHC - SCHL
📍 Ottawa

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior specialist, security applications (appsecops) (ottawa) / ottawa

Subscribe to this job alert:

Get the latest job offers by email for: senior specialist, security applications (appsecops) (ottawa) / ottawa