Intermediate Application Security Engineer (Riviere-des-Prairies—Pointe-aux-Trembles)

Intermediate Application Security Engineer (Riviere-des-Prairies—Pointe-aux-Trembles)

07 Aug
|
Anvil
|
Riviere-des-Prairies—Pointe-aux-Trembles

07 Aug

Anvil

Riviere-des-Prairies—Pointe-aux-Trembles

Intermediate Application Security EngineerAbout ANVILANVIL is a trusted partner in the defence industry, delivering cutting‐edge solutions that enhance military capabilities and operational effectiveness. We extend our expertise to public safety, law enforcement, and national security organizations, accelerating mission‐critical decision‐making through analytical tools, automations, and game‐changing machine learning capabilities. ANVIL helps organizations discover, manage, enrich, fuse, and exploit the information available to them in support of Information Dominance and Decision Advantage.Job TypeFull Time Remote (Hybrid option available for those in the Ottawa area - 55 Murray Street Office). This role may require up to 25% travel, primarily within the National Capital Region, as needed.CompensationCAD $105,000 to $145,000 base salary – placement within range based on experience and qualifications.Role (Description)As an Intermediate Application Security Engineer, you will be an active contributor to ANVIL's growing application security program, working under the mentorship of our Senior Application Security Engineer and reporting to the Director of Security Engineering. This is a hands‐on, execution‐focused role – you will be the person keeping our AppSec tooling running, our vulnerability SLAs on track, and our security gates functioning reliably across the software development lifecycle.You will operate across a diverse and technically demanding environment: ANVIL's products are primarily deployed in air‐gapped, classified customer environments, while our development and demo infrastructure runs on GCP. You will need to be comfortable navigating both Linux and Windows systems and applying sound security judgment in contexts where external connectivity cannot be assumed.This role is well suited to someone early in their security engineering career who is eager to build depth across application security tooling, vulnerability management, and threat modeling – and who thrives with clear mentorship and real ownership of day‐to‐day security operations.We value people who have an ingrained sense of accountability to the team around them. As an ideal candidate, you are technically curious, detail‐oriented, and take pride in doing the fundamentals exceptionally well. You ask valuable questions, follow through on commitments, and communicate clearly when you hit blockers.This role may require up to 25% travel primarily in the National Capital Region. Eligible candidates must either possess or be eligible to obtain a Government of Canada Secret or Top Secret security clearance.Required QualificationsSecurity ClearanceEligible for Government of Canada Secret or Top Secret security clearanceEducation & ExperienceBachelor's degree in Software Engineering, Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience2-4 years of experience in application security, security engineering, or a closely related roleHands‐on experience operating AppSec tooling such as SAST, DAST, SCA, or container scanning platformsDemonstrated experience tracking,



triaging, and driving remediation of security vulnerabilities in a development environmentFamiliarity with secure software development practices and at least one SDLC methodologyFamiliarity with Linux and Windows operating environments from a security perspectiveFamiliarity with threat modeling methodologies (e.G., STRIDE, PASTA, LINDDUN, or Attack Trees)Experience with GCP or equivalent cloud platform for dev/staging environment securitySkills & CompetenciesWorking knowledge of application security principles and common vulnerability classes (OWASP Top 10, SANS CWE)Hands‐on experience with one or more AppSec tooling categories: SAST, DAST, SCA, container scanning, or secrets detectionProven ability to triage vulnerability findings, assess exploitability and risk, and communicate remediation priorities clearly to development teamsFamiliarity with CI/CD pipelines and how security tooling integrates within them (GitLab CI or equivalent)Familiarity with threat modeling concepts and a willingness to develop this skill under senior guidanceWorking knowledge of Linux and Windows system internals relevant to security — file permissions, user privilege models, common attack surfacesFamiliarity with digital forensic investigation concepts, including log analysis, artifact identification, and basic incident triageFamiliarity with containerization technologies (Docker, Kubernetes) and associated security considerationsStrong analytical mindset with exceptional attention to detail and ability to manage multiple open findings or workstreams simultaneouslyClear written and verbal communication skills, with the ability to write concise, actionable vulnerability reportsCollaborative work style with a willingness to learn from and contribute to a small, high‐trust security teamPreferred QualificationsRelevant certifications or coursework (CompTIA Security+, eJPT, CEH, GWEB, or equivalent entry/intermediate security credentials)Scripting and automation experience (Python, Go, Bash, Rust, or other)Experience with PostgreSQL, OpenSearch, or Elasticsearch from a security or operations perspectiveExperience with vulnerability management platforms or risk registersExperience with secret management platforms suited to air‐gapped environments (HashiCorp Vault, OpenBoa, or equivalent on‐premises solutions)Bilingualism French/EnglishExperience working in or closely with defence, public safety, or national security organizationsKey ResponsibilitiesAppSec Tooling & Pipeline IntegrationOperate and maintain ANVIL's AppSec tooling suite, including SAST, DAST, SCA, container scanning,



and secrets detectionMonitor pipeline security gates and ensure tooling is functioning correctly across active development projectsTune and refine scanning rules to reduce false positives and improve signal quality over timeSupport the onboarding of new repositories and services into existing AppSec tooling workflowsDocument tooling configurations, known issues, and operational runbooks to support team continuityVulnerability Management & SLA ComplianceTriage incoming vulnerability findings from automated scans, penetration tests, and third‐party advisoriesAssess exploitability, contextual risk, and business impact to produce clear, prioritized remediation guidance for development teamsTrack open findings against established SLAs, escalating aging or critical issues to the Senior Application Security Engineer as appropriateMaintain and report on the vulnerability register, providing regular status updates on remediation progressWork collaboratively with development teams to unblock remediation efforts and validate fixes once deployedThreat Modeling SupportParticipate in threat modeling sessions alongside the Senior Application Security Engineer, contributing findings and learning structured methodologies (STRIDE, PASTA, or equivalent)Assist in documenting threat models, data flow diagrams, and identified risks for new and evolving system architecturesHelp maintain threat libraries and reusable security design pattern documentation as the program maturesDevelop familiarity with ANVIL's architecture and deployment patterns to contribute meaningfully to future threat modeling engagementsSecure SDLC ParticipationParticipate in code reviews and design discussions as a security contributor, flagging concerns and suggesting mitigationsSupport the enforcement of security review gates and assist developers in understanding and resolving security findingsHelp maintain secure coding guidelines and contribute to developer‐facing security documentationAssist in preparing materials for developer security awareness initiatives under the direction of the Senior Application Security EngineerForensics & Incident SupportApply foundational forensic investigation skills to support incident triage, including log analysis, artifact identification, and timeline reconstruction on Linux and Windows systemsAssist the Director of Security Engineering and the Senior Application Security Engineer in incident response activities, following established procedures for evidence handling and chain‐of‐custody in classified environmentsDocument findings clearly and completely to support post‐incident review and lessons‐learned processesTechnical Support & CollaborationParticipate actively in sprint planning, security reviews, and team stand‐ups as a contributing security voiceProvide security guidance to development teams on day‐to‐day questions related to vulnerabilities, tooling, and secure codingSupport on‐site customer engagements for software product provisioning and security configuration as neededCompensation & BenefitsCompetitive salariesFlexible health benefits package through EquitableIndustry‐leading employer retirement contributions match #J-18808-Ljbffr

📌 Intermediate Application Security Engineer (Riviere-des-Prairies—Pointe-aux-Trembles)
🏢 Anvil
📍 Riviere-des-Prairies—Pointe-aux-Trembles

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: intermediate application security engineer (riviere-des-prairies—pointe-aux-trembles) / riviere-des-prairies—pointe-aux-trembles

Subscribe to this job alert:

Get the latest job offers by email for: intermediate application security engineer (riviere-des-prairies—pointe-aux-trembles) / riviere-des-prairies—pointe-aux-trembles