21 Sep
|
Wawanesa
|
Winnipeg
Job ID:9997Employment Type:Existing RoleWorking Business Language:EnglishSalary:$110,000 - $130,000 (subject to factors such as location, market conditions, and experience)Wawanesa offers a hybrid work workplace where employees can work from any of our offices or remotely, with flexibility between on‑site and remote work.Job OverviewThe Information Security Specialist – Application Security role will contribute to Wawanesa’s success by delivering application security services to our enterprise client groups. This role ensures that Wawanesa’s internal Application and Development teams can deliver secure products to the organization.Job ResponsibilitiesPerform evaluations of client systems, web applications, APIs, and their supporting networks to discover vulnerabilitiesConfigure, run, and monitor automated security testing toolsReview and assess automated security reportsThoroughly document exploit chain/proof of concept scenarios for internal client consumptionAssist clients with the design, implementation, and monitoring of security measures for the protection of web applicationsIdentify, define, and implement system security requirements for external and internal facing web applications and systemsAssist with vulnerability risk assessmentsFollow established practices and processesPerform a role in cyber incident response as requiredGenerate reports based on test findingsPerform other duties as assignedQualificationsBachelor’s degree in computer science, an analytical discipline,
or equivalent experience3+ years of web application security testing experienceKnowledge of secure development best practicesKnowledge of web application vulnerabilities and security considerationsWorking knowledge of industry‑standard technical security controlsFamiliarity with vulnerability assessment and penetration best practicesExperience working with Agile software development teamsExperience working with secure software development lifecyclesExperience with the following:Vulnerability and penetration testing techniques and toolsBurp SuiteMarkup, scripting, and programming languages such as HTML, XML, JavaScript, PHP, Python, Bash, C#, Java, and .NETPossess or working towards one of the following certifications:GIAC Penetration Tester (GPEN)GIAC Web Application Penetration Tester (GWAPT)GIAC Certified Incident Handler (GCIH)Offensive Security Certified Expert (OSCE)Offensive Security Certified Professional (OSCP)GIAC Certified Web Application Defender (GWEB)Must have the ability to communicate effectively, both verbally and in writing, to interact with internal teams and build relationshipsKnowledge of OWASP Top 10 and OWASP AI Top 10Knowledge of SonarQube, SAST, and DAST toolsAbility to work independently and within a teamKnowledge of and experience in the insurance industry is considered an assetDiversity Equity, Inclusion & BelongingWawanesa is committed to Diversity, Equity, Inclusion, and Belonging. We welcome applications from all qualified candidates, including racialized persons, women, Indigenous Peoples, persons with disabilities, members of the 2SLGBTQIA+ community, gender‑diverse and neurodiverse individuals, and anyone who can contribute to further diversification of thought and ideas.All Wawanesa job applicants are subject to Wawanesa's Privacy Policy.Please note that the recruitment process for this position may involve the use of AI tools to screen, assess, or select applicants. All final decisions are taken or reviewed by human recruiters and human hiring leaders in compliance with all applicable legislation.#J-18808-Ljbffr
📌 Information Security Specialist - Application Security - $110,000 - $130,000 A Year (Winnipeg)
🏢 Wawanesa
📍 Winnipeg