Application Security Analyst to advance DevSecOps using SAST, DAST, SCA, and CI/CD pipelines - 1658 / 1670 / 1671 (Toronto)

Application Security Analyst to advance DevSecOps using SAST, DAST, SCA, and CI/CD pipelines - 1658 / 1670 / 1671 (Toronto)

09 Oct
|
S.i. Systems
|
Toronto

09 Oct

S.i. Systems

Toronto

Duration: Until April 9, (possibility of extension) Location: Downtown Toronto - Hybrid — primarily remote; onsite 1–2 times per quarter (optional additional visits) Join a financial services environment supporting global application security and vulnerability management initiatives.

This role focuses on hands-on application security analysis, security testing, Dev

SecOps support, and collaboration with development and Dev

Ops teams across web, mobile, and API environments.

The position includes direct involvement with application security tooling, vulnerability remediation, automation, and operational support activities.

This is a contract prospect supporting maternity leave coverage with potential extension based on future openings.

Must Haves 2+ yrs in IT Design/Application Design & Implementation 3+ yrs Cyber Application Security experience 1+ yrs automating systems, designing automation.

Software development background (C++/Java/.NET) (2+ yrs) Experience in managing Application Security platforms SAST/DAST/SCA/MOBILE (1+yrs) Solid understanding of Dev

SecOps and Agile Security concepts.

Hands on experience with SAST, SCA, DAST, MAST tools and techniques Expert knowledge of OWASP top 10 (Web, Mobile, APIs) and SANS top 25 University or College diploma in Computer Science, engineering or equivalent.

Certification: CISSP/CEH or cyber security certification Nice to Have Security certifications such as GWAPT, GWEB, CEH, CASE, CSSLP or similar preferred but not required.





Experience reading and understanding Pen test findings.

Programming knowledge preferred Experience with secure development and testing of APIs, microservices, containers and Cloud (AWS) is a big plus.

Knowledge of software applications both development and the vendor procurement life cycle.

Designing and implementing Dev

SecOps CI/CD Pipelines (1+yrs) Experience working in process engineering Strong working knowledge of Java, J2EE, web services and application integration technologies Working and designing cloud solutions (1+ yrs) Responsibilities Assist with running and management of application security tools such as SAST, SCA, MAST, DAST, etc.

Review vulnerability results and provide remediation direction to delivery teams Conduct reviews on tools and provide the relevant tuning and upgrades with respect to penetration test findings.

Create metrics (KPI and KRIs) for vulnerability management program and present to senior management.

Participate in crafting the Application Security and vulnerability management directives as required.

Educate development teams on OWASP top 10 vulnerabilities for Web, Mobile and APIs.

Automate redundant security tasks and bring in efficiencies within existing security processes.

Provide ongoing support of mobile and web application systems in production including responding to operational requests, problem analysis, resolution, escalation, and reporting as necessary Create and maintain supporting documentation

📌 Application Security Analyst to advance DevSecOps using SAST, DAST, SCA, and CI/CD pipelines - 1658 / 1670 / 1671 (Toronto)
🏢 S.i. Systems
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: application security analyst to advance devsecops using sast, dast, sca, and ci/cd pipelines - 1658 / 1670 / 1671 (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: application security analyst to advance devsecops using sast, dast, sca, and ci/cd pipelines - 1658 / 1670 / 1671 (toronto) / toronto