Назад
Company hidden
5 дней назад

Application Security Senior Specialist (Fintech)

85 000 - 105 000CAD
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Application Security Senior Specialist (Fintech): Embedding secure-by-design practices across the SDLC for digital payment applications with an accent on threat modeling, vulnerability remediation, DevSecOps tooling, and cloud-native security. Focus on integrating automated security testing into CI/CD pipelines, assessing application risks, and guiding engineering teams across web, mobile, and backend systems.

Location: Toronto, Canada; flexible hybrid work model

Salary: CAD 85,000–105,000 per year, plus eligibility for a short-term incentive plan

Company

hirify.global connects Canadians through secure digital payments, identity verification, and fraud protection, supporting Canada’s financial ecosystem.

What you will do

  • Embed security controls, secure coding practices, and secure-by-design principles throughout the software development lifecycle.
  • Conduct secure design reviews, threat modeling, architecture assessments, application security assessments, code reviews, and vulnerability analysis.
  • Triage vulnerabilities across web, mobile, and backend systems, provide remediation guidance, and validate fixes.
  • Maintain and optimize SAST, SCA, DAST, secrets scanning, container security, and CI/CD security tooling.
  • Assess application risks and support PCI DSS, SOC 2, OWASP, NIST, audit, and enterprise risk reporting activities.
  • Advise engineering, product, cloud, and security teams; deliver secure coding training and communicate risks to technical and non-technical stakeholders.

Requirements

  • 5+ years of experience in application security, software security engineering, or related roles in FinTech, SaaS, or cloud-native environments.
  • Strong knowledge of microservices, APIs, containers, serverless architectures, DevSecOps, and SSDLC frameworks.
  • Hands-on experience with SAST, SCA, DAST, secrets scanning, CI/CD security tooling, threat modeling, code reviews, and vulnerability assessments.
  • Proficiency in at least one programming language, such as Java, Python, JavaScript, or Go, with knowledge of secure coding practices.
  • Knowledge of AWS, Azure, or GCP security principles and familiarity with OWASP Top 10, CWE, NIST, and related frameworks.
  • Eligibility to work for hirify.global in Canada in a full-time capacity is required. Background checks are required before employment.

Nice to have

  • Cybersecurity certifications such as CISSP, CSSLP, CCSP, or OSCP.

Culture & Benefits

  • Flexible hybrid work model with a focus on work-life balance.
  • Generous vacation and wellness days.
  • Employer-paid benefits and an employer-funded RRSP program.
  • 24/7 confidential employee and family assistance program.
  • Pregnancy and parental leave top-up, plus charitable donation matching.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →