5 дней назад
Application Security Senior Specialist (Fintech)
85 000 - 105 000CAD
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Application Security Senior Specialist (Fintech): Embedding secure-by-design practices across the SDLC for digital payment applications with an accent on threat modeling, vulnerability remediation, DevSecOps tooling, and cloud-native security. Focus on integrating automated security testing into CI/CD pipelines, assessing application risks, and guiding engineering teams across web, mobile, and backend systems.
Location: Toronto, Canada; flexible hybrid work model
Salary: CAD 85,000–105,000 per year, plus eligibility for a short-term incentive plan
Company
connects Canadians through secure digital payments, identity verification, and fraud protection, supporting Canada’s financial ecosystem.
What you will do
- Embed security controls, secure coding practices, and secure-by-design principles throughout the software development lifecycle.
- Conduct secure design reviews, threat modeling, architecture assessments, application security assessments, code reviews, and vulnerability analysis.
- Triage vulnerabilities across web, mobile, and backend systems, provide remediation guidance, and validate fixes.
- Maintain and optimize SAST, SCA, DAST, secrets scanning, container security, and CI/CD security tooling.
- Assess application risks and support PCI DSS, SOC 2, OWASP, NIST, audit, and enterprise risk reporting activities.
- Advise engineering, product, cloud, and security teams; deliver secure coding training and communicate risks to technical and non-technical stakeholders.
Requirements
- 5+ years of experience in application security, software security engineering, or related roles in FinTech, SaaS, or cloud-native environments.
- Strong knowledge of microservices, APIs, containers, serverless architectures, DevSecOps, and SSDLC frameworks.
- Hands-on experience with SAST, SCA, DAST, secrets scanning, CI/CD security tooling, threat modeling, code reviews, and vulnerability assessments.
- Proficiency in at least one programming language, such as Java, Python, JavaScript, or Go, with knowledge of secure coding practices.
- Knowledge of AWS, Azure, or GCP security principles and familiarity with OWASP Top 10, CWE, NIST, and related frameworks.
- Eligibility to work for in Canada in a full-time capacity is required. Background checks are required before employment.
Nice to have
- Cybersecurity certifications such as CISSP, CSSLP, CCSP, or OSCP.
Culture & Benefits
- Flexible hybrid work model with a focus on work-life balance.
- Generous vacation and wellness days.
- Employer-paid benefits and an employer-funded RRSP program.
- 24/7 confidential employee and family assistance program.
- Pregnancy and parental leave top-up, plus charitable donation matching.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →
Похожие вакансии
12 дней назад
Senior Application Security Engineer
2 дня назад
Security Engineer (AI/LLM Security)
134 000 - 168 000$
8 дней назад
Staff Security Researcher (AI Security)
168 000 - 238 000$
8 дней назад
Principal Security Researcher (AI Security)
203 200 - 275 000$
Okta
6 дней назад
Staff Product Security Engineer (AI)
180 000 - 247 500$