12 дней назад
Senior Security Service Manager (Application Security)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Security Service Manager (Application Security) (SAST/DAST/SCA): Advancing an enterprise-wide application security program by strengthening security testing capabilities and integrating protection throughout application and data lifecycles with an accent on governance, vulnerability management, and risk-based remediation. Focus on leading security testing services, evaluating emerging threats, advising development and infrastructure teams, and communicating security strategy to executive leadership.
Location: Toronto, ON — Toronto-81 Bay, 18th Floor. Hybrid arrangement with 1–3 days per week on-site and the remaining days remote. Candidates must be legally eligible to work at the specified location and hold a valid work or study permit where applicable.
Company
A relationship-oriented bank focused on modern banking services, client protection, and an empowering work environment.
What you will do
- Lead the creation and ongoing refinement of the enterprise Application Security strategy, governance, business cases, proof of concepts, and product-owner initiatives.
- Oversee and continuously improve SAST, DAST, SCA, and related security testing services across the application lifecycle.
- Measure testing effectiveness, analyze vulnerabilities and emerging threats, and strengthen risk mitigation and remediation strategies.
- Advise application development, operations, and infrastructure teams on integrating security testing into workflows and prioritizing risks.
- Prepare executive documentation and presentations, deliver security awareness and training, and communicate recommendations to improve the organization’s security posture.
- Build relationships with industry peers and vendors while keeping application security capabilities aligned with the evolving threat landscape.
Requirements
- Senior-level experience in application security, vulnerability management, data security standards, and security best practices.
- Experience managing or implementing application security services such as SAST, DAST, SCA, or similar capabilities.
- Experience with dynamic and static application security testing, penetration testing, web application firewalls, runtime protection, mobile application security, and broader threat and vulnerability management.
- Strong strategic leadership, communication, analytical thinking, critical thinking, collaboration, and continuous improvement skills.
- Legal eligibility to work in Canada and a valid work or study permit where applicable are required.
Nice to have
- DevSecOps knowledge and experience.
- CISSP, CISA, or CISM certification in good standing.
Culture & Benefits
- Hybrid work environment with flexibility to manage work activities across on-site and remote days.
- Competitive salary, incentive pay, banking benefits, and a benefits program.
- Defined benefit pension plan, employee share purchase plan, vacation offering, and wellbeing support.
- Professional growth opportunities, including a paid Purpose Day for personal development.
- Inclusive and accessible candidate and employee experience built around trust, teamwork, accountability, and recognition.
Hiring process
- The process may include an attribute-based assessment and additional skills tests, such as simulations, coding, or French proficiency assessments.
- Artificial intelligence tools may be used during recruitment.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →