Назад
Company hidden
5 дней назад

Product Security Specialist (Cybersecurity)

85 500 - 105 600CAD
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Product Security Specialist (Cybersecurity): Performing security evaluations, code reviews, threat modeling, penetration testing, and security automation for connected-transportation products with an accent on vulnerability analysis, secure architecture, and scanner integration. Focus on tracing source code across multiple languages, automating SCA and CI pipelines, identifying coverage gaps, and communicating risk assessments to technical and non-technical stakeholders.

Location: Oakville, Ontario, Canada; flexible hybrid working model with in-person and virtual work

Annual base salary: $85,500–$105,600 CAD

Company

hirify.global develops IoT, connected-transportation, fleet-management, analytics, and machine-learning solutions that process billions of data points daily.

What you will do

  • Perform security evaluations, vulnerability assessments, penetration testing, manual code reviews, and security-based architecture reviews.
  • Validate scanner findings by tracing source code and provide developer-level remediation recommendations.
  • Write and maintain Bash and Python automation for scanner execution, scan input generation, CI pipeline integration, Google Cloud storage, and reporting.
  • Conduct threat modeling, assess security coverage, identify gaps, and support secure architecture and security-by-design practices.
  • Prepare technical assessment reports and explain risk findings to developers, product owners, management, and other stakeholders.
  • Contribute to secure coding standards, developer training, security initiatives, and responses to emerging product threats.

Requirements

  • 5–8 years of experience in security evaluation, security analysis, security code reviews, or relevant development.
  • Bachelor’s degree in Computer Science, Information Management, Engineering, or a related field, or equivalent experience.
  • Experience with source-code, dynamic, and dependency scanners such as Veracode, Fortify, Sentinel, OWASP Dependency-Check, Netsparker, or Qualys.
  • Knowledge of C, C#, .NET, Python, JavaScript/TypeScript, XML, JSON, SOAP, REST, npm, and NuGet.
  • Competency with Linux, Windows, Google Compute Engine, Bash, and Python, with the ability to learn additional programming languages quickly.
  • Strong communication, analytical, organizational, and multitasking skills; security certifications and high-technology industry experience are assets.

Culture & Benefits

  • Flexible hybrid work supported by cloud applications, collaboration tools, and asynchronous working.
  • Home office reimbursement and reliable home internet support requirements.
  • Medical and dental benefits, retirement savings program, and parental leave top-up program for full-time permanent employees.
  • Online learning and networking opportunities, electric vehicle purchase incentive, and work-life balance initiatives.
  • Diverse, inclusive, and accessibility-focused work environment.

Hiring process

  • Employment offers are contingent on proof of eligibility to work and successful completion of a background check.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →