Jobs.ca
Jobs.ca
Language
TekStaff IT Solutions logo

Application Security Analyst

Remote
Toronto, Ontario, Canada
Mid Level
CONTRACTOR

About the role

TekStaff's Client has a current vacancy for " Application Security Analyst ”

Job Description This is a 8 month contract located in Toronto, ON/ Hybrid (primarily remote; onsite 1–2 times per quarter (optional additional visits)

Overview

You are as unique as your background, experience and point of view. Here, you’ll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll have new and exciting opportunities to make life brighter for our clients - who are at the heart of everything we do. Discover how you can make a difference in the lives of individuals, families and communities around the world. Sun Life seeks a talented individual to fill the role of Application Security Analyst within Application Security team. The ideal candidate will play a key role in Application Security, Vulnerability management, and security testing within Sun Life.

Job description

The successful candidate will play a critical role in Sun Life to advance DevSecOps. In this position the incumbent will lead the evaluation, creations and implementation of application security tools, processes within the CI/CD Pipeline's globally. The successful candidate must not only understand the cyber security issues associated with application design and implementation but also must be willing to embrace a development attitude as they will be working closely alongside developers and other DevOps professionals to achieve a secure role out of DevSecOps across Sun Life's major operating geographies globally.

Responsibilities

Assist with running and management of application security tools such as SAST, SCA, MAST, DAST, etc.

Review vulnerability results and provide remediation direction to delivery teams

Conduct reviews on tools and provide the relevant tuning and upgrades with respect to penetration test findings. Create metrics (KPI and KRIs) for vulnerability management program and present to senior management. Participate in crafting the Application Security and vulnerability management directives as required. Educate development teams on OWASP top 10 vulnerabilities for Web, Mobile and APIs. Automate redundant security tasks and bring in efficiencies within existing security processes. Provide ongoing support of mobile and web application systems in production including responding to operational requests, problem analysis, resolution, escalation, and reporting as necessary Create and maintain supporting documentation

Critical Skills / Must-Haves

2+ yrs in IT Design/Application Design & Implementation 3+ yrs Cyber Application Security experience 1+ yrs automating systems, designing automation.

Software development background (C++/Java/.NET) (2+ yrs)

Experience in managing Application Security platforms SAST/DAST/SCA/MOBILE (1+yrs) Solid understanding of DevSecOps and Agile Security concepts.

Hands on experience with SAST, SCA, DAST, MAST tools and techniques

Expert knowledge of OWASP top 10 (Web, Mobile, APIs) and SANS top 25

Soft Skills

Demonstrated experience leading vulnerability management and analysis. Self-motivated, proactive, driven and strong problem-solving skills. Ability to communicate effectively to technical and nontechnical audiences and work with business partners as well as infrastructure teams Excellent communication skills Working in agile environment.

Ability to create professional looking Visio diagrams

Nice-to-Haves

Security certifications such as GWAPT, GWEB, CEH, CASE, CSSLP or similar preferred but not required. Experience reading and understanding Pen test findings.

Programming knowledge preferred

Experience with secure development and testing of APIs, microservices, containers and Cloud (AWS) is a big plus. Knowledge of software applications both development and the vendor procurement life cycle.

Designing and implementing DevSecOps CI/CD Pipelines (1+yrs)

Experience working in process engineering Strong working knowledge of Java, J2EE, web services and application integration technologies Working and designing cloud solutions (1+ yrs)

Education: University or College diploma in Computer Science, engineering or equivalent. Certification: CISSP/CEH or cyber security certification Interview Process 1 interview

TekStaff may use artificial intelligence (AI) tools as part of the applicant screening process. However, applications will also be reviewed by a member of our Recruitment team to ensure a fair and thorough assessment.

About TekStaff IT Solutions

IT Services and IT Consulting
51-200
Founded in 2006

Just over 15 years ago TekStaff IT Solutions Inc was founded based on the need for a localized, professional staffing firm in the Greater Toronto Area. After gaining much recognition, and achieving a solid reputation, TekStaff has become a leading supplier of placement services. Today, we are acknowledged as a top leader in Canadian recruiting and have crossed borders securing contracts throughout the United States. We remain focused on developing long-term relationships with client companies and professionals looking for employment. At TekStaff, we are proud of our contributions to the business and IT industry and excited to continue assisting individuals with leveraging their careers. TekStaff family thrives in an environment of teamwork and growth. Our client-focused, professional culture focuses on continuous learning and collaboration and provides opportunities for personal and professional development. We value and encourage collegiality and work-life balance. TekStaff IT Solutions Inc. is an equal opportunity employer committed to diversity in the workplace. In addition, TekStaff IT Solutions Inc. is committed to providing accommodations for people with disabilities during the recruitment and selection process. In the event you require any accommodations, please advise us in advance and we will work with you to meet your needs.

Similar Jobs