Back to job search
Raise logo
RaiseVerified Job Source

Senior Application Security Specialist

  • Calgary, Alberta, Canada
  • Remote
  • Posted Sep 24, 2026
  • 1 position

Opens an external site

Sign in to save this job
Employment type
Contract
Experience level
Mid-level · 2+ years
Minimum education
Professional degree
Posting language
English
Working hours
40 hours per week
Seniority
Associate
Application method
Direct apply is available

Job summary

The specialist will conduct advanced penetration testing, threat emulation, and crisis simulations to fortify financial infrastructure. They will also bridge the gap between technical security findings and business risk management for non-technical stakeholders.

Job details

Security Developer Contract Length: 3 Months Location: Calgary, Alberta – open to remote Candidates Raise is currently hiring a Security Developer on behalf of our client. They’re expanding their team to meet growing needs, making this a unique opportunity to work with an industry leader. Our Client is a market leading financial institution Note: The primary pay rate is based on T4 classification; however, we will also consider applications from candidates interested in an INC classification, where applicable. Description Security Developer in this role will join our clients growing security engineering team. In this role, you will play a pivotal part in our Threat Intelligence & Security Configuration Project, driving advanced technical assessments, simulating sophisticated threats, and fortifying our financial infrastructure against emerging cyber risks. You will bridge the gap between deep technical vulnerability analysis and cross-functional business execution, ensuring our security posture remains resilient and dynamic. Responsibilities Advanced Threat Emulation & Testing: Execute hands-on penetration testing across web applications, APIs, networks, and cloud environments. Design and conduct complex red team operations to validate organizational detection and response capabilities against real-world adversary tactics. Crisis Simulation & Tabletop Leadership: Design and facilitate strategic enterprise-wide crisis simulations and tactical, team-specific tabletop exercises to enhance corporate communication and refine incident response playbooks. Vendor Governance & Lifecycle Management: Govern external third-party penetration testing vendors by defining technical scopes, establishing Rules of Engagement (ROEs), and validating final findings for organizational risk acceptance. Cross-Functional Risk Translation: Bridge the gap between technical security and business units by translating complex vulnerabilities into clear business risks, driving cross-functional remediation with non-technical stakeholders. Remediation Governance & Defensive Sync: Partner with blue teams and engineering to provide technical remediation guidance, validate security fixes, and translate assessment findings into prioritized engineering action items. Operational Optimization & Tooling: Author high-quality technical documentation (standard operating procedures and runbooks) and develop custom automation scripts to continuously scale assessment efficiency. Qualifications 3+ years of hands-on professional experience in information security, application security, penetration testing, or offensive security roles (preferably within financial services or regulated enterprise environments). Deep expertise in identifying and exploiting OWASP Top 10 vulnerabilities in complex web applications and modern API architectures. Proficiency in internal/external network assessments, lateral movement techniques, and infrastructure hardening. Demonstrated hands-on security experience with GCP (Google Cloud Platform) or other major cloud infrastructure providers (AWS, Azure). Exceptional capability in drafting clear, actionable technical documentation, executive summaries, and standard operating procedures (SOPs). Strong understanding of threat intelligence feeds, adversary tactics (e.g., MITRE ATT&CK framework), and security configuration baselines. Ability to script and automate routine testing or reporting tasks using languages such as Python, Bash, or Go. Outstanding communication skills with the ability to translate highly technical findings into business risks for non-technical stakeholders. Education and Certifications Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field (or equivalent practical industry experience). Industry-recognized security certifications such as OSCP (Offensive Security Certified Professional), GPEN, GWAPT, PNPT, or cloud security certifications (e.g., Google Professional Cloud Security Engineer). Additional Information A requirement for candidates to be considered for this role will be to complete a criminal and credit check (including Canadian Credit Risk Score)

What you’ll do

The specialist will conduct advanced penetration testing, threat emulation, and crisis simulations to fortify financial infrastructure. They will also bridge the gap between technical security findings and business risk management for non-technical stakeholders.

Requirements

Candidates must have at least 3 years of professional experience in information or application security, including hands-on penetration testing. A bachelor's degree in a relevant field and industry-recognized certifications like OSCP or GPEN are required.

Listed skills

  • Go · Preferred
  • Google Cloud · Preferred
  • Python · Preferred

Other relevant skills

Identified from the job description. Confirm important requirements above.

  • Penetration testing
  • Application security
  • Threat intelligence
  • Vulnerability analysis
  • Red team operations
  • Cloud security
  • GCP
  • Python
  • Bash
  • Go
  • OWASP Top 10
  • API security
  • Incident response
  • Network security
  • Infrastructure hardening
  • Risk assessment

Job areas

  • Security & Safety
  • Technology
  • Software
  • Finance & Accounting
  • Engineering

More jobs you can apply to directly

Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.

Browse all Easy Apply jobs