We have other current jobs related to this field that you can find below


  • Old Toronto, Canada Security 1st Title, LLC Full time

    Our mission is to increase the success rate of small businesses. Traditional banking has been a growth limiter rather than a growth enabler for business owners, and we’re changing that. Relay is the all-in-one, collaborative money management platform. We’re building for employer SMBs and their finance function, internal and external, and are focused on...


  • Old Toronto, Canada Security 1st Title, LLC Full time

    Our mission is to increase the success rate of small businesses. Traditional banking has been a growth limiter rather than a growth enabler for business owners, and we’re changing that. Relay is the all-in-one, collaborative money management platform. We’re building for employer SMBs and their finance function, internal and external, and are focused on...


  • Old Toronto, Canada Relay Financial Full time

    Our mission is to increase the success rate of small businesses. Traditional banking has been a growth limiter rather than a growth enabler for business owners, and we’re changing that. Relay is the all-in-one, collaborative money management platform. We’re building for employer SMBs and their finance function, internal and external, and are focused on...


  • Old Toronto, Canada Relay Financial Full time

    Our mission is to increase the success rate of small businesses. Traditional banking has been a growth limiter rather than a growth enabler for business owners, and we’re changing that. Relay is the all-in-one, collaborative money management platform. We’re building for employer SMBs and their finance function, internal and external, and are focused on...


  • Old Toronto, Canada Relay Financial Full time

    Our mission is to increase the success rate of small businesses. Traditional banking has been a growth limiter rather than a growth enabler for business owners, and we’re changing that. Relay is the all-in-one, collaborative money management platform. We’re building for employer SMBs and their finance function, internal and external, and are focused on...


  • Old Toronto, Canada Relay Financial Full time

    Our mission is to increase the success rate of small businesses. Traditional banking has been a growth limiter rather than a growth enabler for business owners, and we’re changing that. Relay is the all-in-one, collaborative money management platform. We’re building for employer SMBs and their finance function, internal and external, and are focused on...


  • Old Toronto, Canada Relay Financial Full time

    Our mission is to increase the success rate of small businesses. Traditional banking has been a growth limiter rather than a growth enabler for business owners, and we’re changing that. Relay is the all-in-one, collaborative money management platform. We’re building for employer SMBs and their finance function, internal and external, and are focused on...


  • Old Toronto, Canada Relay Financial Full time

    Traditional banking has been a growth limiter rather than a growth enabler for business owners, and we’re changing that. Relay is the all-in-one, collaborative money management platform. We’re building for employer SMBs and their finance function, internal and external, and are focused on delivering a human-centric customer experience. Ultimately, we...


  • Old Toronto, Canada Security Bank & Trust Co. Full time

    Location: Toronto, Canada; (Remote from Toronto)The RoleTuneIn, a leading provider of audio streaming services, is seeking an experienced Senior Security Engineer to join our CloudOps team. The CloudOps team plays a pivotal role in the management of production tools such as AWS, CloudFlare, and GitHub self-hosted runners. This role will be instrumental in...


  • Old Toronto, Canada LZ Security & Service GmbH Full time

    Location: Toronto, Canada; (Remote from Toronto)The RoleTuneIn, a leading provider of audio streaming services, is seeking an experienced Senior Security Engineer to join our CloudOps team. The CloudOps team plays a pivotal role in the management of production tools such as AWS, CloudFlare, and GitHub self-hosted runners. This role will be instrumental in...


  • Old Toronto, Ontario, CA LZ Security & Service GmbH Full time

    Location: Toronto, Canada; (Remote from Toronto)The RoleTuneIn, a leading provider of audio streaming services, is seeking an experienced Senior Security Engineer to join our CloudOps team. The CloudOps team plays a pivotal role in the management of production tools such as AWS, CloudFlare, and GitHub self-hosted runners. This role will be instrumental in...


  • Old Toronto, Canada Robinhood Full time

    About the team + role Robinhood is looking for an Application Security Engineering Manager who is passionate about enabling the firm to build and deploy secure applications. A successful Application Security manager will possess a deep understanding of both information security and software engineering and have experience leading a team of engineers from...


  • Old Toronto, Canada Robinhood Full time

    About the team + role Robinhood is looking for an Application Security Engineering Manager who is passionate about enabling the firm to build and deploy secure applications. A successful Application Security manager will possess a deep understanding of both information security and software engineering and have experience leading a team of engineers from...


  • Toronto, Ontario, Canada Manulife Full time

    We are a leading financial services provider committed to making decisions easier and lives better for our customers and colleagues around the world. From our environmental initiatives to our community investments, we lead with values throughout our business. To help us stand out, we help you step up, because when colleagues are healthy, respected and...


  • Toronto, Ontario, Canada Abnormal Security Full time

    About The RoleAbnormal Security is looking for a Software Engineer II who is a solid software developer with a strong interest in Security & Privacy to join the Platform Security team. The Platform Security team owns the Security and Privacy platform services and infrastructure to uphold industry standards for the company's security posture and customer data...


  • Old Toronto, Canada Manulife Insurance Malaysia Full time

    Senior CyberArk Security EngineerWe are a leading financial services provider committed to making decisions easier and lives better for our customers and colleagues around the world. From our environmental initiatives to our community investments, we lead with values throughout our business. To help us stand out, we help you step up, because when colleagues...


  • Old Toronto, Canada Manulife Insurance Malaysia Full time

    Senior CyberArk Security EngineerWe are a leading financial services provider committed to making decisions easier and lives better for our customers and colleagues around the world. From our environmental initiatives to our community investments, we lead with values throughout our business. To help us stand out, we help you step up, because when colleagues...


  • Toronto, Ontario, Canada Wealthsimple Full time

    Position Overview:Wealthsimple is at the forefront of transforming financial management and is seeking skilled professionals to enhance their workforce. As Canada's leading fintech firm, Wealthsimple is committed to delivering clear and affordable financial solutions to over 3 million clients, managing assets exceeding $30 billion. The organization...


  • Toronto, Ontario, Canada Wealthsimple Full time

    Position Overview:Wealthsimple is at the forefront of transforming financial management and is seeking skilled professionals to enhance their team. As Canada's leading fintech organization, Wealthsimple is committed to delivering clear and affordable financial solutions to over 3 million clients, managing assets exceeding $30 billion. The company prioritizes...


  • Toronto, Ontario, Canada Wealthsimple Full time

    Position Overview:Wealthsimple is on a mission to transform the way we handle finances and is seeking skilled professionals to enhance their team. As Canada's leading fintech firm, Wealthsimple is committed to delivering clear and affordable financial solutions to over 3 million clients, managing assets exceeding $30 billion. The organization prioritizes...

Senior Application Security Engineer

2 months ago


Old Toronto, Canada Manulife Insurance Malaysia Full time

Senior Application Security Engineer

Your Opportunity

  • We are looking for an experienced and highly motivated Senior Application Security Engineer to join Manulife’s Global Wealth and Asset Management Application Security team. The role will push forward GWAMs Cross-Enterprise application security vision by creating guidance and mechanisms that enable the company to think firm-wide when considering capabilities development. You'll work closely with business, product, and technology partners to translate long-term objectives into designs that fuel firm-wide reuse and convergence.
  • As an Application Security Engineer, you will work closely with our GWAM IT Risk and Cybersecurity teams in improving the maturity of the practices within third-party and originally developed software solutions.
  • Our Manulife / John Hancock family is going through an exciting, yet challenging metamorphosis. We are transforming from a wise 130-year-old company into an agile 130-year-young company. This is a journey, and to quote T.S. Elliot; “The journey, Not the destination matters...”. On this journey, we expect all to bring their knowledge, skills and experience as a team and, when we don’t know, we will learn.
  • Within the Manulife family, our team is within Global Wealth and Asset Management and as a division we believe the truth is in the numbers. We believe it’s time to change the investment game. To do it differently by focusing on the value we bring our clients, rather than on the usual topics of performance and fees. We have just surpassed $1 trillion in assets under management with a diverse range of both public and private asset classes. Our division is global and have operations in North America, Asia and Europe and we serve a diverse range of clients from our own on-balance general account assets to institutional, retail and wealth.
  • The right individual will be a proactive, self-starter that enjoys and thrives when connecting people and technology to solve sophisticated problems at-scale. You will analyze, model, and develop sophisticated and high-level architecture plans that require the integration of multiple technologies and coordination of functional areas across the organization. If you have a passion and skill for long-term end-to-end thinking balanced with crafting architecture increments that enable value for customers now, this opportunity is for you
  • The Application Security team within the Enterprise Architecture and Risk organization is responsible for defining the application security building blocks and capabilities to embed cross-enterprise application security and optimize how security integrated into the SDLC. We are an organization that values diverse and big thinking, rewards both behaviors and delivery, and focuses on growth and continuous improvement – all in support of Manulife’s mission to help clients and one another succeed. This role is a unique opportunity to join a team and company at the beginning of a multi-year platform transformation whose work will have direct impact on company direction, our customers, and our industry.

What you’re good at

  • Collaborating with Product, Risk, Cyber and Technology teams to craft secure application security programs and patterns that enables business and technology vision.
  • Understand sophisticated modern and legacy integrations and business information models to ensure integrity and a strong security profile
  • Enterprise security and specifically developing large enterprise solutions with respect to developing security controls, methods to mitigate security risks
  • Designing for both functional and non-functional qualities, including availability, resiliency, security, privacy, etc.
  • Assisting the business in the scoping and planning of upcoming initiatives and roadmap items
  • Implementing application security practice including threat modeling, risk assessment, application security to ensure the non-functional requirements are identified, and controls/requirements are required to mitigate these risks.
  • Reviewing, advising, and providing feedback on security within and outside the team
  • Developing reference implementation patterns related to security solutions.
  • Helping to develop new and revising security governance (secure design reviews) processes to ensure alignment of a diverse set of technology projects with the enterprise target state vision.
  • Connecting your business and technical insights to develop innovative proposals for evolving Manulife’s platforms, introducing new products or capabilities, or improving processes that benefit the firm or its customers.

What you have

  • 5+ years Application Security Engineer experience
  • Ability to analyze the information flow and recommend appropriate technology to support the business process.
  • Experience enabling and actively guiding others on application security tools including Static Analysis (SAST), Dynamic Analysis (DAST), OSS (Open-source vulnerabilities).
  • Experience in reviewing security design of business applications and proposing countermeasure to address risk
  • Experience in providing application security support to developers.
  • Experience with Dev Sec Ops and securing different CD/CI pipelines using different types of security tools.
  • Experience and knowledge of security functions (AuthN, AuthZ, Transport Security, Secure Configuration, Data validation/sanitizations, security exceptions logging).
  • Hands-on experience in application and system penetration testing and code reviewing.
  • Experience with Threat modeling, secure development lifecycle and secure testing methodologies
  • Knowledge of Vault capabilities and Security Incident and Event management systems
  • Ability to evaluate new technologies and know the latest industry trends.
  • Good judgment and the ability to handle high pressure situations.
  • Knowledge of the enterprise security space: languages, frameworks (e.g. OWASP Top 10, NIST CSF), techniques, and industry trends.
  • Ability (and preference) to work in an Agile environment.
  • Refined presentation and communication skills and expertise interfacing and communicating effectively with both engineers and executives.
  • Security Certification preferred (CISSP, CISM, OSCP, etc.)

What can we offer you?

  • A competitive salary and benefits packages.
  • A growth trajectory that extends upward and outward, encouraging you to follow your passions and learn new skills.
  • A focus on growing your career path with us.
  • Flexible work policies and strong work-life balance.
  • Professional development and leadership opportunities.
#J-18808-Ljbffr