Senior Specialist, Security Applications

5 days ago

Ottawa, ON, Canada Canada Mortgage and Housing Corporation Full-time

Senior Specialist, Security Applications (AppSec)

Job Requisition ID: 12213

Position Status:Permanent Full Time

Position Type:Hybrid

Travel Requirement:Limited

Language Skill Levels (Read/Write/Speak):CBC

Security Requirement:Secret

Salary:Our salaries generally range from $104,180.28to $130,225.36and are based on qualifications and experience.

About CMHC

The work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system.

At CMHC, we hold ourselves accountable for our results and support our colleagues in their achievements. We thrive on collaboration, connecting across CMHC and involving the right people to get our work done. Our leadership style is guided by trust, where our leaders favour an adaptive approach based on the needs of their teams.

Join us and be part of a team that's committed to making a real difference and be part of something meaningful.

What’s in it for you

We’ve got the purpose, the people and the perks you need for a fulfilling career. Here’s the comprehensive and generous benefits you get when you’re a permanent employee:

  • Annual Paid vacation.
  • Annual individual performance incentive.
  • Comprehensive group insurance plan to support your well-being from day one.
  • Support towards your personal and professional growth with training, mentorship and more.
  • An inclusive workplace culture and environment.
  • While positions at CMHC require some in-office presence, alternative work arrangements may be considered for Indigenous candidates.

Members of the following employment equity deserving groups will be prioritized for this job: Indigenous Peoples

About the role

Join the Technology and Business Transformation team, in the Bilingual Senior Specialist, Application Security. You'll be responsible for designing, governing, and continuously improving the enterprise Application Security (AppSec) program to ensure that applications and software‑delivered services are designed, built, tested, and operated in alignment with the organization’s risk tolerance, security strategy, and regulatory obligations.

The role provides expert‑level advisory services to senior management, architects, and delivery leadership, and is accountable for the effectiveness and outcomes of application security controls across the full Secure Software Development Lifecycle (SSDLC / SDLC), including controls embedded in Agile and DevSecOps delivery models.

Open to internal employees in a Remote position or with a current Hybrid exception living at more than 125 km from a CMHC office.

What you’ll do:

  • Lead and evolve the enterprise Application Security framework, ensuring security requirements are embedded throughout the software development lifecycle and become a core part of how applications are designed, built, tested, and deployed.
  • Establish governance for Secure SDLC and DevSecOps practices, integrating security controls, automated testing, secure coding standards, and risk management directly into day‑to‑day development workflows.
  • Drive a secure‑by‑design and secure‑by‑default culture by providing standards, patterns, and guidance that enable development teams to proactively build security into applications rather than addressing it after deployment.
  • Partner with engineering, platform, and architecture teams to embed application security requirements into Agile delivery models, CI/CD pipelines, development toolchains, cloud‑native environments, and third‑party integrations.
  • Provide expert guidance on secure design decisions, vulnerability remediation, risk‑based control selection, and the adoption of emerging technologies while balancing security, business needs, and delivery velocity.
  • Define and enforce security assurance activities and quality gates—including SAST, DAST, SCA, penetration testing, and code review practices—as integrated components of the software development process.
  • Act as the senior application security advisor and escalation point for complex vulnerabilities, design‑level risks, exception requests, and secure software delivery challenges.

What you should have:

  • A bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related discipline, or an equivalent combination of education and experience.
  • At least 7-10 years of progressive experience in application security, software security, cybersecurity, secure software engineering, or secure software delivery.
  • A proven experience developing and implementing enterprise application security standards, governance frameworks, and security control requirements.