Current jobs related to Lead Application Security Engineer - Canada - United Software Group Inc. - Canada


  • Canada Abnormal Security Corporation Full time

    Position OverviewAbnormal Security Corporation is seeking a Software Security Engineer II who possesses robust software development skills and a keen interest in Security & Privacy to become a vital member of the Platform Security team. Team ResponsibilitiesThe Platform Security team is responsible for managing the Security and Privacy platform services and...


  • Canada Abnormal Security Corporation Full time

    Position OverviewAbnormal Security Corporation is seeking a Software Security Engineer II who possesses robust software development skills and a keen interest in Security & Privacy to become a vital member of the Platform Security team. Team ResponsibilitiesThe Platform Security team is responsible for managing the Security and Privacy platform services and...


  • Canada Abnormal Security Corporation Full time

    About the RoleAbnormal Security Corporation is seeking a skilled Software Security Engineer to join our Platform Security team. As a key member of our team, you will be responsible for designing, developing, and releasing secure service-to-service communication frameworks and toolings, as well as integrating them with security operational analytics and...


  • Canada Abnormal Security Corporation Full time

    About the RoleAbnormal Security Corporation is seeking a skilled Software Security Engineer to join our Platform Security team. As a key member of our team, you will be responsible for designing, developing, and releasing secure service-to-service communication frameworks and toolings, as well as integrating them with security operational analytics and...


  • Canada Abnormal Security Corporation Full time

    About the RoleAbnormal Security Corporation is seeking a skilled Software Security Engineer to join our Platform Security team. As a key member of our team, you will be responsible for designing, developing, and releasing secure service-to-service communication frameworks and toolings, as well as integrating them with security operational analytics and...


  • Canada Abnormal Security Corporation Full time

    About the RoleAbnormal Security Corporation is seeking a skilled Software Security Engineer to join our Platform Security team. As a key member of our team, you will be responsible for designing, developing, and releasing secure service-to-service communication frameworks and toolings, as well as integrating them with security operational analytics and...


  • Canada Abnormal Security Corporation Full time

    Software Engineer II - Platform Security TeamAbnormal Security Corporation is seeking a skilled Software Engineer II to join our Platform Security team. As a key member of this team, you will be responsible for designing, developing, and releasing secure service-to-service communication frameworks and toolings, customer data security and privacy workflows,...


  • Canada Abnormal Security Corporation Full time

    Software Engineer II - Platform Security TeamAbnormal Security Corporation is seeking a skilled Software Engineer II to join our Platform Security team. As a key member of this team, you will be responsible for designing, developing, and releasing secure service-to-service communication frameworks and toolings, customer data security and privacy workflows,...


  • Canada Abnormal Security Corporation Full time

    Software Security EngineerAbnormal Security Corporation is seeking a skilled Software Security Engineer to join our Platform Security team. As a key member of our team, you will design, develop, and release secure service-to-service communication frameworks and toolings, customer data security and privacy workflows, and integrate them with security...


  • Canada Abnormal Security Corporation Full time

    Software Security EngineerAbnormal Security Corporation is seeking a skilled Software Security Engineer to join our Platform Security team. As a key member of our team, you will design, develop, and release secure service-to-service communication frameworks and toolings, customer data security and privacy workflows, and integrate them with security...


  • Canada Abnormal Security Corporation Full time

    Secure Service DeveloperAbnormal Security Corporation is seeking a skilled Software Security Engineer to join the Platform Security team. As a key member of the team, you will design, develop, and release secure service-to-service communication frameworks and toolings, customer data security and privacy workflows, and integrate them with security operational...


  • Canada Abnormal Security Corporation Full time

    Secure Service DeveloperAbnormal Security Corporation is seeking a skilled Software Security Engineer to join the Platform Security team. As a key member of the team, you will design, develop, and release secure service-to-service communication frameworks and toolings, customer data security and privacy workflows, and integrate them with security operational...


  • Canada Abnormal Security Corporation Full time

    {"h1": "Senior Software Security Engineer", "p": "At Abnormal Security Corporation, we're seeking a highly skilled Senior Software Security Engineer to join our Platform Security team. As a key member of our team, you will design, develop, and release secure-by-design and secure-by-default standards across our platform services and components. Your expertise...


  • Canada Abnormal Security Corporation Full time

    {"h1": "Senior Software Security Engineer", "p": "At Abnormal Security Corporation, we're seeking a highly skilled Senior Software Security Engineer to join our Platform Security team. As a key member of our team, you will design, develop, and release secure-by-design and secure-by-default standards across our platform services and components. Your expertise...


  • Canada Abnormal Security Corporation Full time

    Abnormal Security CorporationJob Title: Software Security EngineerJob Summary:We are seeking a highly skilled Software Security Engineer to join our Platform Security team at Abnormal Security Corporation. As a key member of our team, you will be responsible for designing, developing, and releasing secure service-to-service communication frameworks and...


  • Canada Abnormal Security Corporation Full time

    Software Security Engineer IIAbnormal Security Corporation is seeking a skilled Software Security Engineer II to join our Platform Security team. As a key member of our team, you will be responsible for designing, developing, and releasing secure service-to-service communication frameworks and toolings, customer data security and privacy workflows, and...


  • Canada Abnormal Security Corporation Full time

    Software Security Engineer IIAbnormal Security Corporation is seeking a skilled Software Security Engineer II to join our Platform Security team. As a key member of our team, you will be responsible for designing, developing, and releasing secure service-to-service communication frameworks and toolings, customer data security and privacy workflows, and...


  • Canada Abnormal Security Corporation Full time

    Abnormal Security Corporation Job DescriptionWe are seeking a highly skilled Software Security Engineer to join our Platform Security team. As a key member of our team, you will be responsible for designing, developing, and releasing secure service-to-service communication frameworks and toolings, customer data security and privacy workflows, and integrating...


  • Canada Abnormal Security Corporation Full time

    Secure Platform DeveloperAbnormal Security Corporation is seeking a skilled Software Security Engineer to join our Platform Security team. As a key member of our team, you will be responsible for designing, developing, and releasing secure service-to-service communication frameworks and toolings, customer data security and privacy workflows, and integrating...


  • Canada Abnormal Security Corporation Full time

    Secure Platform DeveloperAbnormal Security Corporation is seeking a skilled Software Security Engineer to join our Platform Security team. As a key member of our team, you will be responsible for designing, developing, and releasing secure service-to-service communication frameworks and toolings, customer data security and privacy workflows, and integrating...

Lead Application Security Engineer

2 months ago


Canada United Software Group Inc. - Canada Full time

Senior Application Security Engineer

Work location: Remote

Contract Duration: 12 Months

Note: We are seeking architect-level professionals with extensive experience in 'threat modeling' and application security evaluations.

We are in search of a seasoned Application Security Engineer who can leverage comprehensive business acumen and advanced technical expertise in security to aid in the formulation of strategy, roadmap, and execution for our Application Security initiative. In this capacity, you will identify security vulnerabilities proactively during solution design and mitigate risks during the development phase. You will contribute to the creation of design patterns and development standards to assist developers and architects in constructing secure solutions. Additionally, you will aid in the establishment of assessment frameworks to evaluate designs, subsequently overseeing their implementation. These processes will be particularly crucial in alignment with ongoing technology modernization efforts, with a significant focus on cloud integration.

Job Responsibilities:

  1. Assist in the development of proactive application security frameworks to guarantee secure architecture and development of business solutions. This encompasses frameworks for conducting consistent application security evaluations and threat models, as well as the formulation of secure design patterns and development standards.
  2. Integrate the aforementioned controls into a contemporary Software Development Life Cycle (SDLC).
  3. Execute application security evaluations, threat modeling, and architecture assessments.
  4. Effectively communicate design and development principles to relevant stakeholders.
  5. Enhance security designs proactively to minimize vulnerabilities identified post-development.
  6. Persuade stakeholders to rectify security shortcomings in both solution design and developed code.
  7. Offer solutions to security vulnerabilities while accommodating essential business and technical functionalities.
  8. Automate and standardize all relevant processes.

Required Qualifications:

Technical Skills:

  1. Profound understanding of the OWASP Top 10 and the ability to engage with developers and application architects. A background in development or software architecture is preferred.
  2. Experience with application security frameworks such as BSIMM and SAMM.
  3. Proficiency in conducting cloud architecture assessments, application risk evaluations, and threat modeling.
  4. Experience in embedding security controls into all variations of SDLC, including automation within a CI/CD pipeline.
  5. Evaluates business impact and exposure based on emerging security threats, vulnerabilities, and risks, recommending technologies and solutions for mitigation.
  6. Implements security considerations for in-house developed, COTS, and SaaS solutions.
  7. Translates technical concepts into layman's terms to illustrate business risk.
  8. Collaborates with developers and software architects to modify designs to securely meet business and technical requirements.

Cultural Skills:

  1. Comfortable functioning in an environment characterized by constant change and uncertainty.
  2. Proven experience in mentoring others by providing technical guidance to project teams.
  3. Cultivates relationships with development, software architecture, and product management stakeholders.
  4. Experience in highly regulated environments subject to HIPAA, HITrust, PCI, or other relevant standards.

Preferred Qualifications:

  1. Bachelor's degree in an IT-related field is strongly preferred; a post-graduate degree is advantageous but not mandatory.
  2. Knowledge and experience with configuring security controls and securely migrating enterprise applications to major cloud providers such as Azure (preferred), Amazon Web Services, or Google Cloud.
  3. Familiarity with CI/CD pipelines.
  4. Automation and standardization of software security controls, particularly within a CI/CD pipeline.
  5. Communicates the necessity for security controls to a business audience, including justification of expenditures and efforts.
  6. CISSP, CISM, or equivalent certifications.
  7. GIAC or Offensive Security certifications.
  8. Cloud Architecture and/or Cloud Security Certifications (AWS, Azure, GCP).
  9. Cloud Security Alliance (CCSP, CCSK) (ISC)2 certifications.