Application Security Consultant, OWASP

3 days ago


Toronto, Canada Royal Bank of Canada Full time

Job Summary

Job Description

The Application Security team is undertaking multiple complex enterprise-wide initiatives to improve the security and quality of RBC applications. In this role, you will provide technical execution and expertise in the area of application security tools for the global RBC business and application development teams across all enterprise information technology groups. Primarily, you act as a primary point of contact for application teams, prioritizing and triaging Open Source Security scan results, and communicating the needs of application teams to strategic security leadership. As the vital link between security and developer functions, your expertise will contribute to the development of application security best practices, tools, and processes within RBC. This role will require you to understand various application security testing techniques such as SCA, SAST, and DAST.

WHAT WILL YOU DO?

  • Support end users of application security testing tools, managing tickets through a ticketing platform
  • Proactively solve problems to ensure application development teams are able to best use the latest application security testing tools
  • Educate key organizational stakeholders (e.g. developers, security consultants, executives) on application security matters across the organization
  • Assist in the integration of application security processes and tools into existing enterprise development processes and pipelines
  • Participate in and lead a range of application security assessment activities
  • Assist in the development, evaluation, and implementation of application security testing processes and tools
  • Work in a diverse environment leveraging other team members’ experience and knowledge
  • Research and keep up to date on application security emerging threats, techniques, tools, and trends

Must Have

  • Exposure to application security best practices such as secure coding, security testing techniques and Secure Software Development Lifecycle
  • 2+ years of experience in supporting SCA/SAST/DAST tools, especially in a role responsible for triaging findings and refining scanning rules.
  • Knowledge of Open Source Security
  • 2+ years of experience developing and testing apps in any of the following programming languages: Python, Java, Bash, Perl, JavaScript, C++, C#
  • Strong ability to manage client and stakeholder relations
  • Understanding of CI/CD, DevOps and DevSecOps approaches and experience working with DevOps tools
  • Knowledge of OWASP, SANS or other security-related frameworks

Nice-to-have:

  • Experience with Threat Modelling and Risk Assessment activities
  • Understanding and experience in agile methodology

RBC is committed to supporting flexible work arrangements when and where available. Details to be discussed with Hiring Manager.

What’s in it for you?

We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper. We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.

  • A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable
  • Leaders who support your development through coaching and managing opportunities
  • Ability to make a difference and lasting impact
  • Work in a dynamic, collaborative, progressive, and high-performing team
  • A world-class training program in financial services
  • Flexible work/life balance options
  • Opportunities to do challenging work

#LI-HYBRID
#LI-POST
#TechPJ

Job Skills

Agile Methodology, Application Development, Application Security, Application Security Assessment, Application Security Testing, Critical Thinking, Cybersecurity, Encryption Software, Group Problem Solving, Information Security, Information Security Management, Information Technology Security, Infrastructure Penetration Testing, IT Security Architecture, IT Systems Integration, Java, Process Development (PD), Python (Programming Language), Security Testing, Vulnerability Management

Additional Job Details

Address:

330 FRONT ST W:TORONTO

City:

TORONTO

Country:

Canada

Work hours/week:

37.5

Employment Type:

Full time

Platform:

TECHNOLOGY AND OPERATIONS

Job Type:

Regular

Pay Type:

Salaried

Posted Date:

2024-12-04

Application Deadline:

2025-01-13

Note: Applications will be accepted until 11:59 PM on the day prior to the application deadline date above

Inclusion and Equal Opportunity Employment

At RBC, we embrace diversity and inclusion for innovation and growth. We are committed to building inclusive teams and an equitable workplace for our employees to bring their true selves to work. We are taking actions to tackle issues of inequity and systemic bias to support our diverse talent, clients and communities.

We also strive to provide an accessible candidate experience for our prospective employees with different abilities. Please let us know if you need any accommodations during the recruitment process.

Join our Talent Community

Stay in-the-know about great career opportunities at RBC. Sign up and get customized info on our latest jobs, career tips and Recruitment events that matter to you.

Expand your limits and create a new future together at RBC. Find out how we use our passion and drive to enhance the well-being of our clients and communities at jobs.rbc.com.



  • Toronto, Canada RBC Full time

    Job SummaryThe RBC Application Security team is driving multiple complex enterprise-wide initiatives to enhance the security and quality of our applications. As a key member, you will provide technical expertise in application security tools for global RBC business and development teams. Your primary role will be to serve as a liaison between security and...


  • Toronto, Canada BMO Financial Group Full time

    100 King Street West Toronto Ontario,M5X 1A1 The role is Hybrid (1-2 days in the office) **About the role**: **What will you do**: - ** Information Security Risk Management -** Works with leadership to mature security testing team capabilities including reporting and remediation guidance in alignment with local and global regulatory requirements....


  • Toronto, Ontario, Canada David Joseph & Company Full time

    Job Title: Cybersecurity Expert for Secure Application DevelopmentAbout Us:David Joseph & Company is seeking a highly skilled Cybersecurity Expert to join our team. As a key member of our organization, you will play a critical role in ensuring the security and integrity of our applications.Estimated Salary: $120,000 - $180,000 per year, depending on...


  • Toronto, Canada Canada Life Assurance Company Full time

    **Job Description**: As a Lead, Application Security within the Canada Life Information Security Department, you will be responsible for the security posture of the products your team supports. You will grow your team through hiring, develop the team through coaching, act as a technical escalation point, and ultimately guide the team through critical...


  • Toronto, Canada Broadmind INC Full time

    **Role: THREAD MODELING CONSULTANT** **Location: Toronto, ON** **Hybrid Role** **Duration: 12 Months Contract** **JOB DESCRIPTION**: - Provide security advisory services to technology and business teams. - Perform security assessments for technical solution designs. - Identify threat scenarios and evaluate risk rating based on a thorough review of the...


  • Toronto, Canada Canada Life Assurance Company Full time

    **Job Description**: **What you will do**: - Assist with the configuration and optimization of SAST, SCA, and DAST scanning tools. - Participate in vulnerability management operations, such as: retesting and reprioritizing vulnerabilities, reviewing code changes, approving proposed remediations, etc. - Contribute technical and procedural documentation...


  • Old Toronto, Canada Glassdoor Full time

    Glassdoor is a leading platform for workplace conversations, and we're committed to making worklife better for everyone. As a key member of our team, you'll play a vital role in shaping the future of application security.Company OverviewWe're on a mission to give professionals the tools they need to succeed. Our platform empowers users to connect...


  • Toronto, Ontario, Canada theScore Full time

    About the Role & TeamWe are seeking a highly skilled Senior Application Security Engineer to join our Application Security team at theScore. As part of our team, you will work collaboratively across the entire engineering organization to solve complex security problems and develop standards for security tooling.About the WorkCollaborate with release and...


  • Old Toronto, Canada LZ Security & Service GmbH Full time

    Job Responsibilities:Plan, coordinate, and direct all information security tasks within the area of responsibility to meet the global and local security goals.Support all security incidents of the location with alignment to the incident management process.Work with the Procurement and Legal departments to review and screen suppliers.Lead IT/security...


  • Old Toronto, Canada LZ Security & Service GmbH Full time

    Job Responsibilities:Plan, coordinate, and direct all information security tasks within the area of responsibility to meet the global and local security goals.Support all security incidents of the location with alignment to the incident management process.Work with the Procurement and Legal departments to review and screen suppliers.Lead IT/security...


  • Toronto, Canada RBC Full time

    Job Summary Job Description The Application Security team is undertaking multiple complex enterprise-wide initiatives to improve the security and quality of RBC applications. In this role, you will provide technical execution and expertise in the area of application security tools for the global RBC business and application development teams across all...


  • Toronto, Canada David Joseph & Company Full time

    JOB SUMMARY:We are seeking a skilled Application Security Specialist with experience in secure coding practices, threat modelling, Static Application Security Testing (SAST), Software Composition Analysis (SCA), Dynamic Application Security Testing (DAST), and container security. The ideal candidate will play a critical role in safeguarding our applications...


  • Toronto, Canada RBC Full time

    Job SummaryJob Description The Application Security team is undertaking multiple complex enterprise-wide initiatives to improve the security and quality of RBC applications. In this role, you will provide technical execution and expertise in the area of application security tools for the global RBC business and application development teams across all...


  • Toronto, Canada First National Full time

    We are hiring an Application Security Analyst, Information Security! The Role: We're seeking an Application Security Analyst well-versed in risk analysis, vulnerability assessment methodologies, and information security concepts. Your role involves supporting security risk assessments for both internally developed and third-party/open-source...


  • Toronto, Canada LifeLabs Full time

    For over 50 years, LifeLabs has been Canada’s leading provider of laboratory diagnostic information and digital health connectivity systems, enabling patients and healthcare practitioners to diagnose, treat, monitor and prevent disease. We are passionate about empowering healthier Canadians through accessible, accurate, and innovative diagnostic...


  • Old Toronto, Canada Score Media and Gaming Inc. Full time

    About the Role & Team As part of the theScore team, you will be working with a team of smart, friendly, and dedicated Engineers, Product Managers, and Designers determined to deliver some of the best apps the market has to offer. We want you to be challenged and to get the full experience of what it is like to work at theScore! We are looking for a Senior...


  • Toronto, Ontario, Canada BMO Full time

    About the RoleThe Chief Security Testing Officer will be responsible for leading the security testing activities for BMO based applications. This role will work closely with the Lead of DevSecOps to ensure the execution and coordination of Static and Dynamic Application Security Testing (SAST/DAST). The ideal candidate will have a strong understanding of...


  • Toronto, Canada Aforce solutions Full time

    **Role: THREAD MODELING CONSULTANT** **Location: Toronto, ON** **Hybrid Role -à 3 Days Onsite** **Duration: 12 Months Contract** **JOB DESCRIPTION**: - Provide security advisory services to technology and business teams. - Perform security assessments for technical solution designs. - Identify threat scenarios and evaluate risk rating based on a...


  • Toronto, Canada Insight Global Full time

    About the RoleWe are seeking a highly skilled Security Risk Consultant to join our team at Insight Global in Toronto.Job SummaryThis consultant will be responsible for assessing security risks for web applications across the enterprise, conducting thorough risk assessments, and presenting findings to senior leadership.Key Responsibilities:Conduct full cycle...


  • Old Toronto, Canada LZ Security & Service GmbH Full time

    Job OverviewLZ Security & Service GmbH seeks an experienced IT Security Professional to lead our information security efforts in Toronto, Calgary, or Vancouver.Key Responsibilities:Develop and implement global security strategies aligned with organizational goals.Collaborate with procurement and legal teams to ensure compliance with local regulations.Lead...