Application Security Engineer
5 minutes ago
About TCS TCS is an IT services, consulting, and business solutions organization that has been partnering with many of the world’s largest businesses in their transformation journeys for over 55 years. Its consulting‑led, cognitive‑powered portfolio of business, technology, and engineering services and solutions is delivered through its unique Location Independent Agile delivery model, recognized as a benchmark of excellence in software development. A part of the Tata group, India's largest multinational business group, TCS operates in 55 countries and employs over 607,000 highly skilled individuals, including more than 10,000 in Canada. Equal Opportunity & Inclusion TCS is an equal opportunity employer, and embraces diversity in race, nationality, ethnicity, gender, age, physical ability, neurodiversity, and sexual orientation, to create a workforce that reflects the societies we operate in. Our continued commitment to Culture and Diversity is reflected in our people stories across our workforce and implemented through equitable workplace policies and processes. Additional Information Note: TCS does not use artificial intelligence tools for candidate screening or evaluation. Tata Consultancy Services Canada Inc. is committed to meeting the accessibility needs of all individuals in accordance with the Accessibility for Ontarians with Disabilities Act (AODA) and the Ontario Human Rights Code (OHRC). Should you require accommodations during the recruitment and selection process, please inform Human Resources. Job Summary The Application Security Engineer will perform end‑to‑end penetration testing on web applications and APIs to identify security vulnerabilities, assess risk, and drive remediation. The role includes planning and executing manual and automated tests, producing clear and actionable reports, collaborating with engineering teams to fix issues, and ensuring all findings are logged and tracked through closure in the vulnerability management system. Key Responsibilities Penetration Testing & Assessment Plan, scope, and execute web application and API penetration tests across SDLC phases (pre‑release and production). Perform recon, threat modeling, and attack surface mapping to prioritize test coverage. Identify and validate vulnerabilities including authentication/authorization flaws, injection, XSS, SSRF, deserialization, IDOR, insecure direct object references, logic bugs, misconfigurations, and sensitive data exposure. Test API endpoints (REST/Graph QL) for input validation, rate limiting, broken object‑level authorization (BOLA), and schema/serialization issues. Use both automated scanning and manual exploitation to confirm impact, reproducibility, and exploit chains. Reporting & Remediation Support Prepare detailed technical reports with PoCs, severity ratings (CVSS/SLA alignment), affected components, and business impact. Provide prioritized remediation guidance with code‑level recommendations and secure patterns. Log all findings in the vulnerability tracking system (e.g., JIRA, Azure DevOps, ServiceNow, or dedicated VM platforms), ensuring accurate metadata (CWE/CVE, CVSS, asset, environment, owner). Track remediation progress, validate fixes, and close findings after re‑test. Tooling & Automation Configure, run, and tune DAST or similar tools; integrate results into CI/CD. Build and maintain custom scripts for repeatable tests and payload generation. Maintain test environments, proxies, and lab infrastructure (containers, mock services). Required Qualifications & Skills Good years in application security or red teaming with hands‑on web/API pen testing. Working knowledge of CVSS scoring, CWE mapping, and SLA‑based remediation workflows in platforms like Tenable, Qualys, or custom trackers. Clear technical writing, stakeholder communication, and ability to translate risk into business impact. Preferred Qualifications Experience embedding security testing in CI/CD (GitHub Actions, GitLab CI, Azure DevOps). Familiarity with IaC scanning (Terraform, Bicep), container security, and runtime protections (RASP/WAF). Experience with mobile API testing and SSO/federation architectures. Salary Range CA$100,000 – CA$150,000 per year. Senior Level Mid‑Senior level Employment Type Full‑time Job Function Information Technology Industries IT Services and IT Consulting Application Process Applicants that meet the qualifications for this position will be contacted within a 2‑week period. We invite you to continue to apply for other opportunities that match your profile. #J-18808-Ljbffr
-
Application Security Consultant
2 weeks ago
Toronto, Canada Forward Security Full timeOverview MUST RESIDE IN TORONTO, OTTAWA, OR VANCOUVER As an Application Security Consultant, you will be responsible for performing security assessments on applications and cloud environments. This includes conducting vulnerability assessments, penetration testing, code reviews, and providing recommendations for remediation. The role involves collaborating...
-
Application Security Consultant
2 weeks ago
Toronto, Canada Forward Security Full timeOverview MUST RESIDE IN TORONTO, OTTAWA, OR VANCOUVER As an Application Security Consultant, you will be responsible for performing security assessments on applications and cloud environments. This includes conducting vulnerability assessments, penetration testing, code reviews, and providing recommendations for remediation. The role involves collaborating...
-
Application Security Engineer
6 minutes ago
Toronto, Canada Homebase Full timeHi, Future Homie! At Homebase, you’ll join a team that’s bold, fast-moving, and obsessed with helping small businesses thrive. We build with empathy, act with urgency, and take big swings that drive real-world impact. Here, every Homie shows up to raise the bar, support one another, and celebrate wins as a team. We’re not just building an app—we’re...
-
Application Security Software Engineer
6 minutes ago
Toronto, Canada PointClickCare Full timeThis range is provided by PointClickCare. Your actual pay will be based on your skills and experience — talk with your recruiter to learn more. Base pay range CA$92,900.00/yr - CA$100,000.00/yr PointClickCare is a leading North American healthcare technology platform enabling meaningful care collaboration and real‐time patient insights. For over 20...
-
Toronto, Canada Clio Full timeA leading legal technology firm in Toronto is seeking an Application Security Engineer to join its Security team. The role involves identifying and exploiting vulnerabilities, conducting penetration tests, and collaborating with development teams to foster security. Ideal candidates will have experience in application security and offensive security...
-
Toronto, Canada Clio Full timeA leading legal technology firm in Toronto is seeking an Application Security Engineer to join its Security team. The role involves identifying and exploiting vulnerabilities, conducting penetration tests, and collaborating with development teams to foster security. Ideal candidates will have experience in application security and offensive security...
-
Toronto, Canada Clio Full timeA leading legal technology firm in Toronto is seeking an Application Security Engineer to join its Security team. The role involves identifying and exploiting vulnerabilities, conducting penetration tests, and collaborating with development teams to foster security. Ideal candidates will have experience in application security and offensive security...
-
Lead Application Security Engineer
6 minutes ago
Toronto, Canada Nasdaq, Inc. Full timeLead Information Security Engineer page is loaded## Lead Information Security Engineerlocations: St. John's - 18 Hebron Way: Canada - Montreal - Québec: Canada - Toronto - Ontariotime type: Full timeposted on: Posted Todayjob requisition id: R Designs, develops, modifies, adapts and implements short- and long-term solutions to support information technology...
-
Senior Security Engineer, Application
3 weeks ago
Toronto, Canada Sentry Full timeBad software is everywhere, and we’re tired of it. Sentry is on a mission to help developers write better software faster so we can get back to enjoying technology. With more than $217 million in funding and 100,000+ organizations that believe we’re on to something, we're building performance and error monitoring tools that help companies like Disney,...
-
Toronto, Ontario, Canada Emburse Full timeAbout The CompanyAt Emburse our mission is to help make our users' lives – and their businesses – better. We are dramatically transforming how organizations manage corporate expenses and invoices. We humanize work by automating manual tasks and saving users' time, so they can focus on what matters most – their family, community, or more rewarding work....