Application Security Engineer
3 days ago
About TCS TCS is an IT services, consulting, and business solutions organization that has been partnering with many of the world’s largest businesses in their transformation journeys for over 55 years. Its consulting‑led, cognitive‑powered portfolio of business, technology, and engineering services and solutions is delivered through its unique Location Independent Agile delivery model, recognized as a benchmark of excellence in software development. A part of the Tata group, India's largest multinational business group, TCS operates in 55 countries and employs over 607,000 highly skilled individuals, including more than 10,000 in Canada. Equal Opportunity & Inclusion TCS is an equal opportunity employer, and embraces diversity in race, nationality, ethnicity, gender, age, physical ability, neurodiversity, and sexual orientation, to create a workforce that reflects the societies we operate in. Our continued commitment to Culture and Diversity is reflected in our people stories across our workforce and implemented through equitable workplace policies and processes. Additional Information Note: TCS does not use artificial intelligence tools for candidate screening or evaluation. Tata Consultancy Services Canada Inc. is committed to meeting the accessibility needs of all individuals in accordance with the Accessibility for Ontarians with Disabilities Act (AODA) and the Ontario Human Rights Code (OHRC). Should you require accommodations during the recruitment and selection process, please inform Human Resources. Job Summary The Application Security Engineer will perform end‑to‑end penetration testing on web applications and APIs to identify security vulnerabilities, assess risk, and drive remediation. The role includes planning and executing manual and automated tests, producing clear and actionable reports, collaborating with engineering teams to fix issues, and ensuring all findings are logged and tracked through closure in the vulnerability management system. Key Responsibilities Penetration Testing & Assessment Plan, scope, and execute web application and API penetration tests across SDLC phases (pre‑release and production). Perform recon, threat modeling, and attack surface mapping to prioritize test coverage. Identify and validate vulnerabilities including authentication/authorization flaws, injection, XSS, SSRF, deserialization, IDOR, insecure direct object references, logic bugs, misconfigurations, and sensitive data exposure. Test API endpoints (REST/Graph QL) for input validation, rate limiting, broken object‑level authorization (BOLA), and schema/serialization issues. Use both automated scanning and manual exploitation to confirm impact, reproducibility, and exploit chains. Reporting & Remediation Support Prepare detailed technical reports with PoCs, severity ratings (CVSS/SLA alignment), affected components, and business impact. Provide prioritized remediation guidance with code‑level recommendations and secure patterns. Log all findings in the vulnerability tracking system (e.g., JIRA, Azure DevOps, ServiceNow, or dedicated VM platforms), ensuring accurate metadata (CWE/CVE, CVSS, asset, environment, owner). Track remediation progress, validate fixes, and close findings after re‑test. Tooling & Automation Configure, run, and tune DAST or similar tools; integrate results into CI/CD. Build and maintain custom scripts for repeatable tests and payload generation. Maintain test environments, proxies, and lab infrastructure (containers, mock services). Required Qualifications & Skills Good years in application security or red teaming with hands‑on web/API pen testing. Working knowledge of CVSS scoring, CWE mapping, and SLA‑based remediation workflows in platforms like Tenable, Qualys, or custom trackers. Clear technical writing, stakeholder communication, and ability to translate risk into business impact. Preferred Qualifications Experience embedding security testing in CI/CD (GitHub Actions, GitLab CI, Azure DevOps). Familiarity with IaC scanning (Terraform, Bicep), container security, and runtime protections (RASP/WAF). Experience with mobile API testing and SSO/federation architectures. Salary Range CA$100,000 – CA$150,000 per year. Senior Level Mid‑Senior level Employment Type Full‑time Job Function Information Technology Industries IT Services and IT Consulting Application Process Applicants that meet the qualifications for this position will be contacted within a 2‑week period. We invite you to continue to apply for other opportunities that match your profile. #J-18808-Ljbffr
-
Application Security Consultant
4 weeks ago
Toronto, Canada Forward Security Full timeOverview MUST RESIDE IN TORONTO, OTTAWA, OR VANCOUVER As an Application Security Consultant, you will be responsible for performing security assessments on applications and cloud environments. This includes conducting vulnerability assessments, penetration testing, code reviews, and providing recommendations for remediation. The role involves collaborating...
-
Application Security Engineer
6 days ago
Toronto, Ontario, Canada Fragomen Full timeJob DescriptionAbout the Role:Fragomen, an Am Law 100 Firm and the leading global immigration services provider, is seeking an Application Security Engineer & Architect. This Engineer will join our talent Cyber Security team, which plays a pivotal role in Fragomen's Immigration Technology Innovation Lab. Our industry-leading, immigration-specific...
-
Application Security Engineer
4 days ago
Toronto, Ontario, Canada Homebase Full timeHi, Future HomieAt Homebase, you'll join a team that's bold, fast-moving, and obsessed with helping small businesses thrive. We build with empathy, act with urgency, and take big swings that drive real-world impact. Here, every Homie shows up to raise the bar, support one another, and celebrate wins as a team.We're not just building an app—we're...
-
Application Security Engineer
6 days ago
Toronto, Ontario, Canada Homebase Full timeHi, Future HomieAt Homebase, you'll join a team that's bold, fast-moving, and obsessed with helping small businesses thrive. We build with empathy, act with urgency, and take big swings that drive real-world impact. Here, every Homie shows up to raise the bar, support one another, and celebrate wins as a team.We're not just building an app—we're building...
-
Application Security Engineer
4 hours ago
Toronto, Ontario, Canada Homebase Full timeHi, Future Homie At Homebase, you'll join a team that's bold, fast-moving, and obsessed with helping small businesses thrive. We build with empathy, act with urgency, and take big swings that drive real-world impact. Here, every Homie shows up to raise the bar, support one another, and celebrate wins as a team. We're not just building an app—we're...
-
Application Security Engineer
3 days ago
Toronto, Canada Tata Consultancy Services Full timeAbout TCS TCS is an IT services, consulting, and business solutions organization that has been partnering with many of the world’s largest businesses in their transformation journeys for over 55 years. Its consulting‑led, cognitive‑powered portfolio of business, technology, and engineering services and solutions is delivered through its unique Location...
-
Application Security Engineer
1 week ago
Toronto, Canada Tata Consultancy Services Full timeTalent Acquisition Specialist @ TATA CONSULTANCY SERVICES | Bachelor of Engineering Inclusion without Exception: Tata Consultancy Services (TCS) is an equal opportunity employer, and embraces diversity in race, nationality, ethnicity, gender, age, physical ability, neurodiversity, and sexual orientation, to create a workforce that reflects the societies we...
-
Application Security Engineer
1 week ago
Toronto, Canada Tata Consultancy Services Full timeTalent Acquisition Specialist @ TATA CONSULTANCY SERVICES | Bachelor of EngineeringInclusion without Exception:Tata Consultancy Services (TCS) is an equal opportunity employer, and embraces diversity in race, nationality, ethnicity, gender, age, physical ability, neurodiversity, and sexual orientation, to create a workforce that reflects the societies we...
-
Application Security Engineer
1 week ago
Toronto, Canada Tata Consultancy Services Full timeTalent Acquisition Specialist @ TATA CONSULTANCY SERVICES | Bachelor of EngineeringInclusion without Exception:Tata Consultancy Services (TCS) is an equal opportunity employer, and embraces diversity in race, nationality, ethnicity, gender, age, physical ability, neurodiversity, and sexual orientation, to create a workforce that reflects the societies we...
-
Application Security Engineer
1 week ago
Toronto, Canada Homebase Full timeHi, Future Homie! At Homebase, you’ll join a team that’s bold, fast-moving, and obsessed with helping small businesses thrive. We build with empathy, act with urgency, and take big swings that drive real-world impact. Here, every Homie shows up to raise the bar, support one another, and celebrate wins as a team. We’re not just building an app—we’re...