Retour à la recherche
A
AmyantekSource d’offres vérifiée

1658 - Application Security Analyst

Offre en anglais

Position title: 1658 - Application Security Analyst Working Status: Hybrid — primarily remote; onsite 1–2 times per quarter (optional additional visits) Location: 1 York Street, Toronto, Ontario, M5J 0B6 Duration: August 10, 2026 – April 9, 2027 Seniority Level: Hands-on analyst; not a senior or leadership role. Requires 2–3 years of application security experience and comfort working directly with tools and technical teams. Job description The successful candidate will play a critical role in Sun Life to advance DevSecOps. In this position the incumbent will lead the evaluation, creations a…

  • Télétravail
  • ["Toronto, Ontario, Canada"]
  • Publié 16 juill. 2026
  • Postuler avant le 15 août 2026
  • 1 poste

Résumé du poste

Position title: 1658 - Application Security Analyst Working Status: Hybrid — primarily remote; onsite 1–2 times per quarter (optional additional visits) Location: 1 York Street, Toronto, Ontario, M5J 0B6 Duration: August 10, 2026 – April 9, 2027 Seniority Level: Hands-on analyst; not a senior or leadership role. Requires 2–3 years of application security experience and comfort working directly with tools and technical teams. Job description The successful candidate will play a critical role in Sun Life to advance DevSecOps. In this position the incumbent will lead the evaluation, creations and implementation of application security tools, processes within the CI/CD Pipeline's globally. The successful candidate must not only understand the cyber security issues associated with application design and implementation but also must be willing to embrace a development attitude as they will be working closely alongside developers and other DevOps professionals to achieve a secure role out of DevSecOps across Sun Life's major operating geographies globally. Critical Skills / Must-Haves: 1. 2+ yrs in IT Design/Application Design & Implementation 2. 3+ yrs Cyber Application Security experience 3. 1+ yrs automating systems, designing automation. 4. Software development background (C++/Java/.NET) (2+ yrs) 5. Experience in managing Application Security platforms SAST/DAST/SCA/MOBILE (1+yrs) 6. Solid understanding of DevSecOps and Agile Security concepts. 7. Hands on experience with SAST, SCA, DAST, MAST tools and techniques 8. Expert knowledge of OWASP top 10 (Web, Mobile, APIs) and SANS top 25 Soft Skills: 1. Demonstrated experience leading vulnerability management and analysis. 2. Self-motivated, proactive, driven and strong problem-solving skills. 3. Ability to communicate effectively to technical and nontechnical audiences and work with business partners as well as infrastructure teams 4. Excellent communication skills 5. Working in agile environment. 6. Ability to create professional looking Visio diagrams Nice-to-Haves: 1. Security certifications such as GWAPT, GWEB, CEH, CASE, CSSLP or similar preferred but not required. 2. Experience reading and understanding Pen test findings. 3. Programming knowledge preferred 4. Experience with secure development and testing of APIs, microservices, containers and Cloud (AWS) is a big plus. 5. Knowledge of software applications both development and the vendor procurement life cycle. 6. Designing and implementing DevSecOps CI/CD Pipelines (1+yrs) 7. Experience working in process engineering 8. Strong working knowledge of Java, J2EE, web services and application integration technologies 9. Working and designing cloud solutions (1+ yrs) Education: University or College diploma in Computer Science, engineering or equivalent. Certification: CISSP/CEH or cyber security certification Top Performer Profile A standout candidate is hands-on, detail-oriented, and consistently identifies opportunities to improve tools, policies, and processes. They reduce false positives, enhance automation, and take ownership of their work. They excel at explaining vulnerabilities to delivery teams, improving systems, and generating meaningful metrics for leadership. Coding experience is a strong asset. Responsibilities · Assist with running and management of application security tools such as SAST, SCA, MAST, DAST, etc. · Review vulnerability results and provide remediation direction to delivery teams · Conduct reviews on tools and provide the relevant tuning and upgrades with respect to penetration test findings. · Create metrics (KPI and KRIs) for vulnerability management program and present to senior management. · Participate in crafting the Application Security and vulnerability management directives as required. · Educate development teams on OWASP top 10 vulnerabilities for Web, Mobile and APIs. · Automate redundant security tasks and bring in efficiencies within existing security processes. · Provide ongoing support of mobile and web application systems in production including responding to operational requests, problem analysis, resolution, escalation, and reporting as necessary · Create and maintain supporting documentation

Ce que vous ferez

The successful candidate will assist in managing application security tools and provide remediation direction to delivery teams. They will also automate security tasks and support mobile and web application systems in production.

Exigences

Candidates must have 2-3 years of application security experience and a software development background. They should also have hands-on experience with various application security tools and a solid understanding of DevSecOps concepts.

Autres compétences pertinentes

Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.

  • Application Security
  • DevSecOps
  • Cyber Security
  • Automation
  • Software Development
  • SAST
  • DAST
  • SCA
  • OWASP
  • Agile
  • Vulnerability Management
  • Problem Solving
  • Communication
  • Cloud
  • Java
  • C++

Renseignements supplémentaires

Formation minimale
Baccalauréat
Expérience minimale
2+ ans
Postuler avant le
15 août 2026