Senior Application Security Specialist
- Calgary, Alberta, Canada
- Télétravail
- Publié 24 sept. 2026
- 1 poste
Ouvre un site externe
- Type d’emploi
- Contrat
- Niveau d’expérience
- Intermédiaire · 2+ ans
- Formation minimale
- Diplôme professionnel
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
- Niveau d’expérience
- Associate
- Mode de candidature
- La candidature directe est offerte
Résumé du poste
The specialist will conduct advanced penetration testing, threat emulation, and crisis simulations to fortify financial infrastructure. They will also bridge the gap between technical security findings and business risk management for non-technical stakeholders.
Détails du poste
Security Developer Contract Length: 3 Months Location: Calgary, Alberta – open to remote Candidates Raise is currently hiring a Security Developer on behalf of our client. They’re expanding their team to meet growing needs, making this a unique opportunity to work with an industry leader. Our Client is a market leading financial institution Note: The primary pay rate is based on T4 classification; however, we will also consider applications from candidates interested in an INC classification, where applicable. Description Security Developer in this role will join our clients growing security engineering team. In this role, you will play a pivotal part in our Threat Intelligence & Security Configuration Project, driving advanced technical assessments, simulating sophisticated threats, and fortifying our financial infrastructure against emerging cyber risks. You will bridge the gap between deep technical vulnerability analysis and cross-functional business execution, ensuring our security posture remains resilient and dynamic. Responsibilities Advanced Threat Emulation & Testing: Execute hands-on penetration testing across web applications, APIs, networks, and cloud environments. Design and conduct complex red team operations to validate organizational detection and response capabilities against real-world adversary tactics. Crisis Simulation & Tabletop Leadership: Design and facilitate strategic enterprise-wide crisis simulations and tactical, team-specific tabletop exercises to enhance corporate communication and refine incident response playbooks. Vendor Governance & Lifecycle Management: Govern external third-party penetration testing vendors by defining technical scopes, establishing Rules of Engagement (ROEs), and validating final findings for organizational risk acceptance. Cross-Functional Risk Translation: Bridge the gap between technical security and business units by translating complex vulnerabilities into clear business risks, driving cross-functional remediation with non-technical stakeholders. Remediation Governance & Defensive Sync: Partner with blue teams and engineering to provide technical remediation guidance, validate security fixes, and translate assessment findings into prioritized engineering action items. Operational Optimization & Tooling: Author high-quality technical documentation (standard operating procedures and runbooks) and develop custom automation scripts to continuously scale assessment efficiency. Qualifications 3+ years of hands-on professional experience in information security, application security, penetration testing, or offensive security roles (preferably within financial services or regulated enterprise environments). Deep expertise in identifying and exploiting OWASP Top 10 vulnerabilities in complex web applications and modern API architectures. Proficiency in internal/external network assessments, lateral movement techniques, and infrastructure hardening. Demonstrated hands-on security experience with GCP (Google Cloud Platform) or other major cloud infrastructure providers (AWS, Azure). Exceptional capability in drafting clear, actionable technical documentation, executive summaries, and standard operating procedures (SOPs). Strong understanding of threat intelligence feeds, adversary tactics (e.g., MITRE ATT&CK framework), and security configuration baselines. Ability to script and automate routine testing or reporting tasks using languages such as Python, Bash, or Go. Outstanding communication skills with the ability to translate highly technical findings into business risks for non-technical stakeholders. Education and Certifications Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field (or equivalent practical industry experience). Industry-recognized security certifications such as OSCP (Offensive Security Certified Professional), GPEN, GWAPT, PNPT, or cloud security certifications (e.g., Google Professional Cloud Security Engineer). Additional Information A requirement for candidates to be considered for this role will be to complete a criminal and credit check (including Canadian Credit Risk Score)
Ce que vous ferez
The specialist will conduct advanced penetration testing, threat emulation, and crisis simulations to fortify financial infrastructure. They will also bridge the gap between technical security findings and business risk management for non-technical stakeholders.
Exigences
Candidates must have at least 3 years of professional experience in information or application security, including hands-on penetration testing. A bachelor's degree in a relevant field and industry-recognized certifications like OSCP or GPEN are required.
Compétences indiquées
- Go · Souhaitée
- Google Cloud · Souhaitée
- Python · Souhaitée
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Penetration testing
- Application security
- Threat intelligence
- Vulnerability analysis
- Red team operations
- Cloud security
- GCP
- Python
- Bash
- Go
- OWASP Top 10
- API security
- Incident response
- Network security
- Infrastructure hardening
- Risk assessment
Domaines d’emploi
- Security & Safety
- Technology
- Software
- Finance & Accounting
- Engineering
D’autres postes auxquels postuler directement
Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.
The Properties Group Management Ltd.
Real Estate Law Clerk
CommanditéEmployeur directCandidature simplifiée- Sur place
- Ottawa, ON
- Publié 24 sept. 2026
SOQUIJ
Conseiller(ère) en gestion financière
Employeur directCandidature simplifiée- Hybride
- Montréal, QC
- Publié 23 sept. 2026
SOQUIJ
Analyste financier(ère)
Employeur directCandidature simplifiée- Hybride
- Montréal, QC
- Publié 23 sept. 2026