drjobs Senior Technology Specialist Information Security

Senior Technology Specialist Information Security

Employer Active

1 Vacancy
drjobs

Job Alert

You will be updated with latest job alerts via email
Valid email field required
Send jobs
Send me jobs like this
drjobs

Job Alert

You will be updated with latest job alerts via email

Valid email field required
Send jobs
Job Location drjobs

Waterloo - Canada

Monthly Salary drjobs

Not Disclosed

drjobs

Salary Not Disclosed

Vacancy

1 Vacancy

Job Description

At Equitable we realize that your work life is not just about performing a job; its about being part of a workplace that helps you grow and reach your full potential. Within our friendly and collaborative work environment we recognize that the key to our growth and success is a dedicated motivated and clientresponsive staff. Join Equitable today.

Position Title: Senior Technology Specialist Information Security
Reports To: Senior Technology Manager Information Security
Department:
Information Technology Technology Risk and Governance
Term: Permanent FullTime


Work Arrangements: This is a hybrid role. You will work in our office in Waterloo ON a minimum of two 2 assigned consecutive days every other week plus a fifth 5th) assigned day per month. You are welcome to work from the office more than the minimum requirement and there may be some roles that are required to work in our office more than the minimum requirement.


The Opportunity:Now is an exciting time to join one of the Waterloo Areas Top Employer for 2025 and Southwestern Ontarios Top Employers for 2024!

The Senior Technology Specialist will play a vital role in strengthening our Application Security program and will be on the forefront of change leading the Sec DevOps culture at Equitable. You will contribute by safeguarding our digital assets and ensuring the security of our applications directly impacting our companys success and customer trust. You will provide technical leadership required to manage and reduce application security risks by taking ownership of the Sec DevOps portfolio and establishing current and longterm direction by developing organizationwide security controls that integrate into our DevOps pipelines.


What you will be doing:

  • Act as a subject matter expert on application security domains involving web and mobile platforms.
  • Design and implement robust application security controls to protect against threats and vulnerabilities.
  • Enforce secure coding standards across development teams based on industryaccepted best practices.
  • Design and implement secure CI/CD solutions for development and production environments.
  • Integrate and implement automated application security testing (DAST SAST RASP & IAST) for APIs web and mobile applications.
  • Conduct periodic and ondemand manual penetration testing assessments of applications.
  • Provide guidance on security requirements of application design based on industry best practices or internal policy.
  • Perform system and applicationlevel risk and vulnerability assessments.
  • Collaborate with developers to understand and remediate security vulnerabilities to improve overall security posture.
  • Nurture a training program/curriculum that provides Application Security training to software developers.
  • Assist with code reviews to proactively identify potential vulnerabilities and followup with tooling to prevent future vulnerabilities.
  • Provide timely and detailed reports with evidence of findings risk analysis guidance and remediation instructions.
  • Manage Auth0 for secure authentication and collaborate with development teams to integrate Auth0 in various applications.
  • Facilitate security training sessions for developers to enhance their understanding of secure coding practices.
  • Ensure security is considered at each stage of the software development process.
  • Conduct regular assessments and audits to ensure compliance with SCLC standards.
  • Provide training and guidance to development teams on using SNYK and StackHawk tools to identify and remediate vulnerabilities in applications. Integrate these tools into CI/CD pipelines to ensure continuous security testing.


What you will bring:

  • A Sec DevOps forward mindset with a high emphasis on solving problems via code and API forward approaches.
  • A bachelors degree in computer science Information Systems Engineering cybersecurity or related technical field; or equivalent experience.
  • Certifications such as CISSP OSCP OSCE GWAPT GPEN CEH CompTIA Security .
  • 5 years of experience in web and mobile application security and pen testing.
  • Extensive knowledge of Application Security Risks how they can be detected exploited and mitigated.
  • Strong experience in DevOps development practices CI/CD pipelines and knowledge of orchestration platforms.
  • Thorough understanding of modern software development practices.
  • Strong expertise with cloud environments (AWS / Google Cloud / Azure).
  • Programming/scripting experience (PowerShell ASP .NET Python Perl).
  • Thorough understanding of OWASP Top 10 vulnerabilities and corresponding best practices for mitigation.
  • Experience in deploying application security technologies such as SAST DAST IAST SCA etc.
  • Deep knowledge in the field of IT security (firewalls EDR IDS/IPS SOAR vulnerability scanning forensic and Threat Hunting).
  • Knowledge in security classification frameworks like MITRE or the cyberattack chain.
  • Strong understanding of application design and architecture.
  • Proficient in manual and automated penetration testing methods/tools.
  • Experience with products dealing with penetration testing services which include Backtrack Kali Metasploit Framework.
  • Experience using WAF technologies is highly desirable.
  • Participation in Bug Bounties & Capture the Flag (CTF) would be beneficial.
  • Handson experience with security tools like Nyland StackHawk.
  • Experience with Auth0.



Whats in it for you:

  • A healthy worklife balance with employee wellness top of mind
  • Annual bonus program annual vacation allowance and companypaid benefits program
  • An additional paid volunteer day each year so you can spend time giving back to the community
  • Immediate enrollment in the companys pension program with employer matching
  • Employee resource groups that support an inclusive work environment
  • Tuition support and specialized program assistance
  • An onsite fullservice cafeteria with a variety of daily options
  • Discounts on company products and services and access to exclusive employee perks
  • Regular EQ Together events focused on company togetherness and collaboration


As part of the recruitment/offer process you will be required to:

  • Provide two professional references (minimum one supervisor and above)
  • Undergo a criminal background check

This role is open due to an existing vacancy.

To learn more about Equitable we encourage you to explore our organization.

At Equitable we are committed to providing equal access to employment opportunities across our organization. Please contact our HR team at if you would like to receive our job postings in an alternative format or require an accommodation with the application process.

#LIHybrid

Other details

  • Job FamilyIndividual Contributor Non Transactional
  • Pay TypeSalary

Required Experience:

Senior IC

Employment Type

Full-Time

Company Industry

About Company

Report This Job
Disclaimer: Drjobpro.com is only a platform that connects job seekers and employers. Applicants are advised to conduct their own independent research into the credentials of the prospective employer.We always make certain that our clients do not endorse any request for money payments, thus we advise against sharing any personal or bank-related information with any third party. If you suspect fraud or malpractice, please contact us via contact us page.