AppSec Security Specialist
$85k - $100k per yearCheckfront
About Us
At Checkfront, we’re builders, doers, and difference-makers, driven by a shared mission to reshape the tours, activities, and experiences industry. Alongside our sister brands, Rezdy and Regiondo, we power more than 20,000 businesses and support over $10B in bookings globally. Our technology helps operators thrive while delivering unforgettable moments to travelers around the world.
We work in an industry built on adventure, energy, and human connection, and that same spirit fuels how we show up every day. Spanning North America, Europe, and APAC, our teams are united by bold goals, a bias for action, and an unwavering commitment to delivering for our customers.
But our success starts with people. Our teams are the engine behind everything we create. We value self-starters who take ownership, embrace challenges, and raise the bar for themselves and those around them. We believe in creating space to grow, take risks, and make a real impact, and we celebrate those who lead with curiosity, grit, and drive.
If you’re passionate about security, compliance, and helping teams work smarter and safer, this is your kind of place. Let’s build, grow, and win together.
About the Role
We are seeking an AppSec Security Specialist to support our growing security function, with a primary focus on application security, vulnerability management, and secure development practices across Checkfront and our sister brands.
This is a hybrid security role that combines hands-on application security work with security operations support. You will help identify and remediate risks across our web applications, APIs, cloud environments, and development workflows, while also supporting key security tools across endpoint protection, DLP, SIEM, SOAR, vulnerability management, and security awareness.
This role is ideal for someone who enjoys working with engineering teams, performing web application security scans, coordinating penetration testing activities, investigating security alerts, tracking remediation, and helping the business improve its overall security posture.
What You Will Do
Application Security
- Support application security across Checkfront, Rezdy, Regiondo, and related platforms.
- Perform web application security scans and help validate, prioritize, and track findings through remediation.
- Support vulnerability management processes, including scanning, prioritization, reporting, and remediation tracking.
- Use and support application security tools such as SAST, DAST, SCA, and manage security findings.
- Coordinate with penetration testing vendors, including scoping, scheduling, evidence collection, findings review, and remediation follow-up.
- Work with engineering/dev teams to validate security findings, reduce risk, and improve secure development practices.
- Help identify and reduce risk across web applications, APIs, cloud services, and third-party components.
- Support secure software development practices, including clear guidance on remediation, secure coding, and risk reduction.
Security Operations
- Support day-to-day security operations across endpoint protection, DLP, SIEM, SOAR, and vulnerability management tools.
- Monitor and triage security alerts from tools such as CrowdStrike and related security platforms.
- Assist with incident response activities, including investigation, documentation, escalation, and follow-up actions.
- Help tune alerts, workflows, automations, and reporting to reduce noise and improve security visibility.
- Support security logging, monitoring, and detection improvement initiatives.
Security Awareness and Training
- Manage and support the KnowBe4 security awareness platform.
- Coordinate phishing simulations, training campaigns, reporting, and follow-up actions.
- Help improve employee security awareness through clear communication, practical guidance, and targeted training.
- Track training completion and support reporting related to security education.
Collaboration and Communication
- Partner with security, IT, engineering, legal, privacy, and business teams to support security outcomes.
- Translate security requirements into clear, actionable tasks.
- Communicate findings, risks, and remediation needs to both technical and non-technical stakeholders.
- Help build a security culture focused on ownership, transparency, and continuous improvement.
What We Are Looking For
- 4+ years of experience in application security, security operations, IT security, vulnerability management, or a related field.
- Experience with web application security testing, vulnerability scanning, remediation tracking, or secure software development practices.
- Experience with security tools such as EDR, DLP, SIEM, SOAR, vulnerability management, web application scanning, or security awareness platforms.
- Familiarity with CrowdStrike, KnowBe4, vulnerability scanners, ticketing systems, web application scanning tools, and GRC platforms is an asset.
- Ability to investigate security alerts, document findings, and escalate issues appropriately.
- Ability to work with engineering and IT teams to validate findings, track remediation, and reduce risk.
- Strong attention to detail and the ability to track findings, risks, and remediation items through to completion.
- Strong written and verbal communication skills with both technical and non-technical audiences.
- Comfort working in a fast-moving SaaS environment with multiple brands, systems, and stakeholders.
- A practical, curious, and ownership-driven approach to security.
Nice to Have
- Working knowledge of security and compliance frameworks such as SOC 2, ISO 27001, PCI DSS, GDPR, or similar standards.
- Experience supporting audit preparation, evidence collection, control testing, or ongoing compliance tracking.
- Experience supporting customer security questionnaires, vendor risk assessments, due diligence requests, or RFP security responses.
- Experience supporting SaaS, fintech, travel technology, or other regulated technology environments.
- Familiarity with cloud platforms, secure software development practices, and infrastructure security.
- Experience coordinating external penetration tests or working with third-party security vendors.
- Certifications such as CISSP, Security+, CSSLP, or similar are an asset.
- Experience with privacy, data protection, or AI governance requirements is an asset.
What You Can Expect
When you join our team, you’re stepping into a culture built on momentum, ownership, and connection.
We move fast, think big, and focus hard without losing sight of the people behind the work. Across all our brands, we’re united by a belief that impact comes from empowered teams, clear priorities, and a shared commitment to our customers and each other.
- High trust, high impact: We give our people the autonomy to take ownership, solve problems, and make meaningful contributions.
- Curiosity is encouraged: We value learning, asking questions, and pushing boundaries, not just getting things done, but doing them better.
- Collaboration over ego: We work as one team across geographies and brands. Success is shared, and support is a given.
- Space to grow: Whether you’re deepening your security skills, expanding into compliance, or learning new tools, you’ll be backed to grow.
- Progress over perfection: We embrace change, move quickly, and are constantly iterating to improve how we work and what we deliver.
- You’ll be joining a global team that’s passionate about building something that matters and having a good time while doing it.
The expected salary range for this role is $85,000–$100,000 CAD , with compensation determined based on experience, skills, and qualifications.
We’d love for you to join us on this exciting journey. Together, let’s shape the future of the leisure and tourism industry.
- ...impact. Contract Duration: Sept 1 to Nov 30, 2026 (3 months) Security Clearance: Not required Location: Winnipeg MB preferred,... ...may be possible Role Summary The Security and API Test Specialist is responsible for validating the security, reliability, performance...SuggestedContract workInternshipRemote work
- ...About the Role We’re looking for a Staff Product Security Engineer to lead the design and implementation of secure, scalable, and trustworthy products spanning AI,... ...Certifications such as CKS (Certified Kubernetes Security Specialist), CISSP, CSSLP, or AI/ML-focused security...SuggestedRemote jobInternshipLocal area
- ...backgrounds and experiences who are passionate about quality, teamwork, and making an impact. Contract Start Sept 14th for 6 months Security Clearance: Reliability or higher is required at time of application Job Summary We are seeking an experienced Automation...SuggestedContract workInternship
- ...impact. Contract Duration: Sept 1 - Nov 30, 2026 (3 months) Security Clearance: Not required Location: Winnipeg MB is preferred, remote is possible Role Summary The Performance Test Specialist will plan, design, execute, and report on non-functional testing activities...SuggestedContract workInternshipRemote work
- ...you need to do work that truly matters. We deliver results that exceed expectations and we win together! Your Role: Toronto based Security Engineer, responsible for identifying and matching technology opportunities with the customer’s business issues and objectives....SuggestedRemote jobLong term contractLocal area
- About Pine At Pine, we’re revolutionizing home financing by transforming a traditionally complex and outdated process into a streamlined, efficient experience for Canadians. Through innovative technology and a team of talented, compassionate professionals, we’re making the...
- ...and impact-driven environment, we’d love to hear from you. We’re looking for a detail-oriented and service-minded Sales Operations Specialist to join our Sales Operations team. This role is focused on providing day-to-day operational support to the Sales team, ensuring...Long term contractInternshipWorldwideFlexible hoursShift work
$40k - $45k per year
About Kindsight: Kindsight builds technology that helps fundraisers make a difference. For decades, Kindsight has supported the education, healthcare, and nonprofit sectors with fundraising tools and the largest charitable giving database on the market. And as the giving...$92k - $115k per year
...to drive agentic transformation and harness the power of AI with secure, scalable connectivity. Trusted by over 30,000 customers and... ...visit our Boomi Careers page to learn more. Analytics & AI Specialist (Talent Acquisition) How You'll Make An Impact Are you a...Work at officeFlexible hours$75k per year
...The Role, Enterprise Implementation Specialist - this role is based for applicants located in Canada SiteDocs , a GoCanvas company, is a leading provider of digital safety management software, trusted by thousands of teams to modernize and simplify workplace health and...Remote jobLong term contractFull time- ...of all backgrounds and experiences who are passionate about quality, teamwork, and making an impact. Contract: July - Dec 2026 Security Clearance: Current Reliability or higher is required at time of application. Role Overview The Risk Assessment Consultant will...Contract workInternship
$110k - $135k per year
...team, One Kroll, you’ll contribute to a supportive and collaborative work environment that empowers you to excel. Our Offensive Security professionals are on a mission to make the world a safer place, one company at a time. We help our clients discover, understand, and...Remote work- ...Description Salesforce Security Consultant Job Summary: As a Salesforce Security Consultant, you will play an essential role in enhancing the security posture of our Salesforce environment. You will work closely with the Director of Security to implement remediation...Remote workFlexible hours
- ...interested in working directly for a single sponsor while having the security and additional career opportunities that working for a global... ...worlds…. ClinChoice is searching for a Regulatory Affairs Specialist Consultant with Hybrid/Remote option in CANADA until...Contract workWork at officeRemote work2 days per week3 days per week
- ...commerce brands. We combine paid media, owned media, creative, and analytics to help our clients scale profitably. Our team is made up of specialists who are deeply invested in their craft — and in the success of the brands they serve. This isn't a "jack of all trades" environment...Remote jobPart time
$80k - $120k per year
About Kindsight: Kindsight builds technology that helps fundraisers make a difference. For decades, Kindsight has supported the education, healthcare, and nonprofit sectors with fundraising tools and the largest charitable giving database on the market. And as the giving...- ...Description Job Opportunity: Specialist, Data Analytics, Internal Audit Role Overview... ...Start: July 2026; Expected End: July 2027) Security Clearance: Enhanced (must be in place... ...technology stakeholders to clear bottlenecks and secure reliable access to necessary datasets....Contract workInternship2 days per week1 day per week
$45k per year
...The Role: As an Email Advertising Specialist, you will be responsible for creating and managing email marketing campaigns that drive engagement and conversions. You will work closely with the marketing team to develop strategies that align with our overall business goals...Full timeRemote work$48k per year
...The Role: As a Customer Success Specialist, you will be the primary point of contact for our customers, ensuring they derive maximum value from our products and services. Your responsibilities will include: Building and maintaining strong customer relationships Onboarding...Full timeRemote workFlexible hours$28 - $33 per hour
Toronto East, ON Full-Time | Long-Term Contract $28–33/hr Where Art Meets Engineering. Some people think visually. Some people think mechanically. Very few can do both. We're looking for a highly creative, technically curious designer who thrives at the...Long term contractFull timeDay shift$42k per year
...The Role: As a Customer Support Specialist, you will be the first point of contact for our customers, providing exceptional service and support. Your responsibilities will include: Responding to customer inquiries via phone, email, and chat Resolving customer issues...Full timeRemote workFlexible hours$60k - $65k per year
...to make an impact, realize your potential, and stay inspired every step of the way. As a Digital Campaign/Performance Marketing Specialist , you are responsible for the execution and optimization of digital media campaigns within Flipp’s Private Shopper Network and across...Local areaRemote workFlexible hours$42k per year
...The Role: The Customer Success Specialist will be responsible for ensuring customer satisfaction and fostering long-term relationships with clients. You will act as the primary point of contact for customers, addressing their needs and helping them achieve their goals using...Long term contractFull timeFlexible hours$65k per year
Are you a specialist Psychiatrist (MD, FRCPC or equivalent) in Canada, interested in leveraging your expertise through a flexible remote private... ..., and reach patients who need their expertise, all through a secure and seamless online experience. Key Responsibilities:...Hourly payFull timePart timeSelf employmentPrivate practiceRemote workFlexible hours- About Us The Company: Dotdigital is a thriving global community of passionate, dedicated professionals, committed to the collective success of the organization and its clients. Our core principles of innovation, teamwork, and client-focused solutions drive us to approach...
- ...Join a managed IT and cybersecurity team as a Senior Support Specialist – Infrastructure, a senior technical resource responsible for ensuring... ...time. Technical Support: Resolving end-user IT and security incidents, problems, requests, and changes including password resets...Permanent employmentContract workRemote work
$70k - $90k per year
...customers across North America. This is not a traditional quality assurance role. We're seeking a Food Safety Culture & Compliance Specialist who can combine technical food safety expertise with leadership, training, coaching, and culture development. You'll serve as the...Long term contractPermanent employmentFull timeShift work- ...Territory, and work week This role is based in-store. This is a part-time role working 20-25 hours per week. The Retail Selling Specialist is responsible for adhering to the schedule set out for them by their supervisor. This schedule requires a minimum of 3 weekends...Part timeFor contractorsLocal areaImmediate startWeekend work
- ...find out more about what Aviso has to offer at . The Opportunity: We’re looking to fill an opening with an experienced Security GRC Specialist to join our growing Security GRC team. Reporting to the Director of Security Governance, Risk & Compliance (GRC), the...Full timeInternship
- ...of a cross-functional team of software developers, data and AI specialists, analysts, and vendors; set priorities, manage capacity, remove... ...environment planning, integration and user acceptance testing, security reviews, cutover and rollback planning, release notes, training...Local areaFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to AppSec Security Specialist. Be the first to apply!
- conseiller santé sécurité Canada
- security analyst Canada
- physical security specialist Canada
- spécialiste en sécurité Canada
- spécialiste en sécurité informatique Canada
- security systems specialist Canada
- security operations specialist Canada
- physical security analyst Canada
- conseiller en sécurité financière Canada
- application security consultant Canada
