Application Security Engineer (SME) - DevSecOps, Pen Testing
Astra North Infoteck Inc.
Role Description
We are seeking an experienced Senior Application Security SME/ DevSecOps Security Consultant to lead and mature application security practices across enterprise platforms and development teams. The ideal candidate will have deep expertise in modern application architectures, secure coding practices, security testing methodologies, and the ability to partner effectively with development, engineering, DevOps, and risk teams to embed security throughout the software delivery lifecycle.
Primary Skills
- Application Security
- Secure SDLC (SSDLC)
- DevSecOps
- Threat Modeling
- Cloud Security (Azure, AWS, GCP)
- Security Architecture
- Vulnerability Management
- SAST / DAST / SCA
- OWASP Top 10
- API Security
Key Responsibilities
Application Security Strategy & Advisory
- Act as the Subject Matter Expert (SME) for application security across enterprise platforms and development teams.
- Define and enhance the organization's application security strategy, standards, and control frameworks.
- Provide expert guidance on secure design, secure coding, threat mitigation, and vulnerability management.
- Partner with engineering and architecture teams to embed security-by-design principles into applications and digital initiatives.
Secure SDLC / DevSecOps Enablement
- Drive implementation and maturity of the Secure Software Development Lifecycle (SSDLC).
- Integrate security controls and testing into CI/CD pipelines and DevSecOps workflows.
- Enable use of security tools and automation across build and release processes.
- Promote a shift-left security approach to detect and remediate issues early in the development lifecycle.
Architecture Reviews & Threat Modeling
- Perform application architecture and design reviews to identify security risks and recommend remediation strategies.
- Lead threat modeling sessions for web, mobile, API, and cloud-native applications.
- Review application components for vulnerabilities related to authentication, authorization, session management, input validation, data protection, and API security.
- Recommend secure reference architectures, reusable security patterns, and implementation guardrails.
Security Testing & Vulnerability Management
- Lead or support application security assessments, including:
- Static Application Security Testing (SAST)
- Dynamic Application Security Testing (DAST)
- Software Composition Analysis (SCA)
- API Security Testing
- Manual Security Reviews and Penetration Testing Coordination
- Static Application Security Testing (SAST)
- Analyze, triage, and prioritize vulnerabilities based on risk and business impact.
- Work closely with development teams to track remediation and validate closure of security issues.
- Support secure management of open-source components and third-party libraries.
Cloud & Modern Application Security
- Provide security guidance for modern application environments, including:
- Microservices and APIs
- Containers and Kubernetes
- Cloud-Native Applications
- Serverless and Event-Driven Architectures
- Microservices and APIs
- Collaborate with cloud and platform engineering teams to secure application workloads in Azure, AWS, or GCP.
Compliance, Governance & Risk
- Ensure application security practices align with internal security policies and external standards and regulations.
- Support compliance requirements related to secure development and application security controls.
- Contribute to audit responses, control evidence collection, and security risk assessments.
- Develop security metrics, dashboards, and reporting to track application security posture and control effectiveness.
Required Qualifications
- Bachelor's degree in Computer Science, Information Security, Engineering, or related field.
- 8+ years of experience in Application Security, Secure Software Engineering, Cybersecurity Architecture, or related roles.
- Proven experience implementing and managing application security programs in enterprise environments.
Strong Understanding Of
- Secure SDLC / SSDLC
- DevSecOps Principles
- OWASP Top 10
- API Security Top 10
- Common Software and Web Application Vulnerabilities
Hands-On Experience With Application Security Testing Tools
SAST
- Checkmarx
- Fortify
- Veracode
- SonarQube
DAST
- Burp Suite
- AppScan
- Acunetix
SCA
- Snyk
- Black Duck
- Mend / WhiteSource
Additional Requirements
- Experience in Threat Modeling methodologies (e.g., STRIDE).
- Strong knowledge of Authentication, Authorization, Encryption, Secrets Management, and Secure Design Principles.
- Experience working with Cloud Platforms such as Azure, AWS, or GCP.
- Strong verbal and written communication skills with the ability to work across technical and non-technical stakeholders.
Preferred Qualifications
- Experience in highly regulated industries such as:
- Banking
- Financial Services
- Insurance (BFSI)
- Healthcare
- Public Sector
- Banking
Familiarity With
- NIST
- ISO 27001
- PCI-DSS
- SOC 2
- OSFI Guidelines (Canada)
CI/CD Platforms
- Azure DevOps
- Jenkins
- GitHub Actions
- GitLab
Additional Exposure
- Container Security
- Kubernetes Security
- Cloud Workload Protection
- Red Team / Blue Team Collaboration
- Application-Layer Attack Simulation
- Security Incident Response Readiness
Preferred Certifications
- CISSP
- CSSLP
- CISM
- CEH
- GWAPT
- OSCP
- Azure Security Certifications
- AWS Security Certifications
- GCP Security Certifications
$122.74k - $141.95k per year
...HelloFresh a trusted name - someone with a passion for security and appetite for new challenges. Security Engineers work in a variety of ways to constantly iterate... ...network/cloud penetration, web and mobile application testing, source code reviews, threat analysis, wireless...SuggestedWork at officeRemote workWork from homeFlexible hours2 days per week3 days per week- ...Job Title: Senior QA Automation Engineer – (eCommerce, NeoLoad/LoadRunner, TOSCA, Tricentis) Experience Level:... ...Tricentis, NeoLoad, LoadRunner, QTest, TOSCA • eCommerce Application experience - Must • Test case writing experience - Must • Agile experience -...SuggestedContract work
$121k - $170k per year
...As a Lead, Information Security reporting to Senior Director, Information Security... ...role in designing and delivering secure solutions, protecting systems and applications, and supporting regulatory... ...assessments — including penetration testing and ethical hacking — across complex...SuggestedLong term contractFull timeTemporary workWork at office3 days per week$92k - $118k per year
...Capco is seeking a DevOps/DevSecOps Engineer to join our Technology & Engineering practice in Toronto... ...with development, infrastructure, and security teams to implement DevOps and DevSecOps... ...role requirements, and AI-scheduling applications to improve the efficiency of interview...SuggestedInternshipImmediate start- ...Role: Technical Lead – AI & Secure Application Development Technical Lead – Java | Python | Spring Boot | AI | Secure Coding | Microservices... ...integration while driving AI-enabled development and secure engineering best practices. Key Responsibilities • Integrate...SuggestedContract workWork at office3 days per week
$69k - $114k per year
...coaching Deloitte Global is the engine of the Deloitte network. Our... ...day look like? The Application Segmentation Engineer candidate... ...Trust and micro segmentation security practices. The primary... ...activities including discovery, testing, validation, enforcement, and...Permanent employmentRemote workFlexible hours$90k - $125k per year
...cars. Could you be the full-time Application Design Engineer – Supervision Control Center (SCC) in Toronto,... ...Perform Data Preparation for ATS, SCADA and Security System based on the Design Document and Tools. Test DataPrep output. Ensure configuration management...Long term contractFull timeWorldwideFlexible hours- ...Threat Modeler / Security Architect – AI Security, Cloud & DevSecOps Must Have Technical/Functional Skills Security... ...• ATT&CK • STRIDE Application Security & DevSecOps •... ...programs. Secure Design & Engineering Enablement • Develop, maintain...Permanent employment
$80k - $130k per year
...implement comprehensive automated testing strategies for ETL pipelines data... .... Develop and maintain robust test automation frameworks for data and application testing. Collaborate with... ...Establish and promote Quality Engineering best practices standards and governance...Full timeWork at office- ...Job Summary: The Construction, Testing & Commissioning Engineer will be responsible for planning, executing, and supervising construction, installation... ...safety protocols. # Testing & Commissioning Define test objectives, scenarios, procedures, environments, and tools...
- ...Senior Security Engineer Location : Toronto, On-Site Reports to: Head of Security... ...SSO/SCIM integrations across the full application estate Implement phishing-resistant... ...code capabilities — version-controlled, tested, CI/CD-deployed detections Design and...Full time
$80k - $138k per year
...the team Deloitte’s Cyber Security practice advises organizations... ..., implement, and operate secure identity and access management... ...including Conditional Access, application integrations, SAML/OIDC-based... ...and provisioning (SCIM where applicable) • Knowledge of automation...Permanent employmentFlexible hours$140k - $192.5k per year
...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential... ...Verify Team builds desktop and mobile applications for authentication and authorization... ...applications securely. The Staff Software Engineer in Test Opportunity We seek a passionate and...Local areaWorldwide$150k - $200k per year
...consisting of project controls, operations, finance, estimating, engineering, and other functional groups. Improve project outcomes by... ...Through the implementation of the requirements of the ACA and its applicable regulations, appropriate accommodations will be provided upon...Long term contractContract workFor contractorsInternship- Application Security Architect – CONTRACT – (2-3 days per week) We are looking for an Application Security Architect for a contract role requiring 2-3 days work per week. Onsite is required once every 2 weeks in GTA by Toronto Airport. Your basic responsibilities include:...Contract work2 days per week3 days per week
- ...Job Responsibility: Job Title: IT Security Engineer Job Overview: We are seeking few highly... ...in network security, cryptography, and secure IT architecture. This position offers an... ...-related projects. Security Protocol Testing & Training: Design, develop, and execute...Contract work
$88k - $132k per year
...for dynamic individuals in the Oracle Applications Security and GRC space for on premise and cloud... ...Business Administration, Computer Science, Engineering, Accounting or Information Systems... ...salary ranges in accordance with applicable provincial pay transparency legislation...Weekend work$72k - $138k per year
...ll work closely with utility electrical engineers, delivery teams and product teams to validate... ...configurations. Conduct rigorous testing of load flow calculations, identifying... ...s load flow capabilities and real-world applications. Collaborate with the product team to...Permanent employmentWorldwideFlexible hoursShift work- ...fintech organization looking to add a Senior Software Development Engineer in Test! What youll be responsible for in this role: Leading... ...genetic information political views or activity or other applicable legally protected characteristics. E6 is committed to providing...Full time
- ...AI Security Solution Architect – Application Security, Zero Trust & AI Governance Role Summary • Lead the... ...regulatory compliance, auditability, and secure SDLC integration. Required... ...• LLM risk management DevSecOps & CI/CD • Experience with CI/CD...
$142k - $160k per year
...your contributions. The Job: Cyber Security Engineer What You’ll Do Reporting to the... ...Partner with infrastructure, cloud, application, and business teams to drive timely remediation... ...Controls Application Security Testing PKI/TLS Certificate Lifecycle Management...Temporary workWork at officeRemote work- ...sized organizations in Canada/US. We are currently hiring a Application Release Engineer - Azure for our consulting client in the Toronto area.... ...provisioning automation Delivering changes to development test and production environments. Must Have Skills: Scripting...Full timeContract work
$125k - $175k per year
...crime protect assets and guard national security. With employees based around the... ...experienced Senior Software Development Engineer in Test (SDET) to join our engineering team supporting... ...Familiarity with testing LLM-powered applications and agentic systems; Experience with...Full timeContract workWork at officeLocal areaFlexible hours$45 - $50 per hour
...Remote - Canada PST Oracle Certified Functional SME (Finance - AR, AP, GL, FA) Implement/Support Oracle Application. Ability to understand and articulate client's... ...TE020 and other documents (Configuration, To-Be, FD, TEst Scripts Etc) Strong written and oral communication...Hourly payFixed term contractRemote work$121.12k - $181.68k per year
...with their most complex legal matters. Engineering Manager - Applications, BI & AI Enablement The Role We... ...for code quality, data quality, security, reliability, and maintainability.... ...efficiency through better patterns for testing, review, documentation, and delivery....Full timeLocal area- ...team and role: The Cloud Security team is focused on protecting... ...Robinhood's AWS cloud and providing engineers with foundational security... ...developers to protect their applications. What you bring: The... ...our team by completing this Applicant Accommodation Form. Click...Full time
$137k - $189k per year
...We are hiring a Senior Software Engineer to join our Server Security team. The Server Security team is a development... ...! Let’s change what’s possible for application developers, system architects, and... .... What you’ll do: Build and test new security features in a large, feature...Full timeRemote workWorldwideFlexible hours$96 per hour
Role: CIAM Security Engineer Rates: Up To $96.00 p/h INC. Location: Downtown Toronto, 2x per... ...OpenID Connect, SAML, LDAP, and their application across enterprise and customer identity... ...authentication solutions, ensuring secure, consistent implementations across channels...Contract workBank staff$110k - $140k per year
...excited about! Your role and responsibilities: As a Photonics Test Engineer you will drive the characterization of our active optical... ...intelligence (AI) tools to assist in the screening and assessment of applicants for this position. These tools assist our recruitment team but...Full time$141k - $193k per year
...Secure Every Identity, from AI to Human Identity is the key to... ...The Staff Product Security Engineer Opportunity As a Staff Product... ...in code reviews, penetration testing, and architectural security... ...technical understanding of web applications, backend services,...Local areaWorldwideFlexible hours
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Application Security Engineer (SME) - DevSecOps, Pen Testing. Be the first to apply!
- application engineer Toronto, ON
- automation application engineer Toronto, ON
- software application developer Toronto, ON
- security engineer remote Toronto, ON
- aws security engineer Toronto, ON
- physical security engineer Toronto, ON
- security engineering manager Toronto, ON
- product security engineer Toronto, ON
- security system engineer Toronto, ON
- cnc applications engineer
