Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Application Security Engineer (SME) - DevSecOps, Pen Testing

Temporary

Astra North Infoteck Inc.

Role Description

We are seeking an experienced Senior Application Security SME/ DevSecOps Security Consultant to lead and mature application security practices across enterprise platforms and development teams. The ideal candidate will have deep expertise in modern application architectures, secure coding practices, security testing methodologies, and the ability to partner effectively with development, engineering, DevOps, and risk teams to embed security throughout the software delivery lifecycle.

Primary Skills

  • Application Security
  • Secure SDLC (SSDLC)
  • DevSecOps
  • Threat Modeling
  • Cloud Security (Azure, AWS, GCP)
  • Security Architecture
  • Vulnerability Management
  • SAST / DAST / SCA
  • OWASP Top 10
  • API Security

Key Responsibilities

Application Security Strategy & Advisory

  • Act as the Subject Matter Expert (SME) for application security across enterprise platforms and development teams.
  • Define and enhance the organization's application security strategy, standards, and control frameworks.
  • Provide expert guidance on secure design, secure coding, threat mitigation, and vulnerability management.
  • Partner with engineering and architecture teams to embed security-by-design principles into applications and digital initiatives.

Secure SDLC / DevSecOps Enablement

  • Drive implementation and maturity of the Secure Software Development Lifecycle (SSDLC).
  • Integrate security controls and testing into CI/CD pipelines and DevSecOps workflows.
  • Enable use of security tools and automation across build and release processes.
  • Promote a shift-left security approach to detect and remediate issues early in the development lifecycle.

Architecture Reviews & Threat Modeling

  • Perform application architecture and design reviews to identify security risks and recommend remediation strategies.
  • Lead threat modeling sessions for web, mobile, API, and cloud-native applications.
  • Review application components for vulnerabilities related to authentication, authorization, session management, input validation, data protection, and API security.
  • Recommend secure reference architectures, reusable security patterns, and implementation guardrails.

Security Testing & Vulnerability Management

  • Lead or support application security assessments, including:
    • Static Application Security Testing (SAST)
    • Dynamic Application Security Testing (DAST)
    • Software Composition Analysis (SCA)
    • API Security Testing
    • Manual Security Reviews and Penetration Testing Coordination
  • Analyze, triage, and prioritize vulnerabilities based on risk and business impact.
  • Work closely with development teams to track remediation and validate closure of security issues.
  • Support secure management of open-source components and third-party libraries.

Cloud & Modern Application Security

  • Provide security guidance for modern application environments, including:
    • Microservices and APIs
    • Containers and Kubernetes
    • Cloud-Native Applications
    • Serverless and Event-Driven Architectures
  • Collaborate with cloud and platform engineering teams to secure application workloads in Azure, AWS, or GCP.

Compliance, Governance & Risk

  • Ensure application security practices align with internal security policies and external standards and regulations.
  • Support compliance requirements related to secure development and application security controls.
  • Contribute to audit responses, control evidence collection, and security risk assessments.
  • Develop security metrics, dashboards, and reporting to track application security posture and control effectiveness.

Required Qualifications

  • Bachelor's degree in Computer Science, Information Security, Engineering, or related field.
  • 8+ years of experience in Application Security, Secure Software Engineering, Cybersecurity Architecture, or related roles.
  • Proven experience implementing and managing application security programs in enterprise environments.

Strong Understanding Of

  • Secure SDLC / SSDLC
  • DevSecOps Principles
  • OWASP Top 10
  • API Security Top 10
  • Common Software and Web Application Vulnerabilities

Hands-On Experience With Application Security Testing Tools

SAST
  • Checkmarx
  • Fortify
  • Veracode
  • SonarQube
DAST
  • Burp Suite
  • AppScan
  • Acunetix
SCA
  • Snyk
  • Black Duck
  • Mend / WhiteSource

Additional Requirements

  • Experience in Threat Modeling methodologies (e.g., STRIDE).
  • Strong knowledge of Authentication, Authorization, Encryption, Secrets Management, and Secure Design Principles.
  • Experience working with Cloud Platforms such as Azure, AWS, or GCP.
  • Strong verbal and written communication skills with the ability to work across technical and non-technical stakeholders.

Preferred Qualifications

  • Experience in highly regulated industries such as:
    • Banking
    • Financial Services
    • Insurance (BFSI)
    • Healthcare
    • Public Sector

Familiarity With

  • NIST
  • ISO 27001
  • PCI-DSS
  • SOC 2
  • OSFI Guidelines (Canada)

CI/CD Platforms

  • Azure DevOps
  • Jenkins
  • GitHub Actions
  • GitLab

Additional Exposure

  • Container Security
  • Kubernetes Security
  • Cloud Workload Protection
  • Red Team / Blue Team Collaboration
  • Application-Layer Attack Simulation
  • Security Incident Response Readiness

Preferred Certifications

  • CISSP
  • CSSLP
  • CISM
  • CEH
  • GWAPT
  • OSCP
  • Azure Security Certifications
  • AWS Security Certifications
  • GCP Security Certifications
Vacancy posted a month ago
Similar jobs that could be interesting for youBased on the Application Security Engineer (SME) - DevSecOps, Pen Testing in Toronto, ON vacancy
  • $122.74k - $141.95k per year

     ...HelloFresh a trusted name - someone with a passion for security and appetite for new challenges. Security Engineers work in a variety of ways to constantly iterate...  ...network/cloud penetration, web and mobile application testing, source code reviews, threat analysis, wireless... 
    Suggested
    Work at office
    Remote work
    Work from home
    Flexible hours
    2 days per week
    3 days per week

    HelloFresh

    Toronto, ON
    9 hours ago
  •  ...Job Title: Senior QA Automation Engineer – (eCommerce, NeoLoad/LoadRunner, TOSCA, Tricentis)   Experience Level:...  ...Tricentis, NeoLoad, LoadRunner, QTest, TOSCA • eCommerce Application experience - Must • Test case writing experience - Must • Agile experience -... 
    Suggested
    Contract work

    Astra North Infoteck Inc.

    Toronto, ON
    8 days ago
  • $121k - $170k per year

     ...As a Lead, Information Security reporting to Senior Director, Information Security...  ...role in designing and delivering secure solutions, protecting systems and applications, and supporting regulatory...  ...assessments — including penetration testing and ethical hacking — across complex... 
    Suggested
    Long term contract
    Full time
    Temporary work
    Work at office
    3 days per week

    NASDAQ

    Toronto, ON
    29 days ago
  • $92k - $118k per year

     ...Capco is seeking a DevOps/DevSecOps Engineer to join our Technology & Engineering practice in Toronto...  ...with development, infrastructure, and security teams to implement DevOps and DevSecOps...  ...role requirements, and AI-scheduling applications to improve the efficiency of interview... 
    Suggested
    Internship
    Immediate start

    Capco

    Toronto, ON
    19 days ago
  •  ...Role: Technical Lead – AI & Secure Application Development Technical Lead – Java | Python | Spring Boot | AI | Secure Coding | Microservices...  ...integration while driving AI-enabled development and secure engineering best practices. Key Responsibilities • Integrate... 
    Suggested
    Contract work
    Work at office
    3 days per week

    Astra North Infoteck Inc.

    Toronto, ON
    a month ago
  • $69k - $114k per year

     ...coaching Deloitte Global is the engine of the Deloitte network. Our...  ...day look like?   The Application Segmentation Engineer candidate...  ...Trust and micro segmentation security practices. The primary...  ...activities including discovery, testing, validation, enforcement, and... 
    Permanent employment
    Remote work
    Flexible hours

    Deloitte

    Toronto, ON
    1 hour ago
  • $90k - $125k per year

     ...cars.       Could you be the full-time Application Design Engineer – Supervision Control Center (SCC) in Toronto,...  ...Perform Data Preparation for ATS, SCADA and Security System based on the Design Document and Tools. Test DataPrep output. Ensure configuration management... 
    Long term contract
    Full time
    Worldwide
    Flexible hours

    Alstom

    Toronto, ON
    1 day ago
  •  ...Threat Modeler / Security Architect – AI Security, Cloud & DevSecOps Must Have Technical/Functional Skills Security...  ...• ATT&CK • STRIDE Application Security & DevSecOps •...  ...programs. Secure Design & Engineering Enablement • Develop, maintain... 
    Permanent employment

    Astra North Infoteck Inc.

    Toronto, ON
    28 days ago
  • $80k - $130k per year

     ...implement comprehensive automated testing strategies for ETL pipelines data...  .... Develop and maintain robust test automation frameworks for data and application testing. Collaborate with...  ...Establish and promote Quality Engineering best practices standards and governance... 
    Full time
    Work at office

    CGI

    Toronto, ON
    7 days ago
  •  ...Job Summary: The Construction, Testing & Commissioning Engineer will be responsible for planning, executing, and supervising construction, installation...  ...safety protocols. # Testing & Commissioning Define test objectives, scenarios, procedures, environments, and tools... 

    Sapsol Technologies Inc

    Toronto, ON
    16 days ago
  •  ...Senior Security Engineer Location : Toronto, On-Site Reports to: Head of Security...  ...SSO/SCIM integrations across the full application estate Implement phishing-resistant...  ...code capabilities — version-controlled, tested, CI/CD-deployed detections Design and... 
    Full time

    dominion%20dynamics

    Toronto, ON
    9 hours ago
  • $80k - $138k per year

     ...the team Deloitte’s Cyber Security practice advises organizations...  ..., implement, and operate secure identity and access management...  ...including Conditional Access, application integrations, SAML/OIDC-based...  ...and provisioning (SCIM where applicable)  • Knowledge of automation... 
    Permanent employment
    Flexible hours

    Deloitte

    Toronto, ON
    1 day ago
  • $140k - $192.5k per year

     ...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential...  ...Verify Team builds desktop and mobile applications for authentication and authorization...  ...applications securely.  The Staff Software Engineer in Test Opportunity We seek a passionate and... 
    Local area
    Worldwide

    Okta

    Toronto, ON
    6 days ago
  • $150k - $200k per year

     ...consisting of project controls, operations, finance, estimating, engineering, and other functional groups. Improve project outcomes by...  ...Through the implementation of the requirements of the ACA and its applicable regulations, appropriate accommodations will be provided upon... 
    Long term contract
    Contract work
    For contractors
    Internship

    AECON

    Toronto, ON
    23 days ago
  • Application Security Architect – CONTRACT – (2-3 days per week)  We are looking for an Application Security Architect for a contract role requiring 2-3 days work per week. Onsite is required once every 2 weeks in GTA by Toronto Airport. Your basic responsibilities include:... 
    Contract work
    2 days per week
    3 days per week

    Ward Tech Talent

    Toronto, ON
    more than 2 months ago
  •  ...Job Responsibility: Job Title: IT Security Engineer Job Overview: We are seeking few highly...  ...in network security, cryptography, and secure IT architecture. This position offers an...  ...-related projects. Security Protocol Testing & Training: Design, develop, and execute... 
    Contract work

    Talent To Hire Inc.

    Toronto, ON
    10 days ago
  • $88k - $132k per year

     ...for dynamic individuals in the Oracle Applications Security and GRC space for on premise and cloud...  ...Business Administration, Computer Science, Engineering, Accounting or Information Systems...  ...salary ranges in accordance with applicable provincial pay transparency legislation... 
    Weekend work

    Ernst & Young

    Toronto, ON
    27 days ago
  • $72k - $138k per year

     ...ll work closely with utility electrical engineers, delivery teams and product teams to validate...  ...configurations. Conduct rigorous testing of load flow calculations, identifying...  ...s load flow capabilities and real-world applications. Collaborate with the product team to... 
    Permanent employment
    Worldwide
    Flexible hours
    Shift work

    Deloitte

    Toronto, ON
    1 hour ago
  •  ...fintech organization looking to add a Senior Software Development Engineer in Test! What youll be responsible for in this role: Leading...  ...genetic information political views or activity or other applicable legally protected characteristics. E6 is committed to providing... 
    Full time

    Episode Six

    Toronto, ON
    7 days ago
  •  ...AI Security Solution Architect – Application Security, Zero Trust & AI Governance Role Summary • Lead the...  ...regulatory compliance, auditability, and secure SDLC integration. Required...  ...• LLM risk management DevSecOps & CI/CD • Experience with CI/CD... 

    Astra North Infoteck Inc.

    Toronto, ON
    28 days ago
  • $142k - $160k per year

     ...your contributions. The Job: Cyber Security Engineer What You’ll Do Reporting to the...  ...Partner with infrastructure, cloud, application, and business teams to drive timely remediation...  ...Controls Application Security Testing PKI/TLS Certificate Lifecycle Management... 
    Temporary work
    Work at office
    Remote work

    Momentum Financial Services Group

    Toronto, ON
    21 days ago
  •  ...sized organizations in Canada/US. We are currently hiring a Application Release Engineer - Azure for our consulting client in the Toronto area....  ...provisioning automation Delivering changes to development test and production environments. Must Have Skills: Scripting... 
    Full time
    Contract work

    Tech Talent International

    Toronto, ON
    12 hours ago
  • $125k - $175k per year

     ...crime protect assets and guard national security. With employees based around the...  ...experienced Senior Software Development Engineer in Test (SDET) to join our engineering team supporting...  ...Familiarity with testing LLM-powered applications and agentic systems; Experience with... 
    Full time
    Contract work
    Work at office
    Local area
    Flexible hours

    Magnet Forensics

    Toronto, ON
    12 hours ago
  • $45 - $50 per hour

     ...Remote - Canada PST Oracle Certified Functional SME (Finance - AR, AP, GL, FA) Implement/Support Oracle Application. Ability to understand and articulate client's...  ...TE020 and other documents (Configuration, To-Be, FD, TEst Scripts Etc) Strong written and oral communication... 
    Hourly pay
    Fixed term contract
    Remote work

    SYENERGY DATA INC

    Toronto, ON
    6 days ago
  • $121.12k - $181.68k per year

     ...with their most complex legal matters. Engineering Manager - Applications, BI & AI Enablement The Role We...  ...for code quality, data quality, security, reliability, and maintainability....  ...efficiency through better patterns for testing, review, documentation, and delivery.... 
    Full time
    Local area

    Bennett Jones

    Toronto, ON
    9 days ago
  •  ...team and role: The Cloud Security team is focused on protecting...  ...Robinhood's AWS cloud and providing engineers with foundational security...  ...developers to protect their applications. What you bring: The...  ...our team by completing this Applicant Accommodation Form. Click... 
    Full time

    Robinhood

    Toronto, ON
    3 days ago
  • $137k - $189k per year

     ...We are hiring a Senior Software Engineer to join our Server Security team. The Server Security team is a development...  ...! Let’s change what’s possible for application developers, system architects, and...  .... What you’ll do: Build and test new security features in a large, feature... 
    Full time
    Remote work
    Worldwide
    Flexible hours

    MongoDB

    Toronto, ON
    2 days ago
  • $96 per hour

    Role: CIAM Security Engineer Rates: Up To $96.00 p/h INC. Location: Downtown Toronto, 2x per...  ...OpenID Connect, SAML, LDAP, and their application across enterprise and customer identity...  ...authentication solutions, ensuring secure, consistent implementations across channels... 
    Contract work
    Bank staff

    CorGTA

    Toronto, ON
    1 day ago
  • $110k - $140k per year

     ...excited about! Your role and responsibilities: As a Photonics Test Engineer you will drive the characterization of our active optical...  ...intelligence (AI) tools to assist in the screening and assessment of applicants for this position. These tools assist our recruitment team but... 
    Full time

    Xanadu

    Toronto, ON
    7 days ago
  • $141k - $193k per year

     ...Secure Every Identity, from AI to Human Identity is the key to...  ...The Staff Product Security Engineer Opportunity As a Staff Product...  ...in code reviews, penetration testing, and architectural security...  ...technical understanding of web applications, backend services,... 
    Local area
    Worldwide
    Flexible hours

    Okta

    Toronto, ON
    6 days ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Application Security Engineer (SME) - DevSecOps, Pen Testing. Be the first to apply!