Job Summary
We are seeking a dynamic and detail-oriented AppSec Specialist to join our cybersecurity team. In this role, you will be at the forefront of safeguarding our digital assets by implementing, managing, and enhancing application security measures across diverse platforms and environments. Your expertise will help ensure our applications are resilient against evolving cyber threats, aligning with industry standards such as ISO 27001 and ISO 27002. If you thrive in a fast-paced, collaborative environment and are passionate about cybersecurity, this is your opportunity to make a significant impact!
Responsibilities
- Conduct comprehensive vulnerability research and security analysis on web and mobile applications, identifying potential risks and recommending mitigation strategies.
- Develop, implement, and maintain secure coding practices aligned with SDLC (Software Development Life Cycle) principles to ensure application security from inception through deployment.
- Perform regular security assessments using tools like Nmap, Fiddler, Splunk, and SIEM solutions to monitor for anomalies and potential breaches.
- Manage identity & access management protocols, including LDAP, Active Directory, and PKI systems, to enforce robust authentication and authorization controls.
- Collaborate with development teams using Agile methodologies to integrate security into CI/CD pipelines utilizing tools such as Terraform, Ansible, Jenkins, and DevOps practices.
- Configure and oversee network security devices including firewalls (Cisco ASA), VPNs, Cisco ISE, and intrusion detection systems to protect application infrastructure.
- Lead incident response efforts by analyzing security alerts related to web applications, cloud infrastructure (AWS, Google Cloud Platform), and network architecture components like routing protocols (OSPF, BGP).
Qualifications
- Proven experience in application security within an IT or cybersecurity environment with a strong understanding of computer networking concepts such as TCP/IP, DNS, DHCP, VPNs, and network protocols.
- Hands-on knowledge of operating systems including Windows, Linux (CentOS), UNIX, macOS, Solaris, and Android/iOS platforms.
- Familiarity with cloud computing platforms like AWS, Azure, Google Cloud Platform (GCP), along with cloud architecture best practices for high availability and disaster recovery.
- Proficiency in scripting languages such as Python, Bash (Unix shell scripting), PowerShell for automation of security tasks.
- Experience working within frameworks like COBIT or ISO 27000 series standards (ISO 27001/27002) for information security management.
- Ability to utilize security tools including SIEM (Splunk), SolarWinds, Fiddler, Nmap for vulnerability assessment and network monitoring.
- Strong understanding of encryption technologies including PKI certificates and SSL/TLS protocols for secure communications.
- Knowledge of PCI compliance standards related to secure payment processing environments is a plus.
Join us in protecting our digital landscape by leveraging your cybersecurity expertise! This role offers an exciting opportunity to work on cutting-edge security challenges while collaborating with talented professionals dedicated to excellence in information security.
Pay: $75,000.00-$90,000.00 per year
Work Location: Hybrid remote in Montréal, QC (Montréal)