Requisition ID: 149385
Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.
The Application Security team has global accountability and is highly supportive of the Bank’s business, enabling execution of the Bank’s strategies, operations and services, while ensuring that appropriate security practices are adhered to. This function provides core competency in proactively detecting application code flaws and/or bugs while working with the appropriate teams in instituting appropriate controls to mitigate risks, specifically as it pertains to web application vulnerabilities and threats. The Mobile Security Lead will be expected to work closely with the application development groups to integrate application security processes and procedures into the software development lifecycle.
The Mobile Security Lead is responsible for supporting the Senior Manager, Director, VP, SVP and CISO in achieving IS&C Strategic goals through various processes, including:
Develop and/or enhance strategies and processes to manage security vulnerabilities and threats.
Develop and/or enhance communications to ensure prompt remediation from development and infrastructure support teams, in line with risk management practices.
Develop and/or enhance reporting to development teams and all levels of management in order to provide proper tracking and measurement of remediation activities
Recommend, design, assess, implement, deploy and maintain mobile security controls required to protect Scotiabank and its customers.
Responsible for developing and/or enhancing the strategies and processes to identify, analyze and communicate mobile application vulnerabilities as per the CISO Directive and published communication process flows.
Responsible for adherence to an established process flow that ensures development support teams, infrastructure support teams and business risk owners implement control measures that effectively mitigate or eliminate the identified risk.
Responsible for timely and accurate reporting of all findings to the development teams, appropriate levels of management and the business risk owner.
3+ years’ experience testing Multi-tier Web Applications, Web Services and Web API’s and/or Mobile Applications
Strong understanding of Windows and Linux operating systems
Experience side loading mobile applications on both Android and IOS platforms
Experience with jailbreaking and rooting both Android and IOS devices
Experience with virtualization technologies
Must have the ability to generate reports and tailor communication strategies for various levels of technical staff, executive management, and business clients.
Good communication and support skills for triaging and resolving technical issues.
Experience with scripting languages is an asset (Python, Bash, Powershell, etc.)
University degree or college diploma , and a minimum of four (4) years equivalent security industry-related experience required
CISSP, CEH, OSCP, GMOB and/or CISA designations would be an asset
Location(s): Canada : Ontario : Ottawa || Canada : Ontario : Scarborough
Scotiabank is a leading bank in the Americas. Guided by our purpose: "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.
At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.