Information Security Officer specializing in application and product security for the Government of Alberta. Safeguarding digital services through collaboration and compliance with cybersecurity policies.
Responsibilities
Development, maintenance, advocacy, and compliance for security architecture and DevSecOps framework and policy instruments such as directives, frameworks, policies, standards, and guidelines.
Security architecture subject matter expertise in the one or more following domains: Secure application development processes and tools.
Secure business architecture. Secure data architecture. Secure application architecture. Secure technology architecture.
Consultation, evaluation, and delivery of digital service products throughout the solution development life cycle (SDLC) for conformance to IMT cybersecurity policy instruments including formulation of options and recommendations.
Conduct security review, consult, and advise on secure coding, secrets management, on-premises, Amazon Web Services (AWS), Azure, Google Cloud Platform (GCP), and third-party hosted solutions with verbal and written report.
Provide security advice to business and technical stakeholders, including senior executives.
Participate in projects as an information security subject matter expert with a focus on security architecture and security capabilities within a DevSecOps framework to protect digital service development and operations.
Participate in the identification of information security requirements, as well as the development of strategies and solutions to meet these requirements across the organization.
Facilitate or perform identification, assessment, and treatment of information and technology security threats and risks.
Requirements
A university degree in Computer Science, Information Technology, or a related field.
Minimum of 4 years of related experience in:
Secure solution delivery life cycle, Secure application development.
Securing continuous integration and continuous deployment (CI/CD), DevSecOps, testing, and security architecture.
Equivalencies: A related two-year diploma from a recognized post-secondary institution and a minimum of six (6) years related experience; or A related one-year certificate from a recognized post-secondary institution and a minimum of seven (7) years related experience.
Security certification (CISSP, CISM, CISA, CEH, GPEN, or equivalent) or working toward certification is expected.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.
Senior security advisor simulating cyber threats and strengthening defenses for Desjardins, North America's largest cooperative financial group. Leading complex initiatives, methodologies and cybersecurity risk mitigation.
SA&A Lead securing Azure applications and Microsoft platforms for PLATO, Canada’s Indigenous - owned software testing company. Leading authorization, control testing, evidence collection, and risk remediation.
Senior security advisor simulating and mitigating cyberthreats for Desjardins, North America's largest cooperative financial group. Leading offensive security methodologies, tools and strategic initiatives.
Staff Product Security Engineer building customer identity and authentication services for Affirm’s buy - now - pay - later platform. Designing secure, scalable CIAM backend systems and integrations.
Senior Security Engineer securing AWS infrastructure, production systems, and AI - driven workflows. Building guardrails, vulnerability remediation, monitoring, and incident response for a rapidly scaling platform.