Senior Security Researcher at Geotab ensuring secure development standards across hardware and embedded development. Collaborating with software developers and security teams on various projects.
Responsibilities
Utilizing programming tools to test devices, configuration, and code, providing risk assessments for vulnerabilities, and reporting on the overall quality of current security standards
Work closely with Geotab software developers, the broader Security team, and global strategic initiative stakeholders
Leverages security expertise in Hardware and Embedded Development
Conduct device, cloud infrastructure or web application and code testing for all systems and applications, open source dependencies, and provide analysis and risk assessments for vulnerabilities discovered
Conducts focused information security research and makes recommendations on changes within department and company
Utilize code analysis and fuzzing tools to assess the quality and security of source code
Provide recommendations on tools to address any gaps in coverage as well as defining and implementing security technical and process improvements
Contribute to secure device configuration, infrastructure design and coding standards (involves developing secure coding training for current and future developers)
Conduct manual code reviews for all systems and code changes for a given device, system or application release, providing both a detailed risk analysis of the security posture of the code and technical programming solutions (secure coding standards) to the developers to mitigate insecure code from being implemented
Provide reporting on overall quality of device, infrastructure configuration or source code from a security perspective by project/team (includes trend analysis, defects found, defects remediated, and time to remediate)
Triages and handles/escalates security issues within area of expertise
Support Geotab global strategic initiatives
Participate in candidate interviews during hiring process
Requirements
8+ years of experience with security evaluation/analysis within a technical organization, including security code reviews and risk assessments
8+ years of experience performing hardware, infrastructure, or embedded development (e.g., Network protocol analysis, debugging, virtualization)
Post-Secondary Diploma/Degree in Computer Science, Information Management, Engineering, or a related field
Technical proficiency with Linux, Windows, and languages such as C, Rust, and Python
Professional certification in Information Security (e.g., CISSP, CCSP, CSSLP, CEH, OSCP, OSWE) is highly valued
Excellent verbal and written communication skills, with comfort delivering technical training and presentations
Entrepreneurial mindset with the ability to stay organized and manage multiple priorities in a flat organization.
HR Systems Security Specialist responsible for design, configuration, and administration of security within Workday and SAP. Collaborating with HR and stakeholders to ensure effective access design and compliance.
Cybersecurity advisor working within the DCYB to develop IT security measures. Collaborating with teams to fortify cybersecurity posture and ensuring data protection for citizens.
Consultant in remuneration and occupational health and safety at the Quebec Federation of Municipalities. Ensuring employee needs match organizational requirements and promoting a safe work environment.
Cybersecurity Administrator providing operational support for compliance activities in information security. Assisting vendor risk management, audit coordination, and vulnerability tracking.
Sr. Manager leading cloud security, compliance, and governance at Metergy Solutions Inc. Drive regulatory adherence and risk mitigation across diverse cloud environments with a focus on security by design.
Security Advisor responsible for designing telecommunications network architectures at Alithya. Ensuring all components meet functional and non - functional requirements while adapting to new trends in the field.
Technical Lead in Cybersecurity Engineering at Morgan Stanley driving security initiatives. Collaborate with tech leaders to ensure enterprise - wide cybersecurity effectiveness and compliance in Montreal.
Cyber Security Intern supporting the operation of Capital Power’s cyber security infrastructure. Engaging in daily operational tasks, security reviews, and incident investigations.
Financial Security Advisor selling life and health insurance products and developing client relationships. Analyzing needs and recommending personalized financial solutions in a hybrid work setup.
Director of Identity Data & Workflow Engineering leading IAM engineering strategy and delivery. Overseeing identity data services, workflow automation, and APIs for the enterprise.