Application Security Intern securing Kinaxis’s AI-powered supply-chain orchestration platform. Testing applications, managing vulnerabilities, and improving DevSecOps controls in Ottawa.
Responsibilities
Identify application-level security risks at each stage of development and ensure risks are assessed and mitigated
Integrate static and/or dynamic code analysis tools into the software development lifecycle
Arrange or conduct vulnerability and penetration tests against defined systems
Monitor application security trends and evolving technologies
Keep senior management informed about application security issues and implications for Kinaxis
Assist with risk assessments, threat modeling, and product security reviews
Review and triage SAST and SCA reports
Work with developers to prioritize and remediate findings
Help maintain and fix issues in CI/CD pipelines
Implement enhancements to in-house custom-built security tools
Partner with Corporate IT, Cloud Services, Product Development, and technology partners to implement security solutions and controls
Gain exposure to the full software development lifecycle, threat modeling, static/dynamic analysis, vulnerability management, and offensive security
Requirements
Completion of the 2nd year of a Computer Sciences / Computer Engineering program, Cybersecurity or related field
Currently enrolled in full-time education, or recent/upcoming graduate whose graduation date is within 12 months of the placement end date
Ability to work full-time with no interruption for 8 months starting January 2027
Basic knowledge of secure coding, application security testing, ethical hacking techniques, vulnerability management, and threat management
Hands-on experience with vulnerability management and penetration testing tools such as NMAP, Burp Suite, OWASP ZAP, Nexpose, SonarQube, and Metasploit
Familiarity with one or more programming languages such as JavaScript, PowerShell, Python, Java, or C#
Familiarity with the OWASP Top 10
Highly adaptable and able to pivot based on business priorities and needs
Proactively solicits feedback to ensure alignment
Excellent communication and collaboration skills
Experience with Docker and/or Kubernetes and Jenkins would help
Participation in CTFs, security clubs, or open-source contributions would help
Understanding of CI/CD pipelines and DevSecOps practices would help
Benefits
Flexible vacation and Kinaxis Days (company-wide days off)
Flexible work options
Physical and mental well-being programs
Regularly scheduled virtual fitness classes
Mentorship programs, training, and career development
Threat Intelligence Analyst investigating telecom security threats and customer deployment data for Enea, a global telecom and cybersecurity software company. Supporting client security reviews and threat intelligence operations.
Information Security Analyst governing End - User Computing risks, controls, and remediation for TD, a major North American bank. Advising stakeholders and supporting governance reporting, audits, and regulatory requirements.
IT Security Analyst II coordinating cybersecurity monitoring, MSP oversight, audits, and incident follow - up. Supporting Veristat’s global life - sciences services and regulated technology environments.
Security Analyst protecting GitLab’s DevSecOps platform through vulnerability triage and CVE operations. Coordinating researchers, customers, and internal teams on secure software response.
SIEM/SOAR cybersecurity analyst monitoring threats, building alerts, and measuring controls. Supporting Wepoint’s digital transformation work for businesses and public sector organizations.
SIEM/SOAR information security analyst supporting Wepoint’s digital transformation services. Developing cybersecurity monitoring cases, alerts, dashboards, and security - control documentation.
Security Analyst II protecting Intact’s insurance operations through incident response and SIEM monitoring. Supporting security platforms, incident resolution, dashboards, and IT security initiatives.
Lead AI risk analyst securing CBC/Radio - Canada’s public - service media technology. Designing enterprise AI governance, risk assessments and adversarial testing across the AI lifecycle.