Application Security Manager embedding security directly into products, pipelines, and development workflows at ShareGate. Working closely with developers to ensure secure software delivery.
Responsibilities
Ensure security is embedded into CI/CD pipelines by delivering scalable, automated tooling and integrated security checks (SAST, DAST, SCA, secret scanning);
Enable secure-by-default development by designing and implementing automated, policy-driven security review workflows;
Establish robust security guardrails within AI-assisted development and agent workflows to reduce risk while maintaining developer velocity;
Reduce risk exposure by proactively identifying, assessing, and driving remediation of application security vulnerabilities;
Strengthen application security posture by leading threat modeling and security assessments for new features and architectural changes;
Improve detection and response capabilities through the development of automation, tooling, and streamlined vulnerability management processes;
Elevate cloud and application security by partnering with Infrastructure SecOps to harden Azure environments and deployment practices;
Enhance external security feedback loops by contributing to and scaling the bug bounty program and vulnerability intake processes.
Requirements
8+ years of experience in application security, DevSecOps, or security-focused software development;
Strong software engineering background combined with deep security expertise;
Deep understanding of web application security principles, OWASP Top 10, and CWE Top 25;
Hands-on experience performing secure code reviews in C#;
Experience building and maintaining security automation in CI/CD pipelines (GitHub Actions preferred);
Solid understanding of Azure cloud services, infrastructure security, and deployment patterns;
Experience integrating SAST, DAST, SCA, and secret scanning tools into development workflows;
Proficiency in scripting (Python, Bash) for automation and tooling;
Extensive hands-on experience with AI-assisted and agentic development workflows;
Familiarity with authentication protocols such as OIDC, SAML, and OAuth;
Ability to clearly communicate security risks and trade-offs to both technical and non-technical stakeholders.
Regional Health & Safety Manager leading health, safety, and regulatory compliance for GFL’s environmental services operations in Quebec. Conducting audits, incident management, training oversight, and regional site visits.
Information Security Student supporting vulnerability management and cloud security at Nasdaq Verafin. Assisting with remediation, security posture enforcement, and cloud environment protection.
Senior Principal Security Architect shaping enterprise security architecture for Invesco, a global investment - management firm. Leading cloud, identity, network, data - protection, and risk initiatives.
Principal Security Architect securing Menlo Security’s browser and AI - agent protection platform. Leading cryptography, cloud, vulnerability, and product security architecture.
BDC banking manager overseeing commercial loan security and disbursements across Western Canada. Coordinating due diligence, risk evaluation, lending partners and compliant loan funding.
Cybersecurity new graduate rotating through Intact’s 24 - month tech development program. Supporting threat detection, incident response, infrastructure security, and AI - enhanced security insights.