Expert in application cybersecurity analyzing web components and supporting secure development practices within a dynamic team. Collaborate on cloud application security based in Quebec, Canada.
Responsibilities
Analyze the application security of web components, APIs, and microservices;
Provide security and mitigation recommendations;
Support developers in implementing secure development best practices;
Participate in application risk analysis and in prioritizing remediation measures;
Recommend appropriate security controls for Azure environments;
Contribute to authentication, authorization, and data protection mechanisms;
Support logging, detection, and incident monitoring/tracking;
Produce advisories, reports, risk registers, or mitigation plans.
Requirements
Significant experience in application cybersecurity
Experience with modern web applications, APIs, and microservices
Familiarity with OWASP best practices
Experience in cloud environments
Solid understanding of identity, MFA, OAuth2, OpenID Connect, or equivalents
Ability to explain risks and recommendations in plain language
Application security, API security, and secure development
Identity and access management
Secure code review, SAST/DAST or equivalent approaches
Logging, traceability, and data protection
Risk analysis and mitigation recommendations
Azure B2C / MSAL, Azure Key Vault, Azure WAF
Azure Monitor, Application Insights, Azure API Management
DevSecOps, OWASP ASVS, Quebec's Law 25
Experience in the public sector or in regulated environments
Relevant security certifications
Contract engagements or resource-pool arrangements, depending on client needs
Primarily remote work; availability to coordinate as needed for interventions
Benefits
Remote work and flexibility to accommodate family responsibilities
An entrepreneurial culture that fosters creativity and innovation
Flexible hours (depending on the type of employment contract)
Information Security Officer at Vecima Networks responsible for ISMS maintenance and ISO compliance. Supporting governance activities, supplier security, and incident response during maternity leave coverage.
Information Security Officer specializing in application and product security for the Government of Alberta. Safeguarding digital services through collaboration and compliance with cybersecurity policies.
Senior Security Engineer focusing on Application Security and Vulnerability Management for cybersecurity firm. Collaborating with teams on security operations, incident response, and compliance initiatives.
Security Analyst I supporting security operations and security engineering initiatives at Varicent. Collaborating across teams to strengthen security posture through operational excellence and risk - based decision - making.