Application Security Engineer
MindBridge Analytics Inc.
- Ottawa, ON
- Permanent
- Full-time
- Collaborate with MindBridge software developers and SREs to resolve security issues early. Provide guidance to developers on secure coding practices.
- Participate in design reviews and code reviews to identify issues through threat modeling.
- Work with our vulnerability management team to triage and resolve vulnerabilities and findings from pen tests.
- Maintain and enhance our SAST, DAST, SCA, and container image scanning components within CI/CD workflows.
- Implement policy-as-code for infrastructure and Kubernetes clusters.
- Continuous security awareness
- Keep up with the latest CVE alerts, threat intelligence, and cloud-native security tools.
- Contribute to security playbooks, incident response procedures, and team-wide awareness sessions.
- Assist with novel questions in customer security questionnaires
- Participate in our annual SOC 2 & ISO audit programmes
- Define secure usage patterns for LLMs (e.g., input validation, red-teaming).
- Secure our Azure cloud infrastructure, ensuring compliance with Zero Trust Architecture principles.
- Take part in reviewing LLM vendors and vendor deployments.
- Manage key initiatives, track outcomes, and support strategic decision-making with crisp data and context.
- 5+ years in DevSecOps, Cloud Security, or related roles.
- Written communication is key as this is a remote work team.
- Expert in securing Azure cloud environments (RBAC, NSGs, Key Vault, Defender for Cloud).
- Strong automation and scripting with tools such as Python, Bash, Terraform, and Helm.
- Experience with Kubernetes (AKS preferred) and container security (e.g., image hardening, runtime protection).
- Experience with version control (Git) and exposure to software development best practices for backend (Java/Python) and frontend (Angular)
- Familiarity with:
- CI/CD systems
- SAST/DAST tools
- Secrets management
- SIEM and security logging pipelines.
- Azure Security Engineer Associate or other relevant certifications (CISSP, CKS, etc.)
- Experience working in ISO 27001 or SOC 2 compliant environments.
- Familiarity with LLM threat models and generative AI safety techniques.
- Contributions to open-source projects or security research a plus.
- Fulfill requirements necessary to obtain full background check.
- This is a remote role, with preference for candidates in the Ottawa area for interview purposes. Weโre also open to other Canadian locations through referrals within our network. The ideal candidate will be available to attend in-person onboarding at our Ottawa office.
We are sorry but this recruiter does not accept applications from abroad.