
Senior Specialist, Application Security
Canada Mortgage and Housing Corporation
- Montreal, QC
- Permanent
- Full-time
- Annual paid vacation.
- Annual individual performance incentive.
- Defined benefit pension plan.
- Comprehensive group insurance plan to support your well-being from day one.
- Support towards your personal and professional growth with training, mentorship and more.
- An inclusive workplace culture and environment.
- Ensuring the organization's adherence to security requirements.
- Advising on secure system design and enterprise architecture.
- Providing security guidance for cloud migrations, devops and different IT initiatives.
- Advise on all IT-related projects to ensure they do not introduce additional risks to the organization and comply with security requirements.
- Identify and facilitate the implementation of appropriate controls to effectively manage information risks. Provide complex consultative advice to relevant stakeholders such as Enterprise Architecture, Devops, Audit and Compliance, etc).
- Define and enforce secure coding standards (OWASP Top 10, SANS Top 25, NIST).
- Implement Security-as-Code, integrating SAST, DAST, SCA, and container security scanning into CI/CD pipelines.
- Establish application security guidelines for authentication, authorization, and API security.
- Act as a senior subject matter expert in projects and collaborate with cross-functional teams to integrate security measures and promote adherence to cybersecurity best practices.
- Provide expert-level advice to leadership to guide and influence the management of IT Cybersecurity risks across the corporation.
- Act as an ambassador, and share your knowledge with colleagues and interested parties.
- Support the overall IT Cybersecurity Program and CMHC Corporate Strategy.
- Identify and support the development and evolution of the information Cybersecurity program.
- An undergraduate degree in a related field such as Cyber Security, Computer Security, Information Systems Security, Computer Science or in a related field.
- 8+ years of experience in application security, DevSecOps, and secure software development.
- Expertise in SAST, DAST, SCA, and container security tools (GitHub Advanced Security, Veracode, Owasp Zap, etc).
- A strong knowledge of API security (OAuth, JWT, WAF policies, etc).
- Experience in developement and integrating security into engineering workflows.
- Familiarity with secrets management tools (Azure Key Vault, Cyberark).
- Strong understanding of cloud security best practices (mainly Azure).
- Experience with CI/CD security integration (Azure DevOps, GitHub Actions).
- Experience and/or knowledge of recognized standards and risk frameworks (ie.:NIST CSF, ISO 27000, ITSG-33, etc.).
- Strong communication (written and verbal) and interpersonal skills, including the ability to negotiate, influence and challenge various audiences.
- Experience in writing complex cybersecurity risk analysis/risk assessment reports for a variety of audiences (technical and non-technical).
- A Professional designation, we would prefer Certified Information Systems Security Professional (CISSP), Azure security certifications, or other relevant cloud or Security licence, designation, or certificate.
- Experience with Threat Modeling and risk assessment.
- Familiarity with policy-as-code (OPA, Sentinel) for compliance enforcement.
- Leadership experience mentoring developers and integrating security into engineering workflows.
- A knowledge of Canadian laws and Government of Canada regulatory requirements and standards. E.g. Treasury Board, Office of the Superintendent of Financial Institutes, etc.
- Bilingualism (English and French).
- A background in AI security risks.
- Knowledge of chaos security testing and runtime security monitoring.