Application Security Expert

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 11-50H1B No SponsorCompany SiteLinkedIn

Location

Canada

Posted

2 days ago

Salary

0

Seniority

Senior

Bachelor DegreeFrenchAzureMicroservicesVault

Job Description

Application Security Expert

TEHORA inc.

• Analyze the application security of web components, APIs, and microservices; • Provide security and mitigation recommendations; • Support developers in implementing secure development best practices; • Participate in application risk analysis and in prioritizing remediation measures; • Recommend appropriate security controls for Azure environments; • Contribute to authentication, authorization, and data protection mechanisms; • Support logging, detection, and incident monitoring/tracking; • Produce advisories, reports, risk registers, or mitigation plans.

Job Requirements

  • Significant experience in application cybersecurity
  • Experience with modern web applications, APIs, and microservices
  • Familiarity with OWASP best practices
  • Experience in cloud environments
  • Solid understanding of identity, MFA, OAuth2, OpenID Connect, or equivalents
  • Ability to explain risks and recommendations in plain language
  • Application security, API security, and secure development
  • Identity and access management
  • Secure code review, SAST/DAST or equivalent approaches
  • Logging, traceability, and data protection
  • Risk analysis and mitigation recommendations
  • Azure B2C / MSAL, Azure Key Vault, Azure WAF
  • Azure Monitor, Application Insights, Azure API Management
  • DevSecOps, OWASP ASVS, Quebec's Law 25
  • Experience in the public sector or in regulated environments
  • Relevant security certifications
  • Contract engagements or resource-pool arrangements, depending on client needs
  • Primarily remote work; availability to coordinate as needed for interventions

Benefits

  • Remote work and flexibility to accommodate family responsibilities
  • An entrepreneurial culture that fosters creativity and innovation
  • Flexible hours (depending on the type of employment contract)
  • Sick leave and leave for family events
  • Appropriate IT equipment
  • A fulfilling and motivating workspace
  • Social and environmental initiatives
  • Workplace learning program
  • Career development path

Related Categories

Related Job Pages

More Security Engineer Jobs

eMazzanti Technologies logo

Virtual Chief Information Officer

eMazzanti Technologies

Technology Solutions for Business Growth

Full TimeRemoteTeam 51-200Since 2001H1B No Sponsor

Role Description The Virtual Chief Information Officer (vCIO) will be responsible for providing strategic IT leadership and vision to our organization. This role involves overseeing the development and implementation of IT initiatives, ensuring alignment with business goals, and optimizing technology resources to enhance operational efficiency and innovation. - Develop and implement IT strategies that align with the company's business objectives. - Provide expert guidance on technology investments, infrastructure, and digital transformation initiatives. - Oversee the management of IT operations, including network security, data management, and system maintenance. - Collaborate with executive leadership to identify and prioritize IT projects and initiatives. - Ensure compliance with industry regulations and standards related to information security and data privacy. - Lead and mentor the IT team, fostering a culture of continuous improvement and innovation. - Manage vendor relationships and negotiate contracts to ensure cost-effective solutions. - Monitor and assess emerging technologies to identify opportunities for business growth and improvement. - Develop and manage the IT budget, ensuring efficient allocation of resources. Qualifications - Bachelor’s degree in information technology, Computer Science, or a related field (Master's degree preferred). - Proven experience as a CIO, IT Director, or similar leadership role. - Strong understanding of IT infrastructure, systems, and best practices. - Excellent strategic thinking and problem-solving skills. - Ability to communicate complex technical concepts to non-technical stakeholders. - Experience with cloud computing, cybersecurity, and digital transformation initiatives. - Strong leadership and team management abilities. - Excellent organizational and project management skills. Requirements - Bachelor’s degree in information technology, Computer Science, or a related field (Master's degree preferred). - Proven experience as a CIO, IT Director, or similar leadership role. - Strong understanding of IT infrastructure, systems, and best practices. - Excellent strategic thinking and problem-solving skills. - Ability to communicate complex technical concepts to non-technical stakeholders. - Experience with cloud computing, cybersecurity, and digital transformation initiatives. - Strong leadership and team management abilities. - Excellent organizational and project management skills. Benefits - Competitive salary and performance-based bonuses. - Flexible working hours and remote work options. - Professional development opportunities. - Health, dental, and vision insurance. - Retirement savings plan.

United States
TEHORA logo

Application Security Expert

TEHORA

TEHORA est une firme québécoise multidisciplinaire reconnue pour l’excellence de ses services professionnels, de nature technique et de gestion de projets à l’échelle nationale et internationale. Notre mission est d’accompagner nos clients dans la concrétisation de leurs projets par l’excellence de notre savoir-faire et de notre créativité. Depuis sa création en 2017, notre équipe de professionnels connaît une croissance exponentielle en répondant aux besoins importants en gestion de projets multidisciplinaires, dans le domaine des transports, du génie civil, du TI et plus. Nos collaborateurs travaillent sur des mandats aussi bien à l’interne que chez des clients d’envergure. TEHORA se distingue par sa culture d’entreprise, axée sur le bonheur de ses employés et la diversité. Chez TEHORA, chaque collaborateur est un membre important de l’équipe qui contribue à notre succès collectif. Nos membres ont la flexibilité requise pour avoir un équilibre entre le travail et leur vie privée, tout en menant une carrière enrichissante. Nous offrons un environnement de travail motivant. La diversité des projets, la grande autonomie et l’interaction directe avec les clients sont appréciées. Une telle proximité est possible en raison de notre structure organisationnelle horizontale, qui se traduit par des relations de confiance et une communication efficace entre notre équipe et les clients.

Role Description TEHORA est présentement à la recherche d'un(e) expert(e) en cybersécurité applicative ayant d'excellentes aptitudes techniques, d'excellentes connaissances et qui souhaite mettre à profit ses compétences au sein d'une équipe polyvalente. La personne retenue accompagnera les équipes dans la sécurisation d'une plateforme applicative infonuagique. - Analyser la sécurité applicative de composants Web, API et microservices; - Formuler des recommandations de sécurisation et de mitigation; - Soutenir les développeurs dans l'application des bonnes pratiques de développement sécurisé; - Participer à l'analyse des risques applicatifs et à la priorisation des mesures; - Recommander des contrôles de sécurité adaptés aux environnements Azure; - Contribuer aux mécanismes d'authentification, d'autorisation et de protection des données; - Soutenir la journalisation, la détection et le suivi des incidents; - Produire des avis, rapports, listes de risques ou plans de mitigation. Qualifications - Expérience significative en cybersécurité applicative; - Expérience avec des applications Web modernes, API et microservices; - Connaissance des bonnes pratiques OWASP; - Expérience en environnement infonuagique; - Bonne compréhension de l'identité, MFA, OAuth2, OpenID Connect ou équivalents; - Capacité à vulgariser les risques et recommandations; - Sécurité applicative, sécurité API et développement sécurisé; - Gestion des identités et accès; - Revue de code sécuritaire, SAST / DAST ou approches équivalentes; - Journalisation, traçabilité et protection des données; - Analyse de risques et recommandations de mitigation; - Azure B2C / MSAL, Azure Key Vault, Azure WAF; - Azure Monitor, Application Insights, Azure API Management; - DevSecOps, OWASP ASVS, Loi 25; - Expérience dans le secteur public ou dans un environnement réglementé; - Certifications sécurité pertinentes; Requirements - Mandat contractuel ou banque de ressources, selon les besoins du client; - Télétravail principalement; disponibilité à coordonner selon les demandes d'intervention; Benefits - Du télétravail et de la flexibilité pour s’adapter à vos obligations familiales; - Une culture entrepreneuriale favorisant la créativité et l’innovation; - Horaires flexibles (selon le type de contrat de travail); - Congés en cas de maladie et à l’occasion d’événements familiaux; - Outils informatiques adaptés; - Espace de travail épanouissant et motivant; - Initiatives sociales et environnementales; - Programme d’apprentissage en milieu de travail; - Cheminement de carrière. Company Description TEHORA est une firme québécoise multidisciplinaire reconnue pour l’excellence de ses services professionnels, de nature technique et de gestion de projets à l’échelle nationale et internationale. Notre mission est d’accompagner nos clients dans la concrétisation de leurs projets par l’excellence de notre savoir-faire et de notre créativité. Depuis sa création en 2017, notre équipe de professionnels connaît une croissance exponentielle en répondant aux besoins importants en gestion de projets multidisciplinaires, dans le domaine des transports, du génie civil, du TI et plus. Nos collaborateurs travaillent sur des mandats aussi bien à l’interne que chez des clients d’envergure. TEHORA se distingue par sa culture d’entreprise, axée sur le bonheur de ses employés et la diversité. Chez TEHORA, chaque collaborateur est un membre important de l’équipe qui contribue à notre succès collectif. Nos membres ont la flexibilité requise pour avoir un équilibre entre le travail et leur vie privée, tout en menant une carrière enrichissante. Nous offrons un environnement de travail motivant. La diversité des projets, la grande autonomie et l’interaction directe avec les clients sont appréciées. Une telle proximité est possible en raison de notre structure organisationnelle horizontale, qui se traduit par des relations de confiance et une communication efficace entre notre équipe et les clients.

Canada

Role Description Na Qualificar TI, somos especialistas em Governança de Dados, Gerenciamento de Projetos, Transformação Digital e Outsourcing. Há mais de 24 anos, entregamos soluções estratégicas e as melhores práticas de TI para gerar valor real aos nossos clientes e à sociedade. Se você gosta de aprender, compartilhar conhecimento e construir soluções que fazem diferença, esta vaga é para você. - Elaboração, implantação e condução técnica de projetos de Identidade e Acesso / AD / Intune / Antivirus / SOC / SCCM. Qualifications - Formação: Bacharelado ou Tecnólogo nas áreas de Tecnologia de Informação. - Experiência consolidada, comprovada em carteira ou carta/declaração de empregador anterior, em ao menos duas das seguintes áreas de conhecimento: Identidade e Acesso / AD / Intune / Antivirus / SOC / SCCM. Requirements - Certificações obrigatórias: - Certified Data Management Professional (CDMP) da DAMA International. - Certified Information Management Professional (CIMP) da eLearningCurve. - Ou Pós-graduação ou MBA em Gestão da Informação, Gestão de Dados, ou Governança de TI. Benefits - Ambiente Inovador: Aqui você trabalha com um time diverso e colaborativo, que valoriza o seu conhecimento e incentiva seu crescimento. - Desenvolvimento Contínuo: Oferecemos treinamentos, certificações e programas de capacitação para você evoluir sempre. - Impacto Real: Atuamos em projetos estratégicos que transformam empresas e entregam resultados concretos. - Cultura que acolhe: Valorizamos a diversidade como parte da nossa cultura e acreditamos que a inovação nasce das diferenças.

Brazil
Full TimeRemoteTeam 11-50Since 2012H1B No Sponsor

• Develop, update, and maintain NIRIS software modules in accordance with agreed requirements, priorities, and release planning (NIRIS 4.7 and 4.8) • Evolve Java software components to support sustained compatibility with supported Java LTS runtimes • Implement agreed functional enhancements, including CESMO integration (Electronic Surveillance information exchange) and historic track data capabilities (filtered retrieval from stored NIRIS recordings) • Enhance the RTS subscription mechanism and UI to support filtering by source name, time interval, geolocation, and track number • Prepare software baselines for integration, testing, acceptance, and release • Develop and maintain unit tests and automated tests for implemented software changes • Support regression testing to ensure software quality, maintainability, and early defect detection • Ensure test coverage of at least 85% for delivered changes where technically applicable • Enhance NIRIS logging functionality, including per-port, per-endpoint, and per-interface logging • Implement logging filters, improved stack trace handling, log compression, and framework migration as required • Enable more efficient identification and analysis of runtime errors and operational incidents • Maintain and improve NIRIS interfaces with external systems, including support for Link 16 / JREAP, OTH-Gold, DIS, VMF, AIS, and other agreed formats • Provide technical support for interoperability test events (CWIX, TDLITS, INTEND, customer visits) • Address OANT/SMAQ configuration issues and analyser limit challenges • Update user manuals, governance documentation, technical design documents, interface documentation, test documentation, and release-related artefacts • Ensure all documentation remains accurate, current, and consistent with the implemented software baseline • Participate in sprint planning, daily stand-ups, sprint reviews, and project meetings • Track progress using agreed tools (Jira or equivalent) and proactively communicate risks or deviations • Submit Deliverable Completion Reports with evidence of code commits, test results, and traceability to acceptance criteria

Netherlands