Description
A career as an application security (AppSec) practice leader in the information security team, CISO, at National Bank means acting as an expert and playing an important role in improving the application security practice. It is through your experience in operational cybersecurity, your in-depth knowledge of secure coding and your strong leadership that you will have a positive impact on the security of the Bank and its customers.
Your job:
- Define and implement technical standards ensuring the quality of deliverables
- Collaborate with the service owner as well as the delivery teams in the establishment, implementation and adoption of procedures aligned with the defined business needs
- Monitor and advise the various operational mandates of the team
- Establish a culture of secure development
- Act as a key player in communicating the best practices of application security within development teams
- Contextualize application vulnerabilities
- Support development teams about any application security questioning
Your team:
As a member of the Security Operations Center (SOC), you will be part of a team of approximately 12 people and will have the opportunity to collaborate on a daily basis with experts in defensive and offensive security, cyber threat intelligence and vulnerability management. This position reports to the Senior Director of Offensive Security Operations.
The Bank values continuous development and internal mobility. Our personalized training programs, based on learning in action, allow you to master your craft and develop new areas of expertise. Tools such as Udemy, the Data Academy, language training, the Harvard Learning Center, and coaching and mentoring support are available to you at all times.
Prerequisite:
- Completed industry-related training and 4 years of relevant experience or equivalent experience
- Extensive experience in enterprise software development
- Excellent knowledge of application security and cloud computing
- Experience with vulnerability scanning tools such as Snyk
- Experience with development systems such as Docker, Maven, dotnet, npm, and Poetry
- Experience in scripting to identify cases of bad practices in code