Role at its Core; This is will not be a hands-on SAST/DAST testing role - rather consulting as an application security risk advisor to help enhance security posture, and build secure controls to have a proactive risk management mindset. Risk Advisements on applications, infrastructure, cloud environments. Apply risk management frameworks, policies, and standards. Identify, analyze, and document security risks, vulnerabilities, and control gaps. Prepare and present risk assessment findings, mitigation plans, and recommendations to tech&business stakeholders.
Position: Application Security Risk Advisor
Client: Enterprise Banking client
Type: 6 month contract + extension
Rate: $62.52/hr incorporated
Hybrid: 2x downtown Toronto
Required Skills & Experience
- 7-10+ years of experience working as a security risk advisor at a major North American bank or a large consulting firm
- Azure cloud web risk measurement, web application security vulnerability risk measurement
- Deep understanding on if the application has to be authenticated, encrypted, hardened...and writing a risk report on what would happen if the above were not to be actioned
- Ability to read code security architecture
- Technical methodologies to assess risk such as STRIDE
- Not be hands on SAST/DAST testing - needs to be able assess results to identify risks
- Conducting risk assessments, remediation planning experience
- Application development security assessment
- Work with Development teams - partnering closely w. technology teams to identify and relay these risks)
- Excellent communication skills
** this is a backfill for an existing position**
**AI may be used to help format job description**