Description:
They are looking for an AppSec developer to play a cross-functional and structuring role as a center of excellence in secure development. This person will work closely with the development, CI/CD, and information security teams, as well as the teams responsible for AI governance and responsible use.
Responsibilities:
- Application
Security and Security Practices:
- Define, maintain,
and evolve the security development standards used across Desjardins
- Ensure the
security of internally developed frameworks
- Identify
vulnerabilities, assess their risks, and recommend pragmatic and appropriate
corrective measures
- Promote the
secure-by-design and shift-left security approach
- Design,
develop, and maintain reusable Java security libraries, frameworks, and
components across the organization
- Integrate
application security mechanisms such as authentication, authorization, secure
secret management, encryption, traceability, and secure logging
- Ensure the
security of internally developed frameworks, from their design to their use in
production
- Conduct
code reviews of critical components and propose security and security
improvements Maintainability
- Support
teams in integrating and using common security components
- Cross-functional
role / AppSec Center of Excellence:
- Act as the
organizational reference for application security in development
- Participate
in the development of common patterns, guides, and tools
- Foster a
shared security culture, aligned with Desjardins' cooperative values
- Develop
common technological assets enabling the adoption of best security practices by
development teams
- Act as a
mentor and technical advisor to developers on the challenges of secure
development and securing Java applications
- Participate
in the evolution of security services and platforms made available to delivery
teams
- CI/CD
pipeline integration:
- Collaborate
with DevOps and CI/CD teams to:
- Participate
in the integration of AppSec controls into pipelines (SAST, DAST, SCA, secrets)
- Participate
in the implementation of vulnerability monitoring, detection, and remediation
tools
Description of
the Desired Profile
- The client
envisions an experienced Java developer with a background specializing in
application security, capable of producing code (libraries, frameworks,
reusable security components) while also fulfilling a key role a
cross-disciplinary reference as an AppSec center of excellence.
- The recurring
terms (secure by design, shift-left security, OWASP Top 10, CWE, reusable components)
indicate an expectation of maturity in securing the code itself, not in network
or infrastructure security.
- The desired
profile is hybrid in the strictest sense: neither a generalist Java developer
without a security dimension, nor a security specialist without code
production. The influence component (mentoring, bosses, guides, team support)
is structural and not secondary: the candidate must have already held a
cross-functional role, not just worked within a project team.
- The official
title "Expert IT Security Developer" is broader than the actual role,
which is centered on AppSec and secure Java development, potentially attracting
candidates with network security or governance backgrounds.
Requirements
Required:
- Demonstrated
expertise in application security (AppSec)
- Advanced,
object-oriented Java development
- Development of
reusable frameworks, libraries, or technical components
- Knowledge of
OWASP Top 10 vulnerabilities, CWE, and secure coding practices
- Cross-functional
role (reference, mentoring, team support)
Desired:
- Authentication
and authorization: OAuth2, OpenID Connect, JWT, SAML, or equivalent
- Security
mechanisms: encryption and key management, secrets management, secure logging,
data protection, access controls, and API protection
- Integration of
AppSec controls into CI/CD pipelines: SAST, DAST, SCA, secrets scanning
Asset:
- Tools: SonarQube,
Wiz, Kubernetes, GitHub, or Azure DevOps
- Distributed
architectures, microservices, cloud environments
- Interest in or
knowledge of AI-related security issues