Hiring.Camp

Application Security Analyst

407Etr

·

5 days ago

Salary
$95k – $115k
Location
Head Office (6300 Steeles Ave W, Woodbridge, ON L4H 1J1), Canada
Workplace
Onsite
Type
Full-time
Department
Security
Experience
5+ years
Education
Master
Source
Workday

Description

Title: Application Security Analyst

Department: Information Technology

Location: 6300 Steeles Ave West, Woodbridge

Total Potential Compensation: $95,000-$115,000

Position Summary: 

As an Application Security Analyst, you will be responsible for supporting and operating core security capabilities across 407 ETR’s digital environment, with a primary focus on application security. This includes promoting secure-by-design practices throughout the SDLC and supporting the integration and operation of security tooling and automation, such as SAST, DAST, SCA, ASPM, and penetration testing services. You will work closely with Architecture, DevOps, QA, Product teams, and external partners to embed security controls into requirements, design, development, testing, and release activities, and track and manage security vulnerabilities through remediation. This role also contributes to improving the overall cyber and technology risk posture, with measurable improvements reflected in the Technology and Cyber Risk Indices (TRI/SRI).

Hours of work are onsite, Monday to Friday, 7.5 hours daily, or as required. After-hours support and on-call duties may be required for priority releases or security incidents. 

 

Position Responsibilities: 

AppSec Strategy & SDLC Integration 

  • Embed security requirements and nonfunctional controls into epics, features, and user stories; maintain security traceability throughout the lifecycle.

  • Lead threat modeling at design time for new and changed services (web, mobile, APIs, microservices) and ensure mitigations are implemented prior to coding.

  • Define and operate SDLC security gates (precommit, build, test, deployment) with policydriven thresholds (e.g., fail on Critical/High) and exceptions governance.

DevSecOps Tooling & Automation 

  • Implement and tune SAST, DAST, SCA and ASPM integrations within CI/CD, ensuring coverage, accuracy, and developerfriendly feedback loops; coordinate PTaaS cycles aligned to release schedules 

  • Partner with DevOps to secure build pipelines, artifacts, and environments (e.g., IaC scanning, container image hardening, secrets management, SBOM generation and validation) 

  •    Work with platform teams to evolve pipelines consistent with the 407 ETR DevOps framework and futurestate CI/CD models 

Findings Management & Risk Reporting 

  • Operate a unified findings intake (ASPM as system of record) for automated tool outputs and manual assessments; triage, prioritize, and track remediation to closure 

  • Apply a riskbased SLA model (severity, exploitability, asset criticality) and escalate overdue items; publish weekly triage outcomes and monthly KPIs.  

  • Report AppSec posture using TRI/SRI aligned metrics (e.g., unresolved criticals, meantimetoremediate, coverage, policy conformance) 

Secure Engineering Enablement 

  • Provide secure coding guidance, sample patterns, and remediation support for developers; deliver targeted training and office hours 

  • Collaborate on architecture reviews, pentest scoping, and change risk assessments for web and mobile (using established changetype workflow) 

  • Contribute to AppSec policies/standards and improve documentation (playbooks, runbooks, “definition of done” security criteria)  

Additional Technical Experience 

  • Experience with Data Loss Prevention (DLP) technologies and controls, including policy configuration, monitoring, and incident investigation, is required 

  • Experience with Single Sign-On (SSO) integrations and identity federation protocols is an asset. 

Compliance & Vendor Management 

  • Ensure controls align with PCI DSS Secure SDLC, ISO 27001/27002, and NIST DevSecOps guidance (e.g., SP 800204D); support internal/external audits and evidence collection 

  • Manage AppSec vendor relationships and deliverables per the Application Security Managed Service scope (ASPM, PTaaS, continuous monitoring) 

 

Note: This job description is not intended to be all-inclusive. The employee may perform other related duties, as assigned, to meet the ongoing needs of the organization.

Qualifications  

  • Minimum 5+ years of experience in IT Security, with strong hands-on experience in Security Operations.

  • College Diploma or University Degree in Computer Science, Engineering, or related field.

  • EDR platforms (e.g., endpoint containment, alert triage, investigation).

  • NDR technologies and network-based threat detection.

  • Security Incident Response and Investigation.

  • Strong understanding of attacker techniques and defensive controls (MITRE ATT&CK). 

  • Experience working in regulated or audit-driven environments.

  • Strong understanding of authentication, authorization, MFA, RBAC, and privileged access concepts. 

  • SSO Authentication: Experience implementing and supporting SSO solutions for secure user access across enterprise applications.

Preferred Qualifications

  • Knowledge of standing up a mature Application Security framework

  • Experience with enterprise SOC tooling including SIEM, EDR, NDR, SOAR.

  • Experience operating security controls in hybrid (on‑prem and cloud) environments. 

  • Familiarity with Security Risk Index (SRI), cyber risk metrics, or risk-based reporting.

  • Knowledge of network architecture and segmentation concepts. 

We are actively seeking to fill this role as it is a current vacancy.

About 407 ETR

Highway 407 ETR is an all-electronic open-access toll highway located in the Greater Toronto Area in Ontario, Canada. The highway spans 108 kilometres from Burlington in the west to Pickering in the east. 

407 International Inc. is the sole shareholder of 407 ETR and is owned by: 

  • Cintra Global S.E., a subsidiary of Ferrovial S.A. (48.29%)

  • Canada Pension Plan Investment Board (CPP Investments) and other institutional investors with non-controlling interests (44.20%)

  • Public Sector Pension Investment Board (PSP Investments) (7.51%)

 

Learn more at 407etr.com

Note: At 407 ETR, we are committed to fostering a diverse, equitable, and inclusive work environment. We value the unique perspectives and backgrounds of all individuals, and we firmly believe that our individual differences make us stronger as a whole.

Our commitment to inclusion extends beyond recruitment and encompasses an inclusive workplace culture through raising awareness, ongoing training, and encouraging feedback. We aim to create a safe and supportive environment where all employees can thrive.

Accommodation for disabilities or other grounds protected by human rights legislation are available upon request for candidates taking part in all aspects of the employment selection process.

 

Skills

CI/CDPenetration TestingSIEMSOCDevOpsMicroservicesComplianceLoss PreventionISO 27001

Similar Jobs

30

Application Security Analyst

Sound Physicians · Remote · Remote

4 days ago

Analyst, Application Security

Ice · Jacksonville, FL, US

1 week ago

Analyst, Application Security

Global Ice · Hyderabad, IN

2 weeks ago

Application Security Analyst

Merchants Bancorp · Carmel, IN

1 month ago

Application Security Analyst

Consumers Credit Union · Lake Forest, IL

1 month ago

Application Security Analyst

Bottomlinetechnologies · India

1 month ago

Application Security Analyst

Barclays · Gemini Building A, Prague, Czechia

2 months ago

Application Security Analyst

Toyota · Plano, United States of America

2 months ago

Application Security Analyst

First Line Software · Belgrade

4 months ago

Application Security Analyst

IKO is · Mississauga - Minnesota (HSS), Canada · Remote

5 months ago

Application Security Analyst

Careers Page · Lahore, Pakistan

7 months ago

Director Analyst, Application Security

Gartner · Remote - United Kingdom +2 · Remote

4 days ago

Cybersecurity Application Security Analyst - Expert

Huntington · Easton Ops Cols C Oh, United States of America · Onsite

1 week ago

Senior Analyst - Application Security

Fil · Dalian Office, China

1 week ago

Sr Director Analyst – Application Security and Governance

Gartner · Remote - United Kingdom +3 · Remote

2 weeks ago

Sr Director Analyst – Application Security and Governance (Remote - U.S.)

Gartner · Remote - Texas, United States of America · Remote

2 weeks ago

Junior Application Security Analyst

SYNNEX · Warsaw, Poland +6

3 weeks ago

ERP Application Security Analyst

Cat · East Peoria, Illinois, United States of America +2

3 weeks ago

Senior Application Security Analyst

AmerisourceBergen is now Cencora! Explore our careers. · APAC > India > Pune > Samrat Ashok Path

4 weeks ago

[8PP] Senior Security Analyst- Application Security & DevSecOps

Software Mind · San José, San José Province, Costa Rica · Remote

1 month ago

Senior Analyst - Application Security

Fil · Dalian Office, China

1 month ago

Senior Application Security Analyst

Washington Health Benef · Olympia, WA

1 month ago

IT Analyst Applications (QAD Application Security Analyst )

Cat · Bangalore, Karnataka, India

1 month ago

AI Application Security Analyst - AppSec & ML Security

Pureinsurance · Remote - US, United States of America · Remote

1 month ago

Epic Application Analyst (Security and Data Courier)

Cghmc · LOC003 Vision & Oral Surgery Clinic, United States of America +1

2 months ago

Senior Application Security Analyst (Pentester)

NowSecure · Remote

2 months ago

Senior Cyber Security Analyst, Application & Infrastructure

Irhythmtech · Remote - US, United States of America · Remote

3 months ago

Application Security Analyst for the global telecommunications company in Valencia, Spain

Worldwiders · V, Valencian Community

4 months ago

Senior Application Security Analyst

Bbposlimited · Hong Kong +1

9 months ago

IT Business Analyst (Application Security)

Transform IT · Remote, Onsite

11 months ago