Security & Trust Engineer at AssetWatch, Inc.
Canada, Ontario, Canada -
Full Time


Start Date

Immediate

Expiry Date

21 Dec, 26

Salary

65000.0

Posted On

28 Sep, 26

Experience

2 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Industry

Information Technology & Services

Description

Responsibilities

Perform threat modeling, risk assessments, and architecture reviews to identify and mitigate risk


Support the engineering teams on detailed security requirements to meet compliance requirements and industry best practices


Perform security code reviews looking for potential security vulnerabilities


Act as a subject matter expert to advise and answer questions from engineering and compliance teams on technical product security matters


Define and oversee the deployment of Software Composition Analysis (SCA) tools to compile SBOMs of software components, helping to identify known vulnerabilities and license compliance violations

Define and oversee the deployment of automated security testing tools into CI pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Secret Detection scanning tools

Manual penetration testing of web applications (backend and frontend).Manual penetration testing skills in the domains of cloud infrastructure, embedded/OS or mobile are desirable

Write custom scripts or unit test cases to check for vulnerabilities or broken/missing security controls


Recommend improvements to existing security scanning tools and processes, and propose new ones


Triage the findings from the automated security scanning tools


Validate potential security vulnerabilities to determine whether they are actual true positives, or false positives (i.e. non-applicable) in the product context. Write proof of concept exploits when necessary to achieve this

Assess the risk of vulnerabilities and threats in order to help the business determine their remediation priority order


Communicate the identified security issues to engineering and compliance stakeholders, and manage them throughout the SDLC process to ensure they are properly addressed

Establish and maintain secure coding standards, baseline product security requirements and more general best practices to provide guidance to development teams

Responsibilities

Responsibilities

Perform threat modeling, risk assessments, and architecture reviews to identify and mitigate risk


Support the engineering teams on detailed security requirements to meet compliance requirements and industry best practices


Perform security code reviews looking for potential security vulnerabilities


Act as a subject matter expert to advise and answer questions from engineering and compliance teams on technical product security matters


Define and oversee the deployment of Software Composition Analysis (SCA) tools to compile SBOMs of software components, helping to identify known vulnerabilities and license compliance violations

Define and oversee the deployment of automated security testing tools into CI pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Secret Detection scanning tools

Manual penetration testing of web applications (backend and frontend).Manual penetration testing skills in the domains of cloud infrastructure, embedded/OS or mobile are desirable

Write custom scripts or unit test cases to check for vulnerabilities or broken/missing security controls


Recommend improvements to existing security scanning tools and processes, and propose new ones


Triage the findings from the automated security scanning tools


Validate potential security vulnerabilities to determine whether they are actual true positives, or false positives (i.e. non-applicable) in the product context. Write proof of concept exploits when necessary to achieve this

Assess the risk of vulnerabilities and threats in order to help the business determine their remediation priority order


Communicate the identified security issues to engineering and compliance stakeholders, and manage them throughout the SDLC process to ensure they are properly addressed

Establish and maintain secure coding standards, baseline product security requirements and more general best practices to provide guidance to development teams

Loading...