Senior Lead AppSec and CNAPP Operation at Scotiabank
Toronto, ON M1K 5L1, Canada -
Full Time


Start Date

Immediate

Expiry Date

08 Dec, 25

Salary

0.0

Posted On

09 Sep, 25

Experience

3 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Mitigation, Risk Assessment, Automation, Application Security, It, Working Experience, Jenkins, Sca, Vulnerability Assessment, Communication Skills

Industry

Banking/Mortgage

Description

Requisition ID: 230780
Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.

How To Apply:

Incase you would like to apply to this job directly from the source, please click here

Responsibilities

THE ROLE:

The incumbent is responsible for supporting the Senior Manager, Director, CIO and CISO in achieving enterprise security strategic goals through various processes, including:

  • Develop and/or enhance the strategies and processes to identify, analyze, and communicate AppSec and CNAPP vulnerabilities as per the CISO Directives, technical standards and published communication process flows.
  • Develop and/or enhance strategies and processes to manage the security vulnerabilities and threats for cloud native applications.
  • Develop and/or enhance reporting to development teams and all levels of management to provide proper tracking and measurement of remediation relative to established objectives.

IS THIS ROLE RIGHT FOR YOU? IN THIS ROLE, YOU WILL:

  • Collaborate with stakeholders across the Bank – you will work closely with development and engineering, DevOps, cloud, application security and other application owner teams across the organization to deliver Cloud and Application Security capabilities for the Bank.
  • Contribute to the success of our cloud transformation by supporting the Review and Triage of the findings flagged by AppSec and CNAPP.
  • Recommend, design, assess, implement, deploy and maintain AppSec and CNAPP controls required to protect Scotiabank and its customers.
  • Responsible for adherence to an established process flow that ensures development support teams, infrastructure support teams, and business risk owners implement control measures that effectively mitigate or eliminate the identified risk.
  • Understand how the Bank’s risk appetite and risk culture should be considered in day-to-day activities and decisions.

DO YOU HAVE THE SKILLS THAT WILL ENABLE YOU TO SUCCEED IN THIS ROLE? WE’D LOVE TO WORK WITH YOU IF YOU HAVE:

  • 10+ years’ relevant working experience in IT (cloud security, application security, etc.).
  • 8+ years’ experience with documenting process, procedure, and user guide.
  • 5+ years’ experience practicing application security (SAST, DAST, SCA, MAST) throughout the Secure Software Development Lifecycle (SSDLC), with demonstrated experience in vulnerability assessment, security integration, automation of security processes, risk assessment and mitigation.
  • 5+ years’ experience with Cloud Security domains like CNAPP, CWPP, CSPM and/or tools like SCCE, CrowdStrike, Prisma Cloud, Aqua Enterprise, MS Defender etc.
  • 5+ years’ experience with popular CI/CD tools and processes like BitBucket/GitHub, Jfrog Artifactory, Jenkins, Azure DevOps, GitLab CI/CD, CircleCI.
  • 3+ years’ experience with large organization cloud transformation.
  • Excellent communication skills and good support skills for triaging and analysis of issues for all development teams.
  • Proficient at collaborating with various stakeholders to achieve the objectives assigned.
  • Track records of mentorship and coaching skills for the team.
  • Undergrad or equivalent education.
Loading...