Search jobs > Toronto, ON > Application engineer

Senior Application Security Engineer

theScore
Toronto, ON
Full-time

About the Role & Team

As part of the theScore team, you will be working with a team of smart, friendly, and dedicated Engineers, Product Managers and Designers determined to deliver some of the best apps the market has to offer.

We want you to be challenged and to get the full experience of what it is like to work at theScore! We are looking for a Senior Application Security Engineer to join our Application Security team.

Our team takes a hands-on approach to solving complex security problems in conjunction with writing policies and procedures.

You will work cross-functionally across the entire engineering organization. You will share your unique expertise with the team and be able to grow and expand that expertise.

We have a wide variety of security challenges, and we are looking for someone who is excited to tackle them. Come join us and help us build the best sports apps in the world!

About the Work

  • Collaborate with release and change management, SRE, Engineering, and compliance teams
  • Work with security / internal / external / state auditors to demonstrate compliance
  • Maintain a working knowledge of OWASP top 10 and MITRE top 25 CWE
  • Develop standards for security tooling focused on the application layer (SAST, DAST, SCA, MAST, RASP)
  • Build / implement secure artifact workflows in the SDLC to ensure governance and compliance standards are being met
  • Create technical approaches to implementing Application Security control technologies
  • Contribute to theScore’s Application Security program to support our continued growth
  • Define and report on security metrics, their delivery, and improvements
  • Work with service teams to conduct threat models of theScore’s internal and customer facing applications
  • Assist service teams in understanding and remediating security findings (code bashing)
  • Other duties as required.

About You

  • 5+ years of Application Security or DevOps experience
  • 5+ years of GCP or AWS experience
  • Experience with software supply chain security (SBOMs, Artifact Signing, Attestations)
  • Programming experience in Python or Go
  • Experience with implementing security tooling in CI / CD
  • Experience creating complex CI / CD workflows (building for multiple architectures, local caching, making automated source code changes based on workflow output)
  • Experience supporting RESTful APIs and securing containerized workloads (GKE, EKS)
  • Experience working in regulated environments (PCI-DSS, SOC 2, etc.)
  • Experience leading technical projects and seeing them through to completion
  • Excellent communication skills and a history of working well with other teams
  • Optional : Experience maintaining Kubernetes clusters, or managing Kubernetes deployments

What We Offer

  • Competitive compensation package.
  • Fun, relaxed work environment.
  • Education and conference reimbursements.
  • Parental leave top
  • Opportunities for career progression and mentoring others.

LI-REMOTE

Candidates residing in Ontario requiring special accommodation can email

23 days ago
Related jobs
BMO
Canada, Canada

The Application Security Testing Engineer reports to the Lead of DevSecOps and assists with the security testing activities for BMO based applications. Assists with the execution of highly technical/analytical security assessments of custom web applications, mid-tier application services, API securi...

BMO
Toronto, Ontario

The Application Security Testing Engineer reports to the Lead of DevSecOps and assists with the security testing activities for BMO based applications. Assists with the execution of highly technical/analytical security assessments of custom web applications, mid-tier application services, API securi...

Scotiabank
Toronto, Ontario

Scotiabank's Information Security & Control (IS&C)'s - Application Security is responsible to improve security practices and, through that, to find and preferably prevent security issues within applications. The Application Security team has global accountability and is highly supportive of the Bank...

Manulife
Toronto, Ontario

Advanced knowledge of security systems, access controls, network security, security platform administration, security incident response, security architecture, risk management and security governance framework. As a Senior CyberArk Security Engineer, you will be the mastermind behind the fortress, d...

S.i. Systems
Toronto, Ontario

Senior Mainframe Modernization Engineer to modernize legacy applications and migrate them to AWS Cloud for a critical transformation project. This indicates the role might involve migrating legacy applications to the cloud, integrating them with cloud-based solutions, or managing hybrid environments...

1Password
Canada
Remote

Minimum of 4 years of combined experience in the IT or security space, related to enterprise security or Detection and Response. Partner with other members of the security organization to establish security guidelines that enable the organization to move fast in a safe and secure manner. Experience ...

Ansys
Toronto, Ontario

Join the Ansys Customer Excellence team to partner with our customers to engineer what's ahead, solve their real-world engineering problems, deploy Ansys software in their design workflows, and grow Ansys’ business. As a hands-on subject matter expert, you will use expert-level engineering knowledge...

Zynga
Toronto, Ontario

In partnership with cybersecurity leadership, the Principal Application Security Engineer will work with product teams, game studios, central technology teams, and cybersecurity to perform proactive and offensive security engineering assessments, identifying vulnerabilities in games, systems, applic...

Ripple
Toronto, Ontario

Infrastructure Security Engineers work on a broad set of efforts focusing on scaling and automating security infrastructure and processes. Ripple is looking for passionate Information Security professionals to build a world class Information Security program. Our Security Engineering team is growing...

Amazon Development Centre Canada ULC
Toronto, Ontario

AWS Security is looking for an Application Security Engineer to help validate that our services, applications, and websites are designed and implemented to the highest security standards. You will be responsible for analyzing the security of applications and services, discovering and addressing secu...