Application Security Analyst

BMO
Canada, Canada
65.4K $-121.8K $ / an
Temps partiel

Application Deadline :

12 / 30 / 2024

Address : 100 King Street West

100 King Street West

Job Family Group : Technology

Technology

The role is Hybrid (1-2 days in the office)

About the role :

The Application Security Analyst reports to the Lead of DevSecOps and assists with the security testing activities for BMO based applications.

The role will be responsible for the execution and coordination of Application Security Testing, provides information security consulting services (SAST / DAST Scanning) for BMO overall and businesses / groups.

Liaises with developers and other stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs.

Participates in the execution of information security strategy.

What will you do :

Subject Matter Expertise - Provides technical leadership to business areas as a Security Testing subject matter expert.

Assists with efforts on the execution of security testing operations to include pre-engagement (scoping), engagement (testing) and post-engagement activities (reporting).

Secure Testing - Assists in delivery of security testing projects according to a structured process, to include writing test reports.

This may include oversight and / or execution of the configuration and deployment of security testing software and application of results to security analysis.

Information Security Risk Management - Works with leadership to mature security testing team capabilities including reporting and remediation guidance in alignment with local and global regulatory requirements.

Identifies security gaps and deficiencies by conducting risk assessments; able to recommend corrective action of identified vulnerabilities and weaknesses.

Assists with the execution of planning, testing, tracking, and advises on necessary risk acceptance for identified security risks.

Secure Application Development - Assists with the execution of highly technical / analytical security assessments of custom web applications, mid-tier application services, API security testing, backend applications and databases, including manual, custom and industry known attack methods using a risk-based intelligence-led methodology.

Identifies potential misuse scenarios. Advises on secure development practices.

What you need to succeed :

  • Typically between 2-4 years of relevant experience and a post-secondary degree in Computer Science or Information Systems or a related field of study or an equivalent combination of education and experience.
  • Knowledge of coding languages (e.g. C#, JAVA, JavaScript, TypeScript, Python etc.) and can code with little oversight
  • Familiar with API security and experience with API testing
  • Knowledge of different rapid development processes, e.g. Waterfall, Agile, etc.
  • Knowledge of coding vulnerabilities, frameworks, patching processes, Information Security risk and industry best practices, defense concepts, risk-based assessment approach
  • Knowledge of OWASP Top 10, and the OWASP Testing Guide or other secure coding frameworks, NIST Cyber Security Framework (CSF)
  • Understands the principles of secure coding techniques and secure code reviews, code scanning software and vulnerability code scanning processes, network protocols and connectivity.
  • CISSP, CISSLP, GIAC, OSCP, OSWE, GWAPT, GMOB, GPEN, GXPN, GAWN, etc. Certification is an asset
  • Understands the principles of secure coding techniques and secure code reviews
  • Familiar with code scanning software and vulnerability code scanning processes.
  • Familiar with network protocols and networking infrastructure.
  • Familiar with defense concepts.
  • Understanding of a risk-based assessment approach
  • Familiar with CI / CD Integration of AppSec Testing Tools (SAST, SCA, IAST, etc).

Salary :

$65,400.00 - $121,800.00

Pay Type : Salaried

Salaried

The above represents BMO Financial Group's pay range and type.

Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure.

Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group's expected target for the first year in this position.

BMO Financial Group's total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards.

BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit : : / / jobs.

bmo.com / global / en / Total-Rewards

We're here to help

At BMO we are driven by a shared Purpose : Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people.

By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.

As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one - for yourself and our customers.

We'll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs.

From in-depth training and coaching, to manager support and network-building opportunities, we'll help you gain valuable experience, and broaden your skillset.

To find out more visit us at : / / jobs.bmo.com / ca / en .

BMO is committed to an inclusive, equitable and accessible workplace. By learning from each other's differences, we gain strength through our people and our perspectives.

Accommodations are available on request for candidates taking part in all aspects of the selection process. To request accommodation, please contact your recruiter.

Note to Recruiters : BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property.

BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.

Il y a 1 jour
Emplois reliés
BMO
Canada, Canada

The Application Security Analyst reports to the Lead of DevSecOps and assists with the security testing activities for BMO based applications. Assists with the execution of highly technical/analytical security assessments of custom web applications, mid-tier application services, API security testin...

Behavox
Canada -
Télétravail

As part of the Behavox Cyber Security team the Security Incident Response Analyst will monitor, detect, analyze, and mitigate cyber security incidents. Improve and optimization of SIEM security events working on a team dedicated to extraordinary Cyber Security standards. Experience working with Secu...

Coinbase
Canada
Télétravail

We are looking for a Senior Analyst for International Security within NAMER. Your role includes supporting the build out and execution of International Security first line activities to support ongoing business demands and continued expansion across AMER while collaborating with teams across the com...

Sophos
Canada

Build strong relationships with internal business peers and develop/maintain an understanding of the business process areas under our responsibility that is equal to or exceeding those of our colleagues operating the business. Model current and future state business processes and ask questions neede...

data.ai
Canada
Télétravail

We are looking for an outstanding Junior Data Analyst interested in working in the hot space of app store data and analytics to join our phenomenal Data Science team at data. I work closely with Product Managers to help understand the efficacy of released product features and collaborate with Data A...

Charter
Anywhere - Canada

Cloud & Data Center Systems Support Analyst (Intermediate). Cloud & Data Center Systems Support Analyst. The Cloud & Data Center Systems Support Analyst is responsible for daily operations, proactive management, technology recommendations, implementing best practices and managing incidents/requests ...

Jobber
Canada
Télétravail

Our Security Analyst, GRC, focuses on the governance side of security and is not a technical security operations position requiring specific technical certifications or experience. This opportunity fits those earlier in their security career, new graduates with internship experience, or those lookin...

ClickUp
Canada

We are looking for driven and innovative software engineers with strong site reliability engineering (SRE) discipline or interest in this area to help us make ClickUp the "one app to rule them all". If you are a rockstar engineer with an entrepreneurial and high-paced mindset who are ready to own, d...

VDart Inc
Canada

Role: Network security engineer</b></p> <p><b>Location: Halifax, CA (Remote)</b></p> <p><b>Type: Contract</b></p> <p><b>The day-to-day is:</b></p> <ul> <li>Analyze business requirements and provide recomm...

Oracle
Canada

As a member of the Support organization, your focus is to deliver post-sales support and solutions to the Oracle customer base while serving as an advocate for customer needs. The candidate is expected to provide assistance with both Technical Support issues and product-usage best practices. Signifi...