Sr. Application Security Specialist (GCS)

RBC - Royal Bank
Vancouver, BC
$45-$65 an hour (estimated)
Full-time

Job Summary

Job Description

WHAT IS THE OPPORTUNITY?

Reporting to the Senior Manager of Application Security Transformation - you would provide technical execution in Application Security for the global RBC business and application development teams across all enterprise information technology groups.

You will be participating in the development of application security best practices, tools, and processes. You will also help execute various application security projects across all RBC lines of business.

This role will also require you to have solid understanding of CI / CD pipelines, DevSecOps and various application security testing techniques such as SCA, OSA, SAST, DAST and IAST.

WHAT WILL YOU DO?

Develop automation & integration capabilities for tools onboarding and security controls enforcement by partnering with Enterprise DevOps team.

Support end users & Review Dynamic application security testing reports to validate findings / false positives and assist developers in the remediation.

Develop metrics to measure Security and Risk posture of RBC applications.

Educate key organizational stakeholders (e.g. developers, security consultants, executives) on application security matters across the organization.

Assist in the development, evaluation, and implementation of application security controls and processes.

Ensure applications are thoroughly tested for security vulnerabilities using industry best practices prior to production release.

Research and keep up to date on application security emerging threats, techniques, tools, and trends.

Work in a diverse environment leveraging other team members' experience and knowledge.

WHAT DO YOU NEED TO SUCCEED?

Must have :

Experience developing and testing apps in any of programming languages : Python, Java (preferred).

Knowledge of Secure Software Development practices, SCA / OSA, SAST, DAST, IAST methods & tools.

Understanding of CI / CD and DevSecOps approaches and experience working with DevSecOps tools.

Solid understanding of security-related frameworks and OWASP Top 10 (Web & API).

Strong written / verbal communications skills and ability to manage client / stakeholder relations.

Nice-to-have :

Understanding of GitHub Actions based pipeline & GitHub Advanced Security tools.

Prior experience of leading Enterprise level Application Security Controls & enforcement.

RBC is committed to supporting flexible work arrangements when and where available. Details to be discussed with Hiring Manager.

What's in it for you?

We thrive on the challenge to be our best, progressive thinking to keep growing, and working together to deliver trusted advice to help our clients thrive and communities prosper.

We care about each other, reaching our potential, making a difference to our communities, and achieving success that is mutual.

A comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable

Leaders who support your development through coaching and managing opportunities

Ability to make a difference and lasting impact

Work in a dynamic, collaborative, progressive, and high-performing team

A world-class training program in financial services

Flexible work / life balance options

Opportunities to do challenging work

LI-Hybrid

LI-POST

TECHPJ

Job Skills

Application Programming Interface (API) Security, Application Security, Curiosity, DevOps, DevSecOps, GitHub Actions, GitHub Advanced Security, Java, Leadership, Mentorship, Open Web Application Security Project (OWASP), OWASP Top 10, Prioritization, Python (Programming Language), Secure Coding Practices, Technology Leadership

30+ days ago
Related jobs
RBC - Royal Bank
Vancouver, British Columbia

Application Programming Interface (API) Security, Application Security, Curiosity, DevOps, DevSecOps, GitHub Actions, GitHub Advanced Security, Java, Leadership, Mentorship, Open Web Application Security Project (OWASP), OWASP Top 10, Prioritization, Python (Programming Language), Secure Coding Prac...

Royal Bank of Canada>
Vancouver, British Columbia

API Gateway, API Specifications, API Testing, Application Programming Interface (API) Security, Atlassian JIRA, CloudBees Jenkins, DevSecOps, Dynamic Application Security Testing (DAST), GitHub Actions, GitHub Issues, IT Security Architecture, IT Systems Integration, Kubernetes, OAuth, OWASP Top 10,...

0000050007 Royal Bank of Canada
Vancouver, British Columbia

Decision Making, Group Problem Solving, Identity Access Management (IAM), Information Security, Information Technology Security, IT Systems Integration, Negotiation, Security Controls, Security Information, Security Information and Event Management (SIEM), SIEM Tools, Software Development, Software ...

Royal Bank of Canada>
Vancouver, British Columbia

Decision Making, Group Problem Solving, Identity Access Management (IAM), Information Security, Information Technology Security, IT Systems Integration, Negotiation, Security Controls, Security Information, Security Information and Event Management (SIEM), SIEM Tools, Software Development, Software ...

RBC - Royal Bank
Vancouver, British Columbia

Decision Making, Group Problem Solving, Identity Access Management (IAM), Information Security, Information Technology Security, IT Systems Integration, Negotiation, Security Controls, Security Information, Security Information and Event Management (SIEM), SIEM Tools, Software Development, Software ...

S.i. Systems
Vancouver, British Columbia

Sr Data Architect to develop and implement data governance policies and frameworks to ensure data quality, security, and compliance for B2B applications (ServiceNow, NetCracker, Salesforce, Amdocs, BMC Remedy) for our large telecom client -. Develop and implement data governance policies and framewo...

Promoted
Paladin Security
Burnaby, British Columbia

As our IT Security Analyst, you will be responsible for protecting our systems and data from potential security breaches. Paladin Security is committed to ensuring the highest standards of security for our digital assets and infrastructure. You will analyze security risks, implement security measure...

Promoted
Swim Recruiting
Vancouver, British Columbia

Permanent Information Security Analyst role with an award winning industry leader with a focus on collaboration and internal development. Permanent Information Security Analyst role  . As a result of investment in technology, our client is looking to add an Information Security Analyst to their...

ED Tech Solutions Inc. Surrey
Surrey, British Columbia

Assess physical and technical security risks to data, software and hardware. Develop policies, procedures and contingency plans to minimize the effects of security breaches. ...

Fortinet
Burnaby, British Columbia

The Fortinet Team is looking for an Information Security Analyst to join the Information Security team for Burnaby site. It is a highly technical role assisting the Information Security leadership with daily information security operation activities, both on an organizational and technical level. Ov...