Senior Application Security Analyst

Brak informacji o wynagrodzeniu
SeniorFull-time·B2B
#427145·Dodano wczoraj·0
Źródło: justjoin.it
Aplikuj teraz

Tech Stack / Keywords

SecurityBash

Firma i stanowisko

Svitla Systems Inc. is hiring for a Senior Application Security Analyst for a Canadian courier and package delivery company. The company delivers nearly 500,000 parcels daily across Canada with a technological platform managing over 3500 optimized routes and nearly 500 independent delivery employees. Its services include a digital order tracking platform used by suppliers and logistics service dealers and clients such as Amazon, Pitney Bowes, and Landmark Global.

Wymagania

  • Degree in computer science or equivalent experience with 5 to 10+ years in the field.
  • Required security certification(s): CISSP, CSSLP, CEH, OSCP, GIAC, or equivalent.
  • Cloud or vendor-specific security certification(s) or equivalent experience.
  • Hands-on experience implementing and supporting CI/CD pipelines, secret management, image management, service mesh, WAF, cloud firewall and rule management, Kubernetes, container security, API gateway, cloud workload protection and posture, IaC, compliance as code, and GitOps.
  • Hands-on experience with security testing, secure coding, training, and secure product design.
  • Hands-on experience with security automation and incident response.
  • Strong understanding of APIs, web services, and modern software architecture.
  • Knowledge of scripting languages including Python, Bash.
  • Knowledge of at least one or two development languages: Java, Node.js, C#, .NET.
  • Strong understanding of secure design and threat modeling methodologies.
  • Knowledge of information security risks, frameworks, regulatory requirements, and industry best practices.
  • Familiarity with network protocols and cloud networking; good understanding of network threat landscape.
  • Expert problem-solving skills and advanced interpersonal and communication skills.
  • Autonomous with strong time management skills.
  • Broad knowledge of application security and cloud security.

Obowiązki

  • Bring broad expertise in information and application security to identify threats, recommend controls, and support business goals.
  • Define, implement, and continuously improve security controls and baseline configurations.
  • Assess control effectiveness across CI/CD pipelines and application platforms including desktop, web, mobile, containers, and COTS.
  • Own and evolve application and cloud security services including tool selection, onboarding, configuration, operations, and testing.
  • Serve as the go-to advisor for application security across architecture, engineering, and secure coding practices.
  • Drive security automation and establish repeatable guardrails throughout the SDLC.
  • Lead threat modeling and secure design activities for key initiatives.
  • Partner with engineering, product, platform, architecture, and business teams to design and implement appropriate security features.
  • Act as a subject matter expert for application and cloud security topics.
  • Make decisions on complex issues aligned with best practices in application and cloud security.
  • Deliver outcomes autonomously using creative and practical approaches.
  • Create training materials, guidelines, secure patterns, and documentation.
  • Coordinate and host training sessions, knowledge-sharing forums, and AppSec/CloudSec communities of practice.
  • Mentor and enable stakeholders on web, mobile, API, and cloud security to improve posture and address technical debt.
  • Advise developer squads on vulnerabilities, secure design, and application security best practices.
  • Educate teams on application and cloud risks, secure configuration, secure coding, and core security concepts.

Benefity

  • US and EU projects based on advanced technologies.
  • Competitive compensation based on skills and experience.
  • Regular performance appraisals to support growth.
  • Flexible workspace options: remote or office.
  • Bonuses for article writing, public speaking, and other activities.
  • Generous time off including vacation, national holidays, sick leaves, and family days.
  • Personalized learning programs.
  • Free tech webinars and meetups organized by Svitla.
  • Regular corporate online activities.
Elastyczne godziny
Premie
Płatny urlop

Inne informacje

Informujemy, że administratorem Twoich danych osobowych jest SVITLA EUROPE SPÓŁKA Z O.O. z siedzibą w (31-323) Krakowie przy ul. Opolskiej 110 (dalej „SVITLA”). Możesz skontaktować się z nami listownie (na adres podany powyżej) lub poprzez e-mail: [email protected]. Informujemy również, że w SVITLA został wyznaczony Inspektor Ochrony Danych. Informacje na temat przetwarzania danych osobowych w spółce można uzyskać pod adresem e-mail: [email protected].

Zebrane przez nas dane osobowe będą przetwarzane w celu rekrutacji na stanowisko wskazane w ogłoszeniu o pracę lub w celu pośredniczenia przez SVITLA w nawiązaniu relacji biznesowych ze spółkami z nią powiązanymi lub jej zweryfikowanymi kontrahentami.

Zamierzamy przetwarzać Twoje dane osobowe przez czas trwania rekrutacji i naszej współpracy (dłuższy okres retencji danych osobowych może wynikać z przedawnienia roszczeń lub obowiązków nałożonych na nas przepisami prawa, np. w zakresie przechowywania dokumentów księgowych).

Może się zdarzyć, że Twoje dane osobowe będą przetwarzane transgranicznie przez grupę naszych przedsiębiorców lub zweryfikowanych kontrahentów. Zapewniamy odpowiednie bezpieczeństwo Twoich danych osobowych, stosując obowiązujące reguły korporacyjne, a także tzw. standardowe klauzule umowne dotyczące ochrony danych.

Na mocy RODO przysługują Ci określone prawa w związku z przetwarzaniem Twoich danych osobowych:

masz prawo do uzyskania informacji o tym, jakie dane osobowe dotyczące Ciebie są przez nas przetwarzane oraz do otrzymania ich kopii (prawo dostępu);

jeżeli przetwarzane dane staną się nieaktualne, niekompletne lub niedokładne, masz prawo do ich sprostowania;

możesz żądać od nas usunięcia Twoich danych osobowych, przy czym w takim przypadku nie będzie możliwe zawarcie umowy ze spółkami z grupy SVITLA lub z jej kontrahentami;

możesz w każdej chwili wycofać zgodę na przetwarzanie danych i zażądać ich usunięcia (chyba że przetwarzanie odbywa się na innej podstawie prawnej);

masz prawo wniesienia skargi do Prezesa Urzędu Ochrony Danych Osobowych, jeżeli uznasz, że przetwarzanie Twoich danych osobowych narusza RODO;

nie ma prawnego obowiązku udostępniania nam swoich danych osobowych, jednak bez tego nie jest możliwe zawarcie umowy.

Svitla Systems

Svitla Systems

14 aktywnych ofert

Zobacz wszystkie oferty
Aplikuj teraz