Senior Application Security Testing Engineer
BMOAbout the role
Application Deadline:
11/29/2024Address:
100 King Street WestJob Family Group:
TechnologyAbout the role:
The Application Security Testing Engineer reports to the Lead of DevSecOps and assists with the security testing activities for BMO based applications. The role will be responsible for the execution and coordination of Static and Dynamic Application Security Testing (SAST/DAST), provides information security consulting services (SAST/DAST Scanning) for BMO overall and businesses/groups. Liaises with developers and other stakeholders to understand problems and opportunities and enables BMO to meet its goals by understanding business vision, objectives and KPIs. Participates in the execution of information security strategy.
What will you do:
- Subject Matter Expertise - Provides technical leadership to business areas as a Security Testing subject matter expert. Assists with efforts on the execution of security testing operations to include pre-engagement (scoping), engagement (testing) and post-engagement activities (reporting).
- Secure Testing - Assists in delivery of security testing projects according to a structured process, to include writing test reports. This may include oversight and/or execution of the configuration and deployment of security testing software and application of results to security analysis.
- Information Security Risk Management - Works with leadership to mature security testing team capabilities including reporting and remediation guidance in alignment with local and global regulatory requirements. Identifies security gaps and deficiencies by conducting risk assessments; able to recommend corrective action of identified vulnerabilities and weaknesses. Assists with the execution of planning, testing, tracking, and advises on necessary risk acceptance for identified security risks.
- Secure Application Development - Assists with the execution of highly technical/analytical security assessments of custom web applications, mid-tier application services, API security testing, backend applications and databases, including manual, custom and industry known attack methods using a risk-based intelligence-led methodology. Identifies potential misuse scenarios. Advises on secure development practices.
What you need to succeed:
- Typically between 5 - 7 years of relevant experience and a post-secondary degree in Computer Science or Information Systems or a related field of study or an equivalent combination of education and experience.
- Knowledge of coding languages (e.g. C#, JAVA, JavaScript, TypeScript, Python etc.) and can code with little oversight
- Knowledge of different rapid development processes, e.g. Waterfall, Agile, etc.
- Knowledge of coding vulnerabilities, frameworks, patching processes, Information Security risk and industry best practices, defense concepts, risk-based assessment approach
- Knowledge of OWASP Top 10, and the OWASP Testing Guide or other secure coding frameworks, NIST Cyber Security Framework (CSF)
- Understands the principles of secure coding techniques and secure code reviews, code scanning software and vulnerability code scanning processes, network protocols and connectivity.
- CISSP, CISSLP, GIAC, OSCP, OSWE, GWAPT, GMOB, GPEN, GXPN, GAWN, etc. Certification is an asset
- Understands the principles of secure coding techniques and secure code reviews
- Familiar with code scanning software and vulnerability code scanning processes.
- Familiar with network protocols and networking infrastructure.
- Familiar with defense concepts.
- Understanding of a risk-based assessment approach
- Familiar with CI/CD Integration of AppSec Testing Tools (SAST, SCA, IAST, etc).
- Familiar with API security
Salary:
$81,600.00 - $151,200.00Pay Type:
SalariedThe above represents BMO Financial Group’s pay range and type.
Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group’s expected target for the first year in this position.
BMO Financial Group’s total compensation package will vary based on the pay type of the position and may include perfo
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s