Description:
You are as unique as your background, experience and point of view. Here, you’ll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll have new and exciting opportunities to make life brighter for our clients - who are at the heart of everything we do. Discover how you can make a difference in the lives of individuals, families and communities around the world.
Sun Life seeks a talented individual to fill the role of Senior Application Security Engineer-DevSecOps within Application Operations Services team. The ideal candidate will play a key role in implementing ‘secure by design’ methodology and application security best practices within Sun Life.
This role requires Canadian Enhanced Reliability Security clearance [a minimum of 5 years of consecutive residency in Canada].
What will you do?
- Lead the Application Security program within DevOps and help implement security tooling within CICD pipeline.
- Work with various security champions, developers, and architects across the organization to help them integrate security best practices within their SDLC.
- Create Secure coding guidelines and best practices for various languages technologies
- Conduct Threat modeling exercises and workshops for developers and security champions.
- Create metrics (KPIs and KRIs) on adoption and effectiveness of shift-left initiatives and present to higher management.
- Analyse the vulnerability data from various security tools and recommend fixes to the development teams
- Conduct penetration testing on applications before release and make sure teams are compliant with application security directive.
- Design security solutions and scripts for web/mobile infrastructure to automate repetitive tasks.
- Provide ongoing support of mobile and web application systems in production including responding to service requests, problem analysis, resolution, escalation and reporting as necessary.
What you need to succeed:
- 5 years of experience with tools such as SonarQube, WebInspect, BURP, Jfrog Xray, Sonatype, Chekmarx, CodeDx etc. is a must.
- 2 years experience DevOps processes and tools such as Jenkins, Artifactory, Bitbucket, GIT and CDD etc.
- Development experience in CICD processes, implementing security tools and gating (security gates/checks) within pipeline.
- Good understanding Akamai platform (WAF, Bot Manager etc.) is desired.
- Hands on experience coding practices for web applications (Java and .Net) and Mobile platforms (Android OS, iOS)
- Experience with various threat modelling techniques and be able to identify threats and recommend fixes.
- Experience with secure development and testing of APIs, microservices, containers and Cloud (AWS) is a big plus.
- Strong working knowledge of SPA (single page applications) and client sever model; with hands on experience in Java, J2EE, web services, and .Net technologies.
- Security certifications such as GWAPT, GWEB, CEH, CASE, CSSLP or similar preferred but not required
- Certification or working towards OWASP top 10 and SANS top 25