EQ Bank | Equitable Bank Logo

EQ Bank | Equitable Bank

Security Engineer, Vulnerability Management

Sorry, this job was removed at 06:13 a.m. (EST) on Thursday, Oct 10, 2024
Be an Early Applicant
Hybrid
Toronto, ON
Internship
Hybrid
Toronto, ON
Internship

Purpose of the Job


The Security Engineer, Vulnerability Management is responsible for operating and maintaining security testing tools. In addition, the role performs security testing, provides security advisory services, and collaborates with technology and business teams to integrate security tools and processes into new and existing applications and cloud environments. The role's primary objective is to reduce risk of security vulnerability exploitation to the business while delivering a high level of satisfaction to internal customers by utilizing automated remedial tasks to improve operational efficiency.


Main Activities:

•Perform security testing using tools such as DAST, SAST, IAST, Mobile DAST, SCA, RASP, EASM, and CSPM.

•Provide security advisory services to technology and business teams in the realm of application and cloud/infrastructure security.

•Maintain application security and cloud security toolsets and ensure that they are up-to-date and functioning properly.

•Escalate outstanding application and cloud vulnerability mitigation requests as required. 

•Collaborate with development teams to ensure security is integrated into the development lifecycle

•Assist in the development of documentation for application security processes and procedures.

•Stay up-to date on the latest application and cloud security trends and technologies


Knowledge/Skill Requirements:

  •  A college diploma or university degree is required. Higher accreditation (e.g. Bachelor of Computer Science) is preferred. 
  • At least two years of information security experience.
  • Strong understanding of Application Security concepts and best practices.
  • Understanding of Vulnerability Management concepts and best practices.
  • Experience of setting up and running scanning tools for IT Infrastructure and/or Applications Security Testing is required. 
  • Experience of cloud environment is required.
  • Understanding of CI/CD pipeline and approaches to automate security testing is an asset.
  • The following certifications are an asset: CCSP, CCSK, CISM, CISSP, or CRISC. 
  • Understanding and experience with PCI, MITRE ATT&CK, BSIMM, NIST, ISO 27K an asset. 
  • Experience working in a banking or financial services environment is an asset. 
  • Strong analytical and problem-solving skills.
  • Excellent communication and interpersonal skills.

  • Accountability: 

  • Reports directly to the Manager, DevSecOps & Infrastructure Security
  • This position sets priorities for themselves
  • This position is empowered to make decisions that impact their own position, however, there is decision-making involved relating to vulnerability management, which could have a potential impact on the overall reputation of the bank.
  • It is unlikely the decisions made in this position would have a long-term performance impact to the bank.
  • This position requires contact with suppliers, and potentially with other FIs through information sharing circles, like FS-ISAC. The nature of contact with suppliers is to troubleshoot issues with current products; to understand capabilities of new products. The nature of contact with other FIs is sharing information related to the cyber threat landscape and how to industry is adapting.

EQ Bank | Equitable Bank Toronto, Ontario, CAN Office

30 St Clair Avenue West, Suite 700, Toronto, Ontario, Canada, M4V 3A1

Similar Jobs

Be an Early Applicant
5 Days Ago
Toronto, ON, CAN
3,464 Employees
Mid level
3,464 Employees
Mid level
Fintech • Cryptocurrency
As a Vulnerability Management Security Engineer at Robinhood, you will manage the lifecycle of vulnerabilities, enhance the security posture, and facilitate Bug Bounty processes. You'll work on automating remediation, handling technical triage of vulnerabilities, and collaborating with cross-functional teams to ensure robust cybersecurity measures are in place.
Be an Early Applicant
5 Days Ago
Toronto, ON, CAN
53 Employees
Mid level
53 Employees
Mid level
Information Technology
As a Platform Security Engineer, you'll enhance platform security through monitoring security events, threat modeling, and risk assessments while ensuring alignment with the security strategy and compliance. You'll engage in incident management, provide recommendations, and support control engineering efforts. Your role also includes communication with stakeholders and maintaining awareness of security trends and practices.
Be an Early Applicant
7 Hours Ago
Aurora, ON, CAN
Hybrid
171,000 Employees
Mid level
171,000 Employees
Mid level
Automotive • Hardware • Robotics • Software • Transportation • Manufacturing
The Senior Internal Auditor plans and executes financial and compliance audits to ensure adherence to policies and operational standards, performs data analysis to determine audit scopes, identifies internal control gaps, and drafts formal audit reports with findings and recommendations.

What you need to know about the Toronto Tech Scene

Although home to some of the biggest names in tech, including Google, Microsoft and Amazon, Toronto has established itself as one of the largest startup ecosystems in the world. And with over 2,000 startups — more than 30 percent of the country's total startups — Toronto continues to attract new businesses. Be it helping entrepreneurs manage their finances, simplifying business operations by automating payroll or assisting pharmaceutical companies in launching new drugs, the city's tech scene is just getting started.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account