Application Security Specialist.
Ville Saint-Laurent, Quebec, CA
EXFO develops smarter network test, monitoring, and analytics solutions for the world’s leading telecommunications service providers, network equipment manufacturers, and web-scale companies—and we love what we do!
With nearly 1,900 employees in more than 25 countries, EXFO is the world’s number one provider of fiber optic test solutions and has the largest active assurance deployment. Our broad portfolio of intelligent hardware and software solutions enables our customers’ network transformations related to fiber, 5G, virtualization, and big data analytics.
We are always looking for top talent to help us lead the way in a thriving industry with unlimited opportunities.
Job Summary
With more than 20% of our revenue invested in R&D, EXFO is recognized for its team of experts who create numerous new products to meet the current and future needs of the world’s largest telecommunications network operators. By joining EXFO as an Application Security Specialist, you will work with sophisticated technologies in a dynamic and innovative environment.
The ideal candidate has experience in both application development and information security. The selected individual will work closely with IT security specialists to exchange ideas, collaborate on best practices, and coordinate approaches to address common vulnerabilities and more.
Your Role
-
Evolve, drive, and execute the strategy to ensure application security at EXFO.
-
Perform risk and vulnerability assessments at the system and application levels.
-
Define effective risk mitigation measures while contributing to security awareness programs.
-
Develop and implement application security controls.
-
Provide security expertise, including during product design phases.
-
Meet with application and product teams to discuss vulnerability remediation.
-
Deliver timely and detailed reports, including evidence of findings, risk analysis, recommendations, and remediation guidance.
Technical Skills
-
General understanding of security and data protection regulations and best practices, and their impact on application design.
-
Knowledge of application security testing methods and tools.
-
Knowledge of OWASP, SSDLC, and DevSecOps.
-
Knowledge of security controls and measures in a cloud-native environment (K8s, Docker, AWS, Azure).
-
Knowledge of cryptography (PKI, digital signatures, SSL/TLS).
-
Actively engaged with the broader security community, keeping up with the latest threats, trends, and technologies.
-
Knowledge of hacker attack methods.
-
Software development experience considered an asset.
-
Infrastructure security knowledge considered an asset.
-
Security certifications such as (ISC)² CSSLP or CEH considered an asset.
-
Knowledge of telecommunications technologies/industry considered an asset.
Required Skills
-
Proven leadership experience in security roles.
-
Ability to communicate complex topics clearly and concisely to various audience levels within the organization.
-
Ability to deliver training (e.g., secure coding, security best practices, or compliance with security requirements).
-
Ability to operate effectively in a complex matrix environment.
-
Ability to build trust.
-
Passion and curiosity.
-
Self-starter.
-
Ability to engage and develop team members.
Requirements
-
8+ years of experience in software security.
-
Bilingual (French and English).
-
Bachelor’s degree in Computer Science or a related field.
Any equivalent combination of education and relevant experience will be considered.