• Skip to primary navigation
  • Skip to main content
  • Skip to footer
  • Adresse mail
  • Facebook
  • Instagram
  • Linkedin
  • Twitter

1.844.822.0541

info@nexusgroup.ca

  • Français
    • English
  • Login consultant
  • Offres d’emploi
Nexus Systems Group

Nexus Systems Group

  • Accueil
  • Ce que nous faisons
    • Les solutions de dotation rendues faciles
    • Gestion de la main-d’œuvre occasionnelle et solutions de paie
    • Services-conseils en technologie et prestation
  • Qui nous servons
  • Qui nous sommes
    • Notre équipe
    • Nouvelles et prix
    • Associations et communauté
  • Nous contacter
  • Blogue

IT Security Analyst

mai 23, 2025 by

Typical Day in Role:
• Ensure production code releases are delivered with no Critical or High vulnerabilities
Support the Senior Manager, Director, VP, SVP and CISO in achieving IS&C Strategic goals through various processes, including:
• Develop and/or enhance strategies and processes to manage web application security vulnerabilities and threats for both transactional and marketing/informational web sites.
• Develop and/or enhance communication model to manage web application vulnerability remediation with the development and infrastructure support teams in support of risk management practices on behalf of the business owner.
• Develop and/or enhance reporting to development teams and all levels of management to provide proper tracking and measurement of remediation relative to established objectives
• Recommend, design, assess, implement, deploy and maintain application security controls required to protect the bank and its customers.
• Responsible for developing and/or enhancing the strategies and processes to identify, analyze, and communicate application vulnerabilities as per the CISO Directive and published communication process flows.
• Responsible for adherence to an established process flow that ensures development support teams, infrastructure support teams, and business risk owners implement control measures that effectively mitigate or eliminate the identified risk.
• Responsible for timely and accurate reporting of all findings to the development teams, appropriate levels of management and the business risk owner

Candidate Requirements/Must Have Skills:
1) 10+ years of experience as an IT Security Analyst
2) Experience that demonstrates a comprehensive understanding of multi-tier Web Applications, web APIs, related vulnerabilities and potentials threats, current information released by organizations such as OWASP (Open Web Application Security Project) and CVE (Common Vulnerabilities and Exposures)
3) Experience that demonstrates a comprehensive understanding of the HTTP protocol, Secure Software Development Lifecycle (SDLC) and Web Programing for multi-tier web applications and web services.
– For example, experience with some of these: JavaScript, SQL, HTML, XML, ASP.net, VB.net, Java, PHP, Python, PowerShell, or Ruby, is essential.
4 Demonstrated experience working with the OWASP Application Security Verification Standard (ASVS).
5) Experience performing source code and/or application security assessments, including risk assessments and penetration testing, with vulnerability testing and scanning tools, with at least one of these: Checkmarx, BurpSuite, Acunetix, NetSparker, WebInspect, AppScan, SQLMap, ZAP, and Fortify.

Nice-To-Have Skills:
1) Prior Financial Institutional Experience
2) Experience with gateway technologies and network devices such as Load Balancers, Proxies, IPS, WAF, API Gateway.
3) Experience generating reports and tailoring communication strategies for various levels of technical staff, executive management, and business clients.

Soft Skills Required:
– Excellent written and oral communication skills. Ideas must be able to be understood and shared easily.
– Strong organizational skills

Education:
University degree or college diploma in technical field such as computer science
CISSP and/or CISA designation beneficial but not required.
CEH, OSCP, OSWE designation beneficial but not required.

 

  • Appliquer maintenant
  • Voir tous les emplois

Footer

À PROPOS DE SYSTEMS NEXUS GROUP

Nexus est l’un des chefs de file nord-américains dans la prestation d’augmentation du personnel technologique et de consultation en ressources stratégiques. Grâce à son équipe de professionnels chevronnés qui utilise les meilleures méthodologies de leur catégorie, Nexus tient toujours plus que ses promesses, en livrant des résultats rapides, de qualité et dignes de foi à ses clients et consultants.

DERNIÈRES OPPORTUNITÉS

  • QA Test Analyst mai 27, 2025
  • Junior Analyst mai 23, 2025
  • Marketing Consultant mai 23, 2025
  • IT Security Analyst mai 23, 2025

SOCIAL

  • Adresse mail
  • Facebook
  • Instagram
  • Linkedin
  • Twitter
Report on Business Canada's Top Growing Companies - Nexus Group
Nexus Group Growth 500 2019
Nexus Systems Group Growth 500 2018
NEXUS GROUP SYSTEMS GROUP INC. NEXUSGROUP.CA
  • Nous contacter
  • Politique de confidentialité
  • Termes et conditions