Application Security Analyst II
Montréal, Quebec
Established in 2004, we are a tech pioneer offering world-class adult entertainment and games on some of the internet’s safest and most popular platforms. With the support of an international team of dynamic and collaborative innovators, we are on a mission to enable safe user experiences and empower our communities by celebrating diversity, inclusion, and expression — all while maintaining robust trust-and-safety protocols.
We embrace the best of both worlds! Local talent can thrive in our collaborative office space with the flexibility of a hybrid work environment, while remote team members play an integral role in shaping our dynamic culture from afar. We have offices in Montreal (Quebec), Austin (Texas) and Nicosia (Cyprus).
*A select number of positions require full-time in office attendance*
As an Application Security Analyst II, you will play a critical role in strengthening the organization's security posture and safeguarding data and applications from security threats. You will work closely with Engineering, Product, and DevOps teams to implement the Secure Software Development Lifecycle (SSDLC), establish security best practices, and ensure the continuity of business operations.
What you’ll be doing:
- Validate internal, external, and crowd-sourced application security findings, and clearly communicate them to engineering teams.
- Collaborate with developers to share knowledge and implement security best practices.
- Create and utilize code- and tool-based solutions to address application security issues.
- Identify and assess gaps in the organization’s security posture, particularly from an application security perspective.
- Participate in and act as a subject matter expert for core operations such as vulnerability management and cryptographic operations (e.g., Bug Bounty programs).
- Create and maintain comprehensive documentation, standards, and policies related to tooling, processes, and procedures.
- Propose and assist in the implementation of projects, tools, and technologies that benefit Engineering and the Application Security (AppSec) team.
- Promote awareness and integration of the SSDLC across engineering teams.
- Support junior analysts with task execution and technical troubleshooting.
- Conduct threat modeling and threat hunting assessments.
- Provide guidance on best practices and remediation strategies for GCP/AWS cloud configurations (Terraform & Kubernetes).
- Perform regular audits of features and full applications across Web, API, Mobile, Cloud, and Thick Client infrastructures.
- Stay current on the latest trends, vulnerabilities, and threats in the information security landscape, as well as compliance frameworks such as PCI-DSS and NIST.
What you’ll need to successful:
Must haves:
- A minimum of 3 years of experience in a similar application security role.
- A university or college degree in Information Security, Computer Science, or a related field.
- Proficiency in programming languages such as PHP, Java, Python, or Go.
- eLearnSecurity Junior Penetration Tester (eJPT) certification.
Nice to haves:
- Offensive Security Certified Professional (OSCP).
- Offensive Security Web Expert (OSWE).
- An active Bug Bounty profile.
- eLearnSecurity Junior Penetration Tester (eJPT) certification or similar certification.
- Experience developing open-source offensive security tools.
- Familiarity with tools such as SonarQube, GitLab Pipelines, SBOMs, and Burp Suite.
As an equal opportunity employer, we celebrate diversity and are committed to creating an inclusive environment for all employees
In this role you may be exposed to adult content
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: APIs Application security Audits AWS Burp Suite Cloud Compliance Computer Science DevOps GCP GitLab Java Kubernetes NIST Offensive security OSCP OSWE PHP Python SDLC SonarQube SSDLC Terraform Vulnerabilities Vulnerability management
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.