Lead Information Security Engineer
St Johns-Verafin Way, Canada
Nasdaq
Get the latest stock market news, stock information & quotes, data analysis reports, as well as a general overview of the market landscape from Nasdaq.- Serves as Information Security primary point of contact for a Google cloud-based technology project
- Designs, develops, implements, and solves problems with various information systems security software ensuring resolution.
- Tests, and validates solutions to remediate exploitable conditions on applications.
- Evaluates software fixes (patches) to address sophisticated system vulnerabilities such as malicious code (e.g., viruses), system exploitation using SQL injection, cross-site scripting, buffer overflows, parameter tampering, hidden field manipulation, cookie poisoning, and Web services manipulation.
- Conducts security assessments of complex systems, networks and applications using penetration tests and ethical hacking tools and risk assessment/mediation methodologies to evaluate vulnerabilities. Prepares status reports on security matters to develop security risk analysis scenarios and response procedures.
- Reviews security designs for complex environments.
- Displays technical knowledge and expertise, in addition to a thorough understanding of the industry, when examining security issues, techniques and implications across multiple computing platforms and of varying complexity.
- Supports regulatory compliance initiatives related to the industry regulation
- Works with teams across the organizations involved in the project to deliver information security related tasks
- Education Required: Degree qualified in Computers Science, Information Systems or other related discipline, or equivalent work experience.
- Experience Required: At least 10 years
- Special Qualifications: Has completed one or more of the following Certifications and/or Professionalization status: MCSE certification; GIAC, GSEC, GCFW, GCIA, GCIH, GISO, GSNA, GCFA, GSLC; GPEN, CISA, CISSP, CCSP certifications.
- Experience with application security tools in areas of DAST, SAST, Web Application Penetration Testing.
Come as You Are
Nasdaq is an equal opportunity employer. We positively encourage applications from suitably qualified and eligible candidates regardless of age, color, disability, national origin, ancestry, race, religion, gender, sexual orientation, gender identity and/or expression, veteran status, genetic information, or any other status protected by applicable law.
We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request an accommodation.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: Application security CCSP CISA CISSP Cloud Compliance DAST Ethical hacking GCFA GCFW GCIA GCIH GCP GIAC GISO GPEN GSEC GSLC GSNA Pentesting Red team Risk analysis Risk assessment SAST Scripting Security assessment SQL SQL injection Vulnerabilities XSS
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.