Manulife

Manulife

Senior Application Security Specialist

Toronto, Ontario · Senior

Sponsorship not specifiedDetected 15 days ago
GitAWSAzureCI/CDDevOpsData AnalysisData VisualizationCybersecurityPenetration TestingSOC OperationsComplianceJiraConfluenceCommunicationCollaborationInternal AuditBurp SuiteCISSP

About the role

  • Help shape the future you want to see - and discover that better can take you anywhere you want to go.
  • The successful candidate will play a critical role in establishing and maintaining our security and risk governance frameworks.

Responsibilities

  • Perform code scanning, validation, tuning, and optimization using SAST, DAST, and SCA tools (e.g., Snyk, Burp Suite, SonarQube, Veracode, and Checkmarx) to ensure accurate, prioritized, and actionable remediation results.
  • Supports establishment, development, and maintenance of risk governance frameworks, risk assessment methodologies, risk metrics reporting, and risk management compliance protocols.
  • Document findings and collaborate with cross-functional teams to implement corrective actions.
  • Work closely with senior security engineers, product partners, architects, and cross‑functional teams in Agile/DevOps environments.
  • Lead and participate in meetings to review outstanding vulnerabilities and clarify business and technical impacts.
  • Develop and report actionable KPIs and KRIs aligned with application security policies and standards.
  • Lead meetings to analyze risk indicators and develop executive-level dashboards.
  • Maintain comprehensive documentation of governance processes and contribute to policy updates.
  • Provide professional advice and take a lead role in process or program execution.
  • Be accountable for own work and contribute to setting standards through expertise in own job discipline that impacts other deliverables.

Requirements

  • Strong understanding of information security controls, vulnerability management, and risk management frameworks (NIST CSF, ISO 27001/27002).
  • Experience working with Cloud technologies (Azure, AWS, Ali Cloud)
  • Knowledge of cybersecurity principles, internal controls, and risk management tools.
  • Proficiency in data visualization tools (Tableau, Power BI) and statistical data analysis.
  • Hands‑on experience with tools such as JIRA, Confluence, and Microsoft 365.
  • Experience with cybersecurity assessment frameworks (PTES, OWASP, OSSTM) and penetration testing.
  • Knowledge of ticketing and tracking tools such as ServiceNow - Security Operations, GRC systems like Archer.
  • Knowledge of statistical data analysis and reporting toolsets
  • In-depth knowledge of risk assessment methodologies and risk management frameworks.
  • Proficiency in using risk assessment tools and software.

Nice to have

  • CISSP, CSSLP, OSCP, GWAPT or equivalent industry-recognized security certifications.
  • Cybersecurity, Security Monitoring
  • Vulnerability Assessment, Penetration Testing
  • Threat Modeling, Security Assessment, Security Testing
  • Cyber Threat Intelligence
  • When You Join Our Team
  • We'll empower you to learn and grow the career you want.
  • The role being advertised is an existing vacancy.

Compensation

  • We are committed to fair recruitment, retention, advancement and compensation, and we administer all of our practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, r

Visa & Work Authorization

  • r practices and programs without discrimination on the basis of race, ancestry, place of origin, colour, ethnic origin, citizenship, religion or religious beliefs, creed, sex (including pregnancy and pregnancy-related co

This listing is sourced directly from Manulife's careers page and normalized into a canonical job model.