Location: Montreal
(VERSION EN FRANÇAIS PLUS BAS)
The Role
We're looking for a Web Security Consultant who can help us build secure websites from the ground up.
Security isn't something that should be addressed at the end of a project—it's something that should be considered throughout the entire development lifecycle.
We're looking for someone who can help us establish best practices, identify potential risks before they become problems, and create repeatable standards that every project can follow.
In this role, you'll work closely with our development team to review websites and web applications, ensure they meet current security standards, and build practical processes that improve consistency across every project.
Our web environment is primarily built on Word Press, alongside other modern web technologies. Because of this, strong experience securing Word Press websites, plugins, themes, hosting environments, and deployment workflows is a significant advantage.
Beyond identifying vulnerabilities, you'll help create documentation, checklists, and security guidelines that become part of our standard development workflow.
What You'll Be Doing
Your primary responsibility will be helping the studio build and maintain secure, reliable web solutions.
Responsibilities include:
- Reviewing websites and web applications to ensure they follow current web security best practices.
- Conducting security reviews for Word Press websites and other web applications, identifying platform-specific risks and recommending practical remediation strategies.
- Identifying security vulnerabilities and recommending practical remediation strategies.
- Performing security reviews throughout the development lifecycle rather than only before launch.
- Developing a standardized security checklist that becomes part of every new website project.
- Creating internal documentation and security best practices for developers and project teams.
- Advising developers on secure coding practices and common web application vulnerabilities.
- Helping establish secure deployment, hosting, authentication, and access management standards.
- Recommending security best practices for Word Press core updates, plugin management, user permissions, backups, and hosting configurations.
- Working with project managers and technical teams to ensure security requirements are incorporated into project planning.
- Staying current on evolving security threats, frameworks, and industry standards.
- Supporting periodic security audits and continuous improvements across existing client websites.
What We're Looking For
We're looking for someone who understands that good security is proactive, practical, and scalable. The ideal candidate can evaluate technical implementations, communicate risks clearly, and create processes that make secure development easier for everyone on the team.
You likely have experience with many of the following:
- Web application security principles and secure development practices.
- Familiarity with the OWASP Top 10 and common web application vulnerabilities.
- Security reviews for modern web applications and websites.
- Strong experience securing Word Press websites, including themes, plugins, user roles, hosting environments, and update strategies.
- Authentication, authorization, session management, and access control best practices.
- HTTPS, SSL/TLS, HTTP security headers, and Content Security Policy (CSP).
- Security testing tools and vulnerability assessment methodologies.
- Experience reviewing websites built with modern CMS platforms and JavaScript frameworks.
- Strong documentation skills and experience developing internal standards or technical playbooks.
- Excellent communication skills and the ability to explain technical concepts to both technical and non-technical stakeholders.
What Success Looks Like
Success in this role means:
- Every new website follows a consistent security review process before launch.
- Developers have clear, practical security standards they can apply throughout development.
- Word Press projects follow consistent security standards for deployment, maintenance, and ongoing updates.
- Common vulnerabilities are identified and addressed early in the project lifecycle.
- Internal security…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: