Application Security Analyst
Vernon, BC, Canada
Listed on 2026-08-16
-
IT/Tech
Cybersecurity, IT Consultant, Information Security & Data Protection
Vernon, BC or Remote
Kal Tire is seeking an Application Security Analyst to join our Cybersecurity team. In this role, you'll help protect our applications, systems, and data by identifying security risks, supporting secure software development practices, and implementing controls that strengthen our overall security posture.
Description Application Security Analyst Vernon, BC or RemoteKal Tire is seeking an Application Security Analyst to join our Cybersecurity team. In this role, you'll help protect our applications, systems, and data by identifying security risks, supporting secure software development practices, and implementing security controls that strengthen our overall security posture.
Working closely with developers, Information Services teams, and business stakeholders, you'll lead security assessments, support vulnerability management, and help ensure that security is embedded throughout the software development lifecycle. You'll also play an important role in securing cloud-based and AI-enabled applications while helping the organization stay ahead of emerging threats.
Responsibilities- Lead application security testing activities, including penetration testing and vulnerability assessments.
- Partner with developers and Information Services teams to remediate vulnerabilities and promote secure coding practices.
- Conduct risk, privacy, and security assessments for new and existing applications and systems.
- Integrate security practices into the Secure Software Development Lifecycle (SSDLC), including threat modeling, architecture reviews, and secure design validation.
- Perform manual code reviews and use automated security testing tools, including SAST, DAST, and IAST.
- Deploy, configure, and optimize application security technologies such as Web Application Firewalls (WAF) and Software Composition Analysis (SCA) solutions.
- Investigate application security incidents, conduct root cause analysis, and implement preventative measures.
- Assess and secure cloud, web, and AI-enabled applications, including LLM integrations.
- Ensure applications align with recognized security standards and frameworks, including OWASP Top 10 and OWASP Top 10 for LLM Applications.
- Participate in incident response activities, tabletop exercises, and security readiness initiatives.
- Support security awareness programs and secure development education across the organization.
- Research emerging threats, vulnerabilities, and security technologies and recommend appropriate solutions.
- 4+ years of hands-on cybersecurity experience, including secure coding practices, web technologies, and application security.
- 3+ years of experience managing penetration testing programs and vulnerability assessments.
- 3+ years of experience using security testing tools and integrating security controls into CI/CD pipelines.
- 4+ years of experience managing cybersecurity solutions in a complex enterprise environment.
- 2+ years of experience with Microsoft security technologies, including Azure Dev Ops, Microsoft Sentinel, Microsoft Defender for Endpoint, and Defender for Cloud.
- 1+ year of experience securing AI-enabled applications, including LLM integrations.
- Proven experience as an Application Security Analyst or in a similar cybersecurity role.
- Strong understanding of application, cloud, web, network, and endpoint security principles.
- Knowledge of cybersecurity frameworks, security controls, and industry best practices.
- Ability to assess risk and communicate technical concepts to both technical and non-technical audiences.
- Strong analytical, problem-solving, and technical documentation skills.
- Experience evaluating security controls and recommending improvements.
- Commitment to continuous learning and staying current with emerging technologies and threats.
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- Relevant certifications such as CISSP, CSSLP, GSEC, CASP+, CEH, or equivalent are considered an asset.
- Valid driver's license.
- Ability to travel occasionally.
- Participation in an on-call rotation.
- Ability to work effectively in a remote work environment.
- Experience with…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: