Senior Specialist, Security ; AppSec)
Ottawa, Ontario, Canada
Listed on 2026-09-12
-
IT/Tech
Cybersecurity, Information Security & Data Protection, IT Consultant
Senior Specialist, Security Applications (App Sec)
Job Requisition : 12213
Position Status:Permanent Full Time
Position Type:Hybrid
Travel Requirement:Limited
Language Skill Levels (Read/Write/Speak):CBC
Security Requirement: Secret
Salary:Our salaries generally range from $to $and are based on qualifications and experience.
About CMHC
The work you do and the work we do together matters. We come to work every day with a common purpose: to contribute to a well-functioning housing system.
At CMHC, we hold ourselves accountable for our results and support our colleagues in their achievements. We thrive on collaboration, connecting across CMHC and involving the right people to get our work done. Our leadership style is guided by trust
, where our leaders favour an adaptive approach based on the needs of their teams.
Join us and be part of a team that's committed to making a real difference and be part of something meaningful.
What’s in it for you
We’ve got the purpose, the people and the perks you need for a fulfilling career. Here’s the comprehensive and generous benefits you get when you’re a permanent employee:
- Annual Paid vacation.
- Annual individual performance incentive.
- Comprehensive group insurance plan to support your well-being from day one.
- Support towards your personal and professional growth with training, mentorship and more.
- An inclusive workplace culture and environment.
- While positions at CMHC require some in-office presence, alternative work arrangements may be considered for Indigenous candidates.
Members of the following employment equity deserving groups will be prioritized for this job:
Indigenous Peoples
About the role
Join the Technology and Business Transformation team, in the Bilingual Senior Specialist, Application Security. You'll be responsible for designing, governing, and continuously improving the enterprise Application Security (App Sec) program to ensure that applications and software‑delivered services are designed, built, tested, and operated in alignment with the organization’s risk tolerance, security strategy, and regulatory obligations.
The role provides expert‑level advisory services to senior management, architects, and delivery leadership, and is accountable for the effectiveness and outcomes of application security controls across the full Secure Software Development Lifecycle (SSDLC / SDLC), including controls embedded in Agile and Dev Sec Ops delivery models.
Open to internal employees in a Remote position or with a current Hybrid exception living at more than 125 km from a CMHC office.
What you’ll do:
- Lead and evolve the enterprise Application Security framework, ensuring security requirements are embedded throughout the software development lifecycle and become a core part of how applications are designed, built, tested, and deployed.
- Establish governance for Secure SDLC and Dev Sec Ops practices, integrating security controls, automated testing, secure coding standards, and risk management directly into day-to-day development workflows.
- Drive a secure-by-design and secure-by-default culture by providing standards, patterns, and guidance that enable development teams to proactively build security into applications rather than addressing it after deployment.
- Partner with engineering, platform, and architecture teams to embed application security requirements into Agile delivery models, CI/CD pipelines, development tool chains, cloud-native environments, and third-party integrations.
- Provide expert guidance on secure design decisions, vulnerability remediation, risk-based control selection, and the adoption of emerging technologies while balancing security, business needs, and delivery velocity.
- Define and enforce security assurance activities and quality gates—including…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).