Base Career helps you apply smarter for this job.
Key skills for this role
Lead Loblaw's enterprise Application Security and Vulnerability Management strategy, architecture, engineering, and operations across applications, APIs, cloud workloads, endpoints, servers, containers, and infrastructure.
Own the secure SDLC and DevSecOps control model, integrating SAST, DAST, SCA, API security, secret detection, container scanning, and infrastructure-as-code scanning into GitLab Ultimate and enterprise CI/CD workflows.
Establish risk-based security gates at commit, merge, build, test, and release stages, with clear thresholds, exception governance, developer guidance, and remediation requirements.
Build an application-level DAST and API Security coverage model that maps business applications to repositories, microservices, deployed URLs, environments, API specifications, authentication flows, and accountable owners.
Lead the enterprise vulnerability management lifecycle, including asset discovery, scan coverage, validation, deduplication, risk prioritization, remediation service levels, exceptions, retesting, and verified closure.
Create a unified exposure view that connects vulnerabilities to internet exposure, attack paths, identities, business services, and asset criticality, giving engineering teams and executives clear, actionable risk information.
Own the roadmap and reliable operation of platforms such as GitLab Ultimate, Cortex Cloud / Prisma Cloud, Qualys, API security, attack surface management, and exposure management capabilities.
Establish security patterns for AI-enabled software, generative AI, models, agents, and AI-assisted development; address prompt injection, sensitive-data leakage, insecure tool use, and model or agent supply-chain risk.
Partner with product, development, SRE, cloud, infrastructure, identity, network, data, privacy, SOC, risk, and audit teams to threat model designs, remediate vulnerabilities, respond to events, and provide control evidence.
Lead and develop application security engineers, vulnerability analysts, product owners, and platform specialists; manage budgets, vendors, services, roadmaps, automation, runbooks, succession, and two-deep coverage.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Montréal, CAN
Montréal, CAN
Ottawa, CAN
Vancouver, CAN
, CAN
Vancouver, CAN
Innisfil, CAN
Mississauga, CAN
Montréal, CAN
Proven progressive experience in application security, product security, vulnerability management, cloud security, DevSecOps, or cybersecurity engineering, including leading technical teams or major programs.
Demonstrated success leading application security and vulnerability management in a large, complex enterprise, ideally within retail, healthcare, financial services, telecommunications, or another regulated environment.
Deep expertise in secure SDLC and DevSecOps, including threat modeling, SAST, DAST, SCA, API security, secret detection, container and Kubernetes security, infrastructure-as-code scanning, and CI/CD controls.
Proven experience operating enterprise vulnerability management, including asset and scan governance, finding validation, risk prioritization, remediation SLAs, exceptions, retesting, and executive reporting.
Strong understanding of application and API architectures, microservices, authentication flows, cloud-native services, containers, serverless platforms, and software supply-chain risk across AWS, Azure, GCP, and OCI.
Experience with platforms such as GitLab Ultimate, Qualys, Cortex Cloud / Prisma Cloud, Veracode, Invicti, Snyk, Checkmarx, API security, attack surface management, or exposure management tools.
Experience securing AI/ML, generative AI and agentic applications, AI code assistants, and model or agent supply chains, including prompt injection, data leakage, insecure tool use, and vulnerable dependencies.
Ability to apply CVE, CWE, CVSS, EPSS, known-exploited vulnerability data, threat intelligence, asset criticality, and attack-path context to focus remediation on the risks that matter most.
Excellent executive communication, stakeholder, financial, and vendor leadership skills, with the ability to translate technical exposure into clear decisions and accountable remediation plans.
Bachelor's or Master's degree in Computer Science, Software Engineering, Information Security, Engineering, or a related field. CISSP, CSSLP, CISM, CCSP, GIAC GWEB/GWAPT, OSWE, cloud security, or GitLab credentials are strong assets.
We offer flexibility and balance, and an environment that sets you up for success no matter where your workspace is located. Here, you will find a great team to help you achieve your goals as you help us achieve ours! Work in our fast-paced, exciting Technology environment, helping our stores, colleagues, and customers every day. Loblaw colleagues also enjoy:
Work Perks Program
On-site GoodLife Fitness, Basketball & Volleyball courts, Ice Rink
Groceries delivered to work via PC Express, Dry Cleaning services (1PCC Office)
Tuition Reimbursement & Online Learning
Pension & Benefits
Paid Vacation
Loblaw recognizes Canada's diversity as a source of national pride and strength. We have made it a priority to reflect our nation's evolving diversity in the products we sell, the people we hire, and the culture we create in our organization. At Loblaw, we celebrate diversity and strive to build a culture of inclusion where differences are embraced, valued, and supported. We are committed to being an equal opportunity employer and encourage people from all backgrounds and identities to apply. Accommodation in the recruitment, assessment, and hiring process is available upon request for applicants with disabilities. We thank all candidates for their interest, but please note, only those who meet the minimum requirements will be contacted. www.Loblaw.ca/careers Our commitment to Sustainability and Social Impact is integral to how we do business. Our CORE Values - Care, Ownership, Respect, and Excellence - guide our decisions and come to life through our Blue Culture.
Our commitment to Sustainability and Social Impact is an essential part of the way we do business, and we focus our attention on areas where we can have the greatest impact. Our approach to sustainability and social impact is based on three pillars – Environment, Sourcing and Community – and we are constantly looking for ways to demonstrate leadership in these important areas. Our CORE Values – Care, Ownership, Respect and Excellence – guide all our decision-making and come to life through our Blue Culture. We offer our colleagues progressive careers, comprehensive training, flexibility, and other competitive benefits – these are some of the many reasons why we are one of Canada’s Top Employers, Canada’s Best Diversity Employers, Canada’s Greenest Employers & Canada’s Top Employers for Young People.
If you are unsure whether your experience matches every requirement above, we encourage you to apply anyway. We are looking for varied perspectives which include diverse experiences that we can add to our team. We have a long-standing focus on diversity, equity and inclusion because we know it will make our company a better place to work and shop. We are committed to creating accessible environments for our colleagues, candidates and customers. Requests for accommodation due to a disability (which may be visible or invisible, temporary or permanent) can be made at any stage of application and employment. We encourage candidates to make their accommodation needs known so that we can provide equitable opportunities. Please Note : Candidates who are 18 years or older are required to complete a criminal background check. Details will be provided through the application process.
#EN
Verified company details for this employer are not available yet.
CAD 128000-176000 yearly / year
Full-time
Senior
Onsite
Apply faster on company sites with our extension.