Base Career helps you apply smarter for this job.
Key skills for this role
Lead security risk assessments for applications, infrastructure, cloud, network, and enterprise technology initiatives using ISO 27001, NIST, PCI DSS, SOC 2, and internal security standards to identify, assess, document, and communicate security risks and remediation strategies.
Conduct security architecture and design reviews to ensure solutions align with organizational security standards, regulatory requirements, and industry best practices.
Perform threat modelling, vulnerability analysis, and impact assessments to identify risks and recommend appropriate mitigation strategies.
Partner with engineering, infrastructure, architecture, and business teams to provide security guidance throughout project lifecycles.
Present security findings, risk recommendations, and remediation plans to technical and non-technical stakeholders.
Promote Security by Design principles throughout project delivery lifecycles and enterprise technology initiatives.
Champion Secure Software Development Lifecycle (SSDLC) practices, including secure coding standards, shift-left security, automated testing, and CI/CD integration.
Manage and mature application security programs, including SAST, SCA, DAST, penetration testing, vulnerability management, and API security.
Manage third-party application security testing activities, validate findings, and drive remediation efforts based on risk.
Identify security gaps across the technology landscape and recommend scalable, practical solutions to strengthen goeasy's security posture.
Act as a trusted advisor on information security, privacy, compliance, and risk management matters.
Evaluate existing security technologies and processes, recommending improvements that enhance efficiency, effectiveness, and security maturity.
Support and maintain security controls and compliance initiatives, including PCI DSS, SOC 2, Bill 198, and other regulatory requirements.
Skip the repetitive application forms
Install the Base Career Chrome Extension and autofill job applications across major job boards with your profile.
Trusted by over 500,000 job seekers on Base Career
More from this employer
Mississauga, CAN
Abbotsford, CAN
Mississauga, CAN
Cold Lake, CAN
Mississauga, CAN
Toronto, CAN
Québec, CAN
Toronto, CAN
Québec, CAN
Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related field; postgraduate education is considered an asset.
8+ years of Information Security experience, including 5+ years specializing in Application Security, Security Architecture, Security Risk Assessments, and Threat Modeling within complex enterprise environments.
Strong knowledge of secure software development practices (SSDLC), DevSecOps, CI/CD pipelines, secure coding principles, and modern application security frameworks.
Hands-on experience with application security testing and vulnerability management, including SAST, SCA, DAST, penetration testing, and API security.
Deep understanding of cloud, infrastructure, network, and web application security, including OWASP Top 10 vulnerabilities and remediation methodologies.
Experience leading cross-functional security initiatives, influencing technical and business stakeholders, and working within regulated environments such as PCI DSS, SOC 2, SOX, and/or Bill 198.
Experience with Azure and/or AWS cloud platforms is required; previous Information Security Architect experience, programming/scripting experience (e.g., Java, Python, JavaScript, Go, Apex, or R), and Linux/Unix administration are considered strong assets.
Professional certifications including CISSP (required). Additional certifications such as CRISC, CSSLP, CCSP, CISM, OSCP, or GPEN are considered assets.
We offer a Flexible Work Program that provides you the ability to work three days onsite per week , from our Mississauga office.
Internal Applicants: please apply through the link and provide written endorsement from your current manager.
$141,570.00 – $154,000.00 CAD (includes base salary and bonus)
We’re committed to attracting and rewarding top talent. Our compensation ranges are thoughtfully designed to reflect market competitiveness, internal equity, and the experience and impact each candidate brings to the role.
At goeasy, we believe transparency fosters trust — and that rewarding performance with fair, competitive pay and meaningful growth opportunities is key to our success.
Should your total compensation expectations fall above the posted range, we still encourage you to apply. If selected for an interview, you’ll have the opportunity to discuss this with our recruitment team, as there may be flexibility based on your background and overall fit. Total compensation includes base salary and bonus.
This posting is for an existing vacancy within our team.
In keeping with our mission to create better tomorrows for our employees, each year goeasy commits to continuously enhancing its total rewards. Here are some of the perks we offer:
Enjoy company-paid volunteer days to give back to the community.
Access 24/7 healthcare with Virtual Doctor Appointments.
Personalize your benefits with a flexible modular benefits package.
Stay fit and energized with exclusive access to our on-site private gym at our head office.
At goeasy, we believe that we can only be the best when people are able to bring their best selves to work every day. goeasy is committed to an inclusive, equitable and accessible workplace. By learning from each other’s differences, we gain strength through our people and our perspectives. As an equal opportunity employer, we are committed to providing accommodations (including accessible meeting rooms, captioning for virtual interviews, etc.) to help us remove barriers so that you can participate throughout the interview process. Please let the talent acquisition team know if you require an accommodation during any aspect of the recruitment process and we will work with you to address your needs.
Additional Information:
All candidates considered for hire must successfully pass a criminal background check, credit check, and validation of their work experience to qualify for hire. We thank all interested applicants; however, we will only be contacting those for interview who possess the skills and qualifications outlined above.
Canadian non-prime consumer lender and lease-to-own retailer.
Visit company websiteJobs and hiring trendsCAD 141570-154000 yearly / year
Full-time
Senior · 8+ years experience
Hybrid
Apply faster on company sites with our extension.