1

Application Security Analyst Jobs in Quebec (NOW HIRING)

GRC Lead/Security Analyst (Montreal - Canada) Founded in 2000, Ivalua is a leading global provider ... WHAT HAPPENS NEXT If your application fits this specific position's needs, our skilled Talent team ...

Beyond alerts: help protect our security operations! What if your next investigation could stop a ... Send us your application, we want to hear from you! Join the Coveolife! We encourage all qualified ...

Beyond alerts: help protect our security operations! What if your next investigation could stop a ... Send us your application, we want to hear from you! Join the Coveolife! We encourage all qualified ...

next page

Showing results 1-20

Application Security Analyst information

See Quebec salary details

$65.5K

$104.9K

$159K

How much do application security analyst jobs pay per year?

As of Aug 22, 2026, the average yearly pay for application security analyst in Quebec is $104,906.00, according to ZipRecruiter salary data. Most workers in this role earn between $81,500.00 and $127,500.00 per year, depending on experience, location, and employer.

What is an application security analyst?

Application Security Analysts are professionals responsible for identifying and mitigating security vulnerabilities in software applications. They assess applications for risks by performing code reviews, vulnerability assessments, and penetration testing. Their role includes working with development teams to ensure security best practices are followed throughout the software development lifecycle. Application Security Analysts also help develop security policies, provide training, and respond to security incidents related to applications.

What are some common challenges faced by application security analysts when collaborating with development teams?

Application Security Analysts often encounter challenges in aligning security best practices with fast-paced development cycles. Ensuring that security recommendations are integrated early without delaying product releases requires strong communication and a collaborative approach with developers. Analysts must balance advocating for robust security measures while understanding development constraints, and often need to translate technical vulnerabilities into clear, actionable guidance for non-security professionals. Building trust and fostering a culture of shared responsibility for security helps overcome these challenges.

What are the key skills and qualifications needed to thrive as an application security analyst, and why are they important?

To thrive as an Application Security Analyst, you need a strong understanding of secure coding practices, vulnerability assessment, and information security principles, often supported by a degree in computer science or related certifications like CISSP or CEH. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing suites, and security information and event management (SIEM) systems is essential. Analytical thinking, attention to detail, and effective communication are critical soft skills for identifying risks and collaborating with development teams. These competencies are vital to proactively identifying vulnerabilities, minimizing risks, and ensuring robust application security in evolving technology environments.

What is the difference between Application Security Analyst vs Security Engineer?

AspectApplication Security AnalystSecurity Engineer
CertificationsCompTIA Security+, CISSP, CEHCISSP, CEH, Security+
Work EnvironmentFocus on application vulnerabilities, code reviews, and security assessmentsDesigns and implements security infrastructure, manages security tools
Industry UsageCommon in software development and IT teamsFound in cybersecurity teams across various industries
Primary FocusIdentifying and mitigating application security risksBuilding and maintaining security systems and protocols

While both roles involve cybersecurity, Application Security Analysts primarily focus on securing software applications through assessments and vulnerability management. Security Engineers work on developing and maintaining security infrastructure, ensuring overall organizational security. Both roles are essential in a comprehensive cybersecurity strategy but differ in scope and daily responsibilities.

Infographic showing various Application Security Analyst job openings in Quebec as of August 2026, with employment types broken down into 79% Full Time, 17% Part Time, and 4% Contract. Highlights an 89% Physical, 3% Hybrid, and 8% Remote job distribution, with an average salary of $104,906 per year, or $50.4 per hour.

GRC Lead/Security Analyst

Ivalua

Montreal, QC • On-site

Full-time

Posted 22 days ago


Job description

GRC Lead/Security Analyst

(Montreal - Canada)

Founded in 2000, Ivalua is a leading global provider of cloud-based procurement solutions.

COMPANY OVERVIEW

At Ivalua we are a global community of exceptional professionals, who believe that digital transformation revolutionizes supply chain sustainability and resiliency to unlock the power of supplier collaboration. We achieve this through our leading cloud-based spend management platform that empowers hundreds of the world's most admired brands to effectively manage all categories of spend and all suppliers to increase profitability, improve ESG (environmental, social, and corporate governance) performance, lower risk, and improve productivity. Driven by our passions and fueled by our shared ambitions, we empower and challenge each other to create meaningful experiences for our colleagues, customers, partners, and communities. 

Learn more at www.ivalua.com. Follow us on LinkedIn 

THE OPPORTUNITY

CONTEXT:

You will be part of the InfoSec team with a mission to build, maintain, and continuously improve our Information Security program, providing peace of mind and assurance of protection and safety to our customers. Our team is hands-on, with a strong problem-solving mindset, capable of thinking holistically about implementation and providing solutions to address our customers' long-term challenges. We work hard and play hard, enjoying various indoor and outdoor activities organized by the company, allowing you to focus, collaborate, and unleash your creativity.

ROLE: 

We are looking for a GRC Lead/Security Analyst to join our InfoSec team. This role will help drive various GRC activities which include supporting prospect and customer security questions, maintaining security policies, supporting security audits and assessments and driving new security certifications/compliance initiatives. 

WHAT YOU WILL DO WITH US 

  • Lead and support compliance initiatives in accordance with global and regional standards, including SOC 1/SOC 2, ISO 27001, IRAP, PCI-DSS, SecNumCloud, Cyber Essentials Plus (CE+), BSI C5, and NIST 800-53.
  • Evaluate technical controls across the entire technology stack, including all layers of the TCP/IP model (e.g., network segmentation, firewall rules, TLS/SSL configuration, IDS/IPS, access controls, application security, encryption in transit and at rest, and cloud security configurations), and translate security requirements into concrete guidelines for engineering and infrastructure teams.
  • Lead and manage client security audits, security questionnaires, and contract reviews, primarily for the EMEA region. Participate in the negotiation and review of French contracts to ensure alignment with security and compliance requirements.
  • Participate in meetings with prospects and clients and effectively present Ivalua's security architecture and controls to them.
  • Lead or support internal and third-party security risk management processes, including the identification, analysis, scoring, mitigation planning, and ongoing monitoring of risks.
  • Support ongoing compliance monitoring activities using manual processes, automation, and GRC tools to maintain the effectiveness of controls, generate audit evidence, and ensure ongoing audit readiness.
  • Ensure the implementation and coordination of key security and availability controls, such as business impact assessments, disaster recovery plan tests, security incident response drills, access reviews, etc.

YOUR PROFILE

If you have the below experience and strengths this role could be for you:

Skills and Experience:

  • At least 4 years of experience as a GRC Security Analyst.
  • Solid practical knowledge of security, risk, and compliance frameworks (e.g., NIST CSF & 800-53, ISO 27001, SOC, HITRUST, HIPAA, PCI-DSS, GDPR).
  • Direct experience managing audits, self-assessments, or risk assessments against one or more of the InfoSec frameworks listed above. 
  • Experience in implementing or supporting security risk management processes (risk assessments, risk registers, business impact analyses).
  • Proficiency with continuous compliance and monitoring platforms.
  • A solid understanding of cloud platforms (Azure, AWS, GCP) and the ability to discuss security architecture and the implementation of controls with technical teams.
  • Knowledge and experience working with the IT and security team, as well as a thorough understanding of security concepts across all technology layers (network, infrastructure, web applications, cloud environments).
  • Knowledge of security and risk industry literature, as well as leading reference knowledge bases (e.g., OWASP, MITRE ATT&CK, NIST 800-39).
  • Relevant certifications in auditing and/or information security (e.g., CISSP, CISA, CISM, Azure Cloud Security) are preferred.
  • Previous experience at a Big 4 firm or in a security/compliance role in a cloud/SaaS environment is a plus.
  • Bachelor's degree in Computer Science, or relevant field preferred with a minimum of 4 years of relevant professional experience OR Equivalent combination of education and experience

Soft Skills:

  • Excellent interpersonal, organizational, and communication skills. Ability to communicate effectively and professionally in French and English, including in contractual, regulatory, and technical contexts.
  • Ability to conduct business in English is required given our customer base; wherever possible, we will support the employee's right to work in French
  • Proven ability to work with geographically dispersed teams as well as with external service providers, auditors, or regulators.
    Strong organizational skills and attention to detail; ability to manage multiple priorities simultaneously in a fast-paced environment.
  • Strong sense of initiative, high level of motivation, and the ability to work independently with minimal supervision.

WHAT HAPPENS NEXT

If your application fits this specific position's needs, our skilled Talent team will reach out to schedule an initial screening call. Get one step closer to achieving your goals - apply today! 

Our Talent team will guide you through every step of the interview process - from preparation to completion. They're here to support you! 

Our recruitment process is designed to assess your competencies through a series of personalized interviews with internal stakeholders relevant to the role. 

Interviews will be conducted virtually via video or on-site with face-to-face meetings.

LIFE AT IVALUA

  • Hybrid working model (3 days in the office per week)
  • We're a team dedicated to pushing the boundaries of product innovation and technology
  • Sustainable Growth, Privately Held
  • A stable and cash-flow positive Company since 10 years
  • Snacks and weekly lunches in the office
  • Feel empowered to pursue your goals with improved team collaboration and increased creativity/productivity
  • Unlock and unleash your full professional potential with our exceptional training and career development program
  • Join a dynamic and international team of top-notch professionals who are experts in their respective fields
  • Collaborate with like-minded individuals who are deeply passionate and highly motivated about their work
  • Experience a truly diverse and inclusive work environment where your unique contributions are highly valued
  • Regular social events, competitive outings, team running events, and musical activities
  • Comparably recognized Ivalua for the following (https://www.comparably.com/companies/ivalua): 

Powered by People - Powered by You!

United by our values we embrace diversity and equity in the broadest possible sense to create an inclusive workplace. To help our customers make supply chains more efficient, sustainable and resilient, we rely on a global team with a variety of backgrounds, skills and views. We believe in equal opportunity and in diversity as a driver of innovation that cultivates a spirit of inclusiveness, creates a productive and fun place to work, and provides fulfilling career opportunities for all Ivaluans. https://www.linkedin.com/company/ivalua/about/

Experience life at Ivalua - check out our captivating video! Gain insight into our unique company culture and get a glimpse of what it's like to work with us.

#LI-MV1

#LI-HYBRID