1

Application Security Engineer Jobs in Ontario (NOW HIRING)

Application Security Engineer (REMOTE)

Ottawa, ON ยท Remote

CA$117K - CA$146K/yr

Job Purpose The Application Security Engineer is responsible for strengthening the security of our applications, platforms, and development processes. This position partners with software engineers ...

Application Security Developer

Toronto, ON ยท Hybrid

CA$137K - CA$157K/yr

We are currently seeking an Application Security Engineer to join our rapidly growing Security team. The Application Security team is responsible for emulating real-world adversaries to proactively ...

Lead Application Security Engineer

Toronto, ON ยท Hybrid

CA$121K - CA$170K/yr

Hands-on experience with application security tools including dynamic and static analysis and web application penetration testing. * Strong ability to assess and communicate security risks across ...

... application security * Direct, hands-on experience securing AI-integrated systems including LLM ... Track record of influencing engineering decisions and behaviour without formal authority over the ...

Position: Security Engineer (Coding Agent Experience) Type: Contract Compensation: $85/hour ... Experience with application security , cloud security , infrastructure security , or vulnerability ...

The Cloud Security Engineer, Cloud Security Engineering will be responsible for providing technical ... Develop tools and scripts required by teams and end users using various cloud and application ...

Cyber Security Engineer I

Mississauga, ON ยท On-site

CA$81K - CA$115K/yr

Mobile application security and Pen testing tools The successful candidate must have demonstrated advanced ability to engineer, design, build, support and document solutions in these areas of ...

Mobile application security and Pen testing tools The successful candidate must have demonstrated advanced ability to engineer, design, build, support and document solutions in these areas of ...

Application Security Analyst

Woodbridge, ON ยท Hybrid

CA$95K - CA$115K/yr

Application Security Analyst Department: Information Technology Location: 6300 Steeles Ave West ... You will work closely with Architecture, DevOps, QA, Product teams, and external partnerstoembed ...

Security Engineer, DevOps

Toronto, ON ยท On-site

CA$110K - CA$150K/yr

Design and embed application security controls within development pipelines, partner with product and platform engineers to design remediation solutions, clearly communicate implications and timing ...

next page

Showing results 1-20

Application Security Engineer information

See Ontario salary details

$69K

$136.7K

$206.5K

How much do application security engineer jobs pay per year?

As of Aug 4, 2026, the average yearly pay for application security engineer in Ontario is $136,737.00, according to ZipRecruiter salary data. Most workers in this role earn between $113,500.00 and $154,000.00 per year, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are the most commonly searched types of Application Security Engineer jobs in Ontario? The most popular types of Application Security Engineer jobs in Ontario are:
What are popular job titles related to Application Security Engineer jobs in Ontario? For Application Security Engineer jobs in Ontario, the most frequently searched job titles are:
What job categories do people searching Application Security Engineer jobs in Ontario look for? The top searched job categories for Application Security Engineer jobs in Ontario are:
What are popular job titles related to Application Security Engineer jobs in ON? For Application Security Engineer jobs in ON, the most frequently searched job titles are:
Infographic showing various Application Security Engineer job openings in Ontario as of July 2026, with employment types broken down into 78% Full Time, 17% Part Time, 1% Temporary, and 4% Contract. Highlights an 91% Physical, 3% Hybrid, and 6% Remote job distribution, with an average salary of $136,737 per year, or $65.7 per hour.

Senior Application Security Engineer

Scotiabank

Toronto, ON โ€ข On-site

Other

PTO

This job post hasย expired today.ย Applications are no longer accepted.


Job description

Requisition ID: 258939ย 
Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.

Purpose

The Senior Application Security Engineer is responsible for providing technical leadership across application security engineering, supporting secure software delivery through industry leading SDLC practices, tooling, and automation. This role focuses on the design, integration, and continuous improvement of enterprise application security capabilities, including secure CI/CD integrations, vulnerability detection, and remediation workflows.

The role contributes to the overall success of the Application Security Product & Engineering function by ensuring security tooling, processes, and integrations effectively protect the Bank and its customers from application layer threats. All activities are executed in compliance with regulatory requirements, internal policies, and risk management standards.

What You'll Do:

Technical Leadership

  • Provide technical leadership and guidance in a team environment spanning multiple geographies to support Application Security toolsets, responsible for their effectiveness, reliability, and outcomes.
  • Lead design, integration, and implementation of enterprise application security tooling (e.g., SAST, DAST, SCA, SBOM, API security, secrets detection).
  • Makes technical prioritization and trade-off decisions across application security tooling, balancing risk, scalability, developer experience, and operational efficiency.
  • Analytical and troubleshooting expertise and a strong ability to guide, mentor, train others how to investigate complex system integration problems, problem ownership, patience, understanding, and empathy of the difficulty of hunting for problems in other teams' software and architecture problems as a consultant and expert.

Secure SDLC & DevSecOps Enablement

  • Support integration of application security controls and tooling into DevOps pipelines and developer workflows across diverse deployment environments to enable secure-by-design and secure-by-default software delivery.
  • Define and implement SDLC processes and best practices used across engineering and security DevOps teams.
  • Support AppSec SLAs using DevOps skill sets to solution and resolve across the application stack.

Automation, Self-service & Continuous Improvement

  • Innovate and automate to reduce manual processes used to support security toolsets.
  • Influence an engineering culture of self-service tools that improve the developer experience through low-code solutions.
  • Contribute to the adoption of SDLC best practices and enterprise tooling to be used by all engineers.
  • Drive continuous improvement by contributing to the creation, collection, and reporting of KPIs, identifying efficiencies, and assisting the team in their deliverables.

Risk, Governance & Controls

  • Understand how the Bank's risk appetite and risk culture should be considered in daytoday activities and decisions.
  • Actively pursues effective and efficient operations of their respective areas in accordance with Scotiabank's Values, its Code of Conduct, and the Global Sales Principles, while ensuring the adequacy, adherence to, and effectiveness of day to day business controls to meet obligations with respect to operational, compliance, AML/ATF/sanctions, and conduct risk.

Stakeholder Collaboration & Delivery

  • Work across teams including engineering, external vendors, and technology teams to meet application security tooling roadmaps, and maintain security compliance and software currency within the tools and infrastructure.
  • Champions a support team to customer focused culture to deepen client relationships and leverage broader Bank relationships, systems, and knowledge.
  • Contributes to a high-performance environment and an inclusive work environment.

What You'll Bring:

  • 5+ years of experience leading and mentoring DevSecOps engineering teams within Agile and modern Software Development Life Cycle (SDLC) environments.
  • 5+ years of domain expertise in Application Security (AppSec), including hands-on experience deploying and managing enterprise vendor security platforms (such as SCA, SBOM, SAST, DAST, MAST, API Security, and CNAPP).
  • 5+ years of hands-on experience with containerization and orchestration technologies, specifically Docker and Kubernetes (k8s), including cluster architecture, performance tuning, and optimizing container workloads. Infrastructure as Code (IaC) experience preferred.
  • 5+ years of robust cloud infrastructure (such as Azure, GCP, AWS) and system administration experience across Linux and Windows ecosystems, with deep knowledge of network troubleshooting, firewalls, routing, and proxy configurations.
  • 5+ years of software development and scripting experience (such as Python, PowerShell, Bash, Java, C#, or .NET), with a strong focus on building, integrating, and consuming APIs across diverse architectures.
  • 5+ years of systems architecture and engineering experience designing and troubleshooting CI/CD pipelines (such as Jenkins, BitBucket, Azure DevOps, GitHub Actions). Strong proficiency with software build tools (such as Maven, Gradle) and package managers (such as npm).
  • 5+ years of experience authoring, reviewing, and maintaining comprehensive technical documentation and architectural designs for complex, enterprise-scale platforms and solutions.
  • Exceptional analytical and problem-solving abilities, paired with strong organizational, time-management, and cross-team communication skills.

ย 

Working Conditions

Work in standard office-based environments located in Scarborough and Downtown Toronto; non-standard hours are a common occurrence. No external travel required.

Interested?

If your experience is closely related but doesn't align perfectly with every qualification, we do encourage you to apply - you might be the right candidate for this or other roles at Scotiabank!

At Scotiabank, every employee is empowered to reach their fullest potential, respected for who they are and, embraced for their differences. That's why we work to grow and diversify talent and engage employees in a performance-oriented culture.

What's in it for you?

  • Diversity, Equity, Inclusion & Allyship - We strive to create an inclusive culture where every employee is empowered to reach their fullest potential, respected for who they are, and are embraced through bias-free practices and inclusive values across Scotiabank. We embrace diversity and provide opportunities for all employee to learn, grow & participate through our various Employee Resource Groups (ERGs) that span across diverse gender identities, ethnicity, race, age, ability & veterans.
  • Accessibility and Workplace Accommodations - We value the unique skills and experiences each individual brings to the Bank and are committed to creating and maintaining an inclusive and accessible environment for everyone. Scotiabank continues to locate, remove, and prevent barriers so that we can build a diverse and inclusive environment while meeting accessibility requirements.
  • Upskilling through online courses, cross-functional development opportunities, and tuition assistance.
  • Competitive Rewards program including bonus, flexible vacation, personal, sick days, and benefits will start on day one.
  • Community Engagement - no matter where you choose to work from; we offer opportunities for community engagement & belonging with our various programs.

Location(s): ย Canada : Ontario : Torontoย 
Scotiabank is a leading bank in the Americas. Guided by our purpose: "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.ย ย 
At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let ourย  Recruitment team know. If you require technical assistance, please click here. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.