1

Application Security Manager Jobs in Ontario (NOW HIRING)

Application Security Analyst

Woodbridge, ON ยท Hybrid

CA$95K - CA$115K/yr

Manage AppSec vendor relationships and deliverables per the Application Security Managed Service scope (ASPM,PTaaS, continuous monitoring) Note: This is not intended to be all-inclusive. The employee ...

Application Security Developer

Toronto, ON ยท Hybrid

CA$119K - CA$161K/yr

The Application Security team is responsible for emulating real-world adversaries to proactively ... Strong AWS security experience on EC2 and managed services * Infrastructure security (WAF, ACLs ...

Application Security Engineer (REMOTE)

Ottawa, ON ยท Remote

CA$117K - CA$146K/yr

Integrate and manage security tooling within CI/CD pipelines, including SAST, DAST, SCA, IaC ... Ensure application security practices align with regulatory and compliance frameworks (e.g., NIST ...

Improve the application security function at HelloFresh to harden the apps & services against abuse ... Decent exposure to Terraform, Docker, container mgmt. services, CI/CD and secrets management in ...

next page

Showing results 1-20

Application Security Manager information

See Ontario salary details

$11K

$155.5K

$236.5K

How much do application security manager jobs pay per year?

As of Aug 12, 2026, the average yearly pay for application security manager in Ontario is $155,466.00, according to ZipRecruiter salary data. Most workers in this role earn between $132,500.00 and $163,500.00 per year, depending on experience, location, and employer.

What does an Application Security Manager do?

An Application Security Manager is responsible for overseeing the security of software applications within an organization. They identify and address potential security vulnerabilities, implement best practices for secure development, and ensure compliance with security standards. Their role often includes working with development teams, conducting security assessments, and responding to security incidents to protect sensitive data. Application Security Managers help maintain the confidentiality, integrity, and availability of applications throughout their lifecycle.

What are the key skills and qualifications needed to thrive as an Application Security Manager, and why are they important?

To thrive as an Application Security Manager, you need expertise in application security principles, risk assessment, secure coding practices, and a relevant degree or certifications like CISSP or CSSLP. Familiarity with security testing tools (such as SAST, DAST, and vulnerability scanners), secure development frameworks, and compliance standards is essential. Strong leadership, communication, and problem-solving skills help you collaborate with development teams and guide security initiatives. These skills are crucial to effectively safeguard applications, ensure regulatory compliance, and reduce security risks within organizations.

What are some common challenges faced by Application Security Managers when integrating security into the software development lifecycle?

Application Security Managers often encounter challenges in embedding security practices early and consistently within fast-paced development environments. Balancing the need for robust security with the demands for rapid delivery can result in pushback from development teams or tight deadlines. They must also navigate evolving threat landscapes and ensure that both technical and non-technical stakeholders are aligned on security priorities. Building strong cross-team relationships and fostering a culture of security awareness are key to overcoming these obstacles.
What cities in Ontario are hiring for Application Security Manager jobs? Cities in Ontario with the most Application Security Manager job openings:
Infographic showing various Application Security Manager job openings in Ontario as of August 2026, with employment types broken down into 1% As Needed, 77% Full Time, 21% Part Time, and 1% Contract. Highlights an 93% Physical, 3% Hybrid, and 4% Remote job distribution, with an average salary of $155,466 per year, or $74.7 per hour.

Application Security Analyst

Ontario 407

Woodbridge, ON โ€ข Hybrid

CA$95K - CA$115K/yr

Full-time

Posted 28 days ago


Job description

Title: Application Security Analyst

Department: Information Technology

Location: 6300 Steeles Ave West, Woodbridge

Total Potential Compensation: $95,000-$115,000

Position Summary:

As anApplication Security Analyst, you willbe responsible forsupporting and operating core security capabilities across 407 ETR's digital environment, with a primary focus on application security. This includes promoting secure-by-design practices throughout the SDLC and supporting the integration and operation of security tooling and automation, such as SAST, DAST, SCA, ASPM, and penetration testing services. You will work closely with Architecture, DevOps, QA, Product teams, and external partnerstoembed security controls into requirements, design, development, testing, and release activities, andtrackand manage security vulnerabilities through remediation.Thisrole also contributes to improving the overall cyber and technology risk posture, with measurable improvements reflected in the Technology and Cyber Risk Indices (TRI/SRI).

Hours of work are onsite, Monday to Friday, 7.5 hours daily, or asrequired. After-hours support and on-call duties may berequiredfor priority releases or security incidents.

Position Responsibilities:

AppSec Strategy & SDLC Integration

  • Embedsecurity requirementsandnonfunctional controls into epics, features, and user stories;maintainsecurity traceability throughout the lifecycle.

  • Leadthreat modelingat design time for new and changed services (web, mobile, APIs, microservices) and ensure mitigations are implemented prior to coding.

  • Define and operateSDLC security gates(precommit, build, test, deployment) with policydriven thresholds (e.g., fail on Critical/High) and exceptions governance.

DevSecOpsTooling & Automation

  • Implement and tuneSAST, DAST, SCAandASPMintegrations within CI/CD, ensuring coverage, accuracy, and developerfriendly feedback loops; coordinatePTaaScycles aligned to release schedules

  • Partner with DevOps to secure build pipelines, artifacts, and environments (e.g.,IaCscanning, container image hardening, secrets management, SBOM generation and validation)

  • Work with platform teams to evolve pipelines consistent with the 407 ETR DevOps framework andfuturestateCI/CD models

Findings Management & Risk Reporting

  • Operate aunified findings intake(ASPM as system of record) for automated tool outputs and manual assessments; triage, prioritize, and track remediation to closure

  • Apply ariskbased SLAmodel (severity, exploitability, asset criticality) and escalate overdue items; publish weekly triage outcomes and monthly KPIs.

  • Report AppSec posture usingTRI/SRIaligned metrics (e.g., unresolvedcriticals, meantimetoremediate, coverage, policy conformance)

Secure Engineering Enablement

  • Providesecure coding guidance, sample patterns, and remediation support for developers; deliver targeted training and office hours

  • Collaborate onarchitecture reviews, pentest scoping, and change risk assessments for web andmobile(using established changetype workflow)

  • Contribute to AppSecpolicies/standardsand improve documentation (playbooks, runbooks, "definition of done" security criteria)

AdditionalTechnical Experience

  • Experience withData Loss Prevention (DLP) technologiesand controls, including policy configuration, monitoring, and incident investigation, isrequired

  • Experience withSingle Sign-On (SSO) integrationsand identity federation protocols is an asset.

Compliance & Vendor Management

  • Ensure controls align withPCI DSS Secure SDLC,ISO 27001/27002, andNISTDevSecOpsguidance (e.g., SP 800204D); support internal/external audits and evidence collection

  • Manage AppSec vendor relationships and deliverables per theApplication Security Managed Servicescope (ASPM,PTaaS, continuous monitoring)

Note:This job description is not intended to be all-inclusive. The employee may perform other related duties, as assigned, to meet the ongoing needs of the organization.

Qualifications

  • Minimum5+ years of experience in IT Security, with strong hands-on experience in Security Operations.

  • College Diploma or University Degree in Computer Science, Engineering, or related field.

  • EDR platforms (e.g., endpoint containment, alert triage, investigation).

  • NDR technologies and network-based threat detection.

  • Security Incident Response and Investigation.

  • Strong understanding of attacker techniques and defensive controls (MITRE ATT&CK).

  • Experience working in regulated or audit-driven environments.

  • Strong understanding of authentication, authorization, MFA, RBAC, and privileged access concepts.

  • SSO Authentication: Experience implementing and supporting SSO solutions for secure user access across enterprise applications.

PreferredQualifications

  • Knowledge of standing up a mature Application Security framework

  • Experience with enterprise SOC tooling including SIEM, EDR, NDR, SOAR.

  • Experience operating security controls in hybrid (onprem and cloud) environments.

  • Familiarity with Security Risk Index (SRI), cyber risk metrics, or risk-based reporting.

  • Knowledge of network architecture and segmentation concepts.

We are actively seeking to fill this role as it is a current vacancy.

About 407 ETR

Highway 407 ETR is an all-electronic open-access toll highway located in the Greater Toronto Area in Ontario, Canada. The highway spans 108 kilometres from Burlington in the west to Pickering in the east.

407 International Inc. is the sole shareholder of 407 ETR and is owned by:

  • Cintra Global S.E., a subsidiary of Ferrovial S.A. (48.29%)

  • Canada Pension Plan Investment Board (CPP Investments) and other institutional investors with non-controlling interests (44.20%)

  • Public Sector Pension Investment Board (PSP Investments) (7.51%)

Learn more at407etr.com

Note:At 407 ETR, we are committed to fostering a diverse, equitable, and inclusive work environment. We value the unique perspectives and backgrounds of all individuals, and we firmly believe that our individual differences make us stronger as a whole.

Our commitment to inclusion extends beyond recruitment and encompasses an inclusive workplace culture through raising awareness, ongoing training, and encouraging feedback. We aim to create a safe and supportive environment where all employees can thrive.

Accommodation for disabilities or other grounds protected by human rights legislation are available upon request for candidates taking part in all aspects of the employment selection process.