Advising developers on secure coding practices and common web application vulnerabilities. * Helping establish secure deployment, hosting, authentication, and access management standards.
Advising developers on secure coding practices and common web application vulnerabilities. * Helping establish secure deployment, hosting, authentication, and access management standards.
We're seeking someone to join our team as a Lead Web Proxy / AI Gateway Specialist in ... application protocols in HTTPS, WebSocket, SSE, and apply relevent security control in DLP/AV ...
We're seeking someone to join our team as a Lead Web Proxy / AI Gateway Specialist in ... application protocols in HTTPS, WebSocket, SSE, and apply relevent security control in DLP/AV ...
The Application Development team is seeking a Senior Full Stack Application Developer to support ... Design, develop, test, and maintain enterprise web applications using modern Microsoft technologies
The Application Development team is seeking a Senior Full Stack Application Developer to support ... Design, develop, test, and maintain enterprise web applications using modern Microsoft technologies
We are looking for an innovative Full Stack Web Developer for our Electric-Eye team working a web ... Develop tools and application features to improve the workflow of processing emission-related data
Quick apply
We are looking for an innovative Full Stack Web Developer for our Electric-Eye team working a web ... Develop tools and application features to improve the workflow of processing emission-related data
The Application Development team is seeking a Senior Full Stack Application Developer to support ... Design, develop, test, and maintain enterprise web applications using modern Microsoft technologies
The Application Development team is seeking a Senior Full Stack Application Developer to support ... Design, develop, test, and maintain enterprise web applications using modern Microsoft technologies
We are looking for an innovative Full Stack Web Developer for our Electric-Eye team working a web ... Develop tools and application features to improve the workflow of processing emission-related data
We are looking for an innovative Full Stack Web Developer for our Electric-Eye team working a web ... Develop tools and application features to improve the workflow of processing emission-related data
The Application Development team is seeking a Senior Full Stack Application Developer to support ... Design, develop, test, and maintain enterprise web applications using modern Microsoft technologies
The Application Development team is seeking a Senior Full Stack Application Developer to support ... Design, develop, test, and maintain enterprise web applications using modern Microsoft technologies
The Application Development team is seeking a Senior Full Stack Application Developer to support ... Design, develop, test, and maintain enterprise web applications using modern Microsoft technologies
The Application Development team is seeking a Senior Full Stack Application Developer to support ... Design, develop, test, and maintain enterprise web applications using modern Microsoft technologies
The Application Development team is seeking a Senior Full Stack Application Developer to support ... Design, develop, test, and maintain enterprise web applications using modern Microsoft technologies
The Application Development team is seeking a Senior Full Stack Application Developer to support ... Design, develop, test, and maintain enterprise web applications using modern Microsoft technologies
Every application is carefully reviewed, and we will get back to you as soon as possible. Thank you ... What you'll do You will lead a passionate team of web developers to design and build our new Toon ...
Every application is carefully reviewed, and we will get back to you as soon as possible. Thank you ... What you'll do You will lead a passionate team of web developers to design and build our new Toon ...
Chef(fe) d'quipe, Dveloppement Web & Infonuagique / Team Lead, Web Development & Cloud
Montreal, QC · On-site
Every application is carefully reviewed, and we will get back to you as soon as possible. Thank you ... What you'll do You will lead a passionate team of web developers to design and build our new Toon ...
Quick apply
Chef(fe) d'quipe, Dveloppement Web & Infonuagique / Team Lead, Web Development & Cloud
Montreal, QC · On-site
Every application is carefully reviewed, and we will get back to you as soon as possible. Thank you ... What you'll do You will lead a passionate team of web developers to design and build our new Toon ...
Dveloppeur front-end principal (React) / Lead Front-End Developer (React) GenAIz est la recherche ... Responsable de la qualitDvelopper et mettre jour notre application web React * Assurer la ...
Quick apply
Dveloppeur front-end principal (React) / Lead Front-End Developer (React) GenAIz est la recherche ... Responsable de la qualitDvelopper et mettre jour notre application web React * Assurer la ...
Work crossfunctionally with internal groups such as LDAP / Web Proxy Engineering, Security Architecture, Governance and Compliance * 8+ years of application development experience using C#, .NET, ...
New
Work crossfunctionally with internal groups such as LDAP / Web Proxy Engineering, Security Architecture, Governance and Compliance * 8+ years of application development experience using C#, .NET, ...
New
You Are You are an AI-Powered Application Developer with strong experience building custom web applications. You're highly analytical, thrive in solving complex problems, and enjoy building scalable ...
You Are You are an AI-Powered Application Developer with strong experience building custom web applications. You're highly analytical, thrive in solving complex problems, and enjoy building scalable ...
We are looking to hire talented developers to join our team. Be part of a fast moving, lean product ... web application. Deliver reliable, scalable new features to MOKO users developed using Python ...
Quick apply
We are looking to hire talented developers to join our team. Be part of a fast moving, lean product ... web application. Deliver reliable, scalable new features to MOKO users developed using Python ...
Develop the RTINGS mobile application using Hotwire Native, delivering a native app experience ... Build native screens and bridge components where a web-based experience isn't sufficient.
Develop the RTINGS mobile application using Hotwire Native, delivering a native app experience ... Build native screens and bridge components where a web-based experience isn't sufficient.
Developer * Full-time PermanentRole * Benefitsavailable day 1: Medical, Dental, Retirement Plan ... web-based product application built in Kotlin.If you would like to be part of a creative ...
Developer * Full-time PermanentRole * Benefitsavailable day 1: Medical, Dental, Retirement Plan ... web-based product application built in Kotlin.If you would like to be part of a creative ...
As a full-stack application Developer, reporting directly to the Digital Lead Architect, you will be part of the connectivity innovation team constantly improving BRPs Consumer applications and be ...
As a full-stack application Developer, reporting directly to the Digital Lead Architect, you will be part of the connectivity innovation team constantly improving BRPs Consumer applications and be ...
WordPress Architect
Montreal, QC · On-site
Evolving Web has an opening for a WordPress Architect. You'll work closely with our developers ... Knowledge of security best practices in web application development, particularly within WordPress ...
Quick apply
WordPress Architect
Montreal, QC · On-site
Evolving Web has an opening for a WordPress Architect. You'll work closely with our developers ... Knowledge of security best practices in web application development, particularly within WordPress ...
Front-End Web Developer
Montreal, QC · On-site +1
Join us and let's lead the way forward, together. Why choose GIRO? Join a Quebec software company ... HOW YOU'LL MAKE A POSITIVE IMPACT GIRO is looking for a Front-End Web Developer to join its team.
Front-End Web Developer
Montreal, QC · On-site +1
Join us and let's lead the way forward, together. Why choose GIRO? Join a Quebec software company ... HOW YOU'LL MAKE A POSITIVE IMPACT GIRO is looking for a Front-End Web Developer to join its team.
Lead Web Application Developer information
What are the key skills and qualifications needed to thrive as a Lead Web Application Developer, and why are they important?
What are Lead Web Application Developers?
How does a Lead Web Application Developer typically collaborate with cross-functional teams during a project?

Contractor
Posted 18 days ago
Job description
(VERSION EN FRANCAIS PLUS BAS)
The Role
We're looking for a Web Security Consultant who can help us build secure websites from the ground up.
Security isn't something that should be addressed at the end of a project-it's something that should be considered throughout the entire development lifecycle.
We're looking for someone who can help us establish best practices, identify potential risks before they become problems, and create repeatable standards that every project can follow.
In this role, you'll work closely with our development team to review websites and web applications, ensure they meet current security standards, and build practical processes that improve consistency across every project.
Our web environment is primarily built on WordPress, alongside other modern web technologies. Because of this, strong experience securing WordPress websites, plugins, themes, hosting environments, and deployment workflows is a significant advantage.
Beyond identifying vulnerabilities, you'll help create documentation, checklists, and security guidelines that become part of our standard development workflow.
What You'll Be Doing
Your primary responsibility will be helping the studio build and maintain secure, reliable web solutions.
Responsibilities include:
- Reviewing websites and web applications to ensure they follow current web security best practices.
- Conducting security reviews for WordPress websites and other web applications, identifying platform-specific risks and recommending practical remediation strategies.
- Identifying security vulnerabilities and recommending practical remediation strategies.
- Performing security reviews throughout the development lifecycle rather than only before launch.
- Developing a standardized security checklist that becomes part of every new website project.
- Creating internal documentation and security best practices for developers and project teams.
- Advising developers on secure coding practices and common web application vulnerabilities.
- Helping establish secure deployment, hosting, authentication, and access management standards.
- Recommending security best practices for WordPress core updates, plugin management, user permissions, backups, and hosting configurations.
- Working with project managers and technical teams to ensure security requirements are incorporated into project planning.
- Staying current on evolving security threats, frameworks, and industry standards.
- Supporting periodic security audits and continuous improvements across existing client websites.
What We're Looking For
We're looking for someone who understands that good security is proactive, practical, and scalable. The ideal candidate can evaluate technical implementations, communicate risks clearly, and create processes that make secure development easier for everyone on the team.
You likely have experience with many of the following:
- Web application security principles and secure development practices.
- Familiarity with the OWASP Top 10 and common web application vulnerabilities.
- Security reviews for modern web applications and websites.
- Strong experience securing WordPress websites, including themes, plugins, user roles, hosting environments, and update strategies.
- Authentication, authorization, session management, and access control best practices.
- HTTPS, SSL/TLS, HTTP security headers, and Content Security Policy (CSP).
- Security testing tools and vulnerability assessment methodologies.
- Experience reviewing websites built with modern CMS platforms and JavaScript frameworks.
- Strong documentation skills and experience developing internal standards or technical playbooks.
- Excellent communication skills and the ability to explain technical concepts to both technical and non-technical stakeholders.
What Success Looks Like
Success in this role means:
- Every new website follows a consistent security review process before launch.
- Developers have clear, practical security standards they can apply throughout development.
- WordPress projects follow consistent security standards for deployment, maintenance, and ongoing updates.
- Common vulnerabilities are identified and addressed early in the project lifecycle.
- Internal security documentation and checklists become part of the agency's standard workflow.
- Clients can trust that their websites are built according to current security best practices.
- The studio continuously improves its security posture as technologies and threats evolve.
Bonus Points
It's a plus if you have experience with:
- Penetration testing or vulnerability assessments.
- Cloud hosting platforms such as AWS, Azure, or Google Cloud.
- Web application firewalls (WAF) and CDN security.
- DevSecOps practices and CI/CD security integration.
- Compliance frameworks such as SOC 2, ISO 27001, GDPR, or PCI DSS.
- Deep expertise in WordPress security, including hardening, plugin vulnerability management, hosting security, and performance/security best practices.
- Shopify, Webflow, headless CMS, or modern JavaScript framework security.
- Security automation and monitoring tools.
Why Join Invisible Colors?
At Invisible Colors, we build digital experiences that clients trust. Most of our web projects are built on WordPress, making security expertise in that ecosystem especially valuable. Security is a critical part of delivering quality work-not an afterthought. You'll help establish the standards and processes that shape how every website is built, giving our developers the tools and guidance they need to deliver secure, reliable solutions from day one. If you're passionate about making security practical, scalable, and integrated into modern web development, we'd love to hear from you.
______________________________________
Le role
Nous sommes a la recherche d'un(e) Consultant(e) en securite Web qui nous aidera a concevoir des sites Web securitaires des leur conception.
Pour nous, la securite ne doit pas etre une etape ajoutee a la fin d'un projet : elle doit etre integree a chaque phase du cycle de developpement.
Nous recherchons une personne capable d'etablir des bonnes pratiques, d'identifier les risques avant qu'ils ne deviennent des problemes et de mettre en place des standards reproductibles que toutes les equipes pourront appliquer a l'ensemble des projets.
Dans ce role, vous travaillerez en etroite collaboration avec notre equipe de developpement afin de revoir des sites Web et des applications Web, de vous assurer qu'ils respectent les normes de securite actuelles et de mettre en place des processus pratiques favorisant une approche coherente sur tous nos projets.
Notre environnement Web repose principalement sur WordPress, en plus d'autres technologies Web modernes. Une solide experience en securisation de sites WordPress, des extensions (plugins), des themes, des environnements d'hebergement et des processus de deploiement constitue donc un atout majeur.
Au-dela de l'identification des vulnerabilites, vous contribuerez a creer de la documentation, des listes de verification (checklists) et des lignes directrices en matiere de securite qui feront partie integrante de notre processus de developpement.
Ce que vous ferez
Votre principale responsabilite sera d'aider le studio a concevoir et maintenir des solutions Web securitaires, fiables et durables.
Responsabilites:
- Effectuer des revues de securite de sites Web et d'applications Web afin de s'assurer qu'ils respectent les meilleures pratiques actuelles en matiere de securite.
- Realiser des analyses de securite sur des sites WordPress et d'autres applications Web, identifier les risques propres aux plateformes et recommander des mesures correctives adaptees.
- Identifier les vulnerabilites de securite et proposer des solutions concretes pour les corriger.
- Effectuer des revues de securite tout au long du cycle de developpement plutot qu'uniquement avant la mise en production.
- Developper une liste de verification (checklist) de securite standardisee qui sera integree a tous les nouveaux projets Web.
- Produire de la documentation interne et des guides de bonnes pratiques destines aux developpeurs et aux equipes de projet.
- Conseiller les developpeurs sur les pratiques de developpement securitaire et les vulnerabilites courantes des applications Web.
- Contribuer a l'etablissement de standards en matiere de deploiement securise, d'hebergement, d'authentification et de gestion des acces.
- Recommander les meilleures pratiques concernant les mises a jour du noyau WordPress, la gestion des extensions, les permissions des utilisateurs, les sauvegardes et les configurations d'hebergement.
- Collaborer avec les gestionnaires de projets et les equipes techniques afin d'integrer les exigences de securite des la planification des projets.
- Assurer une veille continue sur les nouvelles menaces, les cadres de reference et les meilleures pratiques de l'industrie.
- Participer aux audits de securite periodiques et a l'amelioration continue des sites Web de nos clients.
Ce que nous recherchons
Nous recherchons une personne qui comprend qu'une bonne strategie de securite est proactive, pragmatique et evolutive.
Le ou la candidat(e) ideal(e) est capable d'evaluer des implementations techniques, de communiquer clairement les risques et de mettre en place des processus qui facilitent l'adoption de pratiques securitaires par l'ensemble de l'equipe.
Vous possedez idealement plusieurs des competences suivantes:
- Excellente comprehension des principes de securite des applications Web et des pratiques de developpement securitaire.
- Bonne connaissance du OWASP Top 10 et des principales vulnerabilites des applications Web.
- Experience en revue de securite de sites Web et d'applications Web modernes.
- Solide experience en securisation de sites WordPress, incluant les themes, les extensions (plugins), les roles utilisateurs, les environnements d'hebergement et les strategies de mise a jour.
- Maitrise des meilleures pratiques en matiere d'authentification, d'autorisation, de gestion des sessions et de controle des acces.
- Bonne connaissance de HTTPS, SSL/TLS, des en-tetes de securite HTTP ainsi que des politiques Content Security Policy (CSP).
- Experience avec des outils de tests de securite et des methodologies d'evaluation des vulnerabilites.
- Experience de revue de securite de sites developpes avec des CMS modernes et des frameworks JavaScript.
- Excellentes competences en documentation et experience dans la creation de normes internes, de guides techniques ou de playbooks.
- Excellentes aptitudes en communication et capacite a vulgariser des concepts techniques aupres d'intervenants techniques et non techniques.
A quoi ressemble le succes dans ce role
Vous serez considere(e) comme ayant du succes lorsque :
- Tous les nouveaux sites Web suivent un processus de revue de securite coherent avant leur mise en production.
- Les developpeurs disposent de standards de securite clairs et faciles a appliquer tout au long du developpement.
- Les projets WordPress respectent des standards uniformes en matiere de deploiement, de maintenance et de mises a jour.
- Les vulnerabilites les plus courantes sont detectees et corrigees tot dans le cycle de developpement.
- La documentation interne et les listes de verification en matiere de securite deviennent des elements standards du processus de developpement de l'agence.
- Les clients ont confiance que leurs sites Web sont developpes selon les meilleures pratiques actuelles en matiere de cybersecurite.
- Le studio ameliore continuellement son niveau de securite a mesure que les technologies et les menaces evoluent.
Atouts
Une experience dans les domaines suivants constitue un avantage important :
- Tests d'intrusion (Penetration Testing) ou evaluations de vulnerabilites.
- Plateformes d'hebergement infonuagique telles qu'AWS, Microsoft Azure ou Google Cloud.
- Pare-feu applicatifs Web (WAF) et securite des reseaux de diffusion de contenu (CDN).
- Pratiques DevSecOps et integration de la securite dans les pipelines CI/CD.
- Cadres de conformite tels que SOC 2, ISO 27001, RGPD (GDPR) ou PCI DSS.
- Expertise avancee en securite WordPress, notamment le durcissement (hardening), la gestion des vulnerabilites des extensions, la securite des environnements d'hebergement ainsi que les meilleures pratiques en matiere de performance et de securite.
- Securite des plateformes Shopify, Webflow, des CMS Headless ou des frameworks JavaScript modernes.
- Outils d'automatisation, de surveillance et de monitoring de la securite.
Pourquoi joindre Invisible Colors?
Chez Invisible Colors, nous concevons des experiences numeriques auxquelles nos clients peuvent faire confiance. La majorite de nos projets Web sont developpes sur WordPress, ce qui fait de l'expertise en securite sur cette plateforme un element particulierement important.
Pour nous, la securite fait partie integrante de la qualite d'un projet - elle n'est jamais une reflexion de derniere minute.
Dans ce role, vous contribuerez a etablir les standards, les processus et les meilleures pratiques qui guideront le developpement de chacun de nos sites Web. Vous donnerez a nos developpeurs les outils, les ressources et les lignes directrices necessaires pour livrer des solutions securitaires, fiables et durables des le premier jour.
Si vous etes passionne(e) par une approche de la securite qui est a la fois pratique, evolutive et pleinement integree au developpement Web moderne, nous aimerions vous rencontrer.
Employment Type: CONTRACTOR