Expoint - all jobs in one place

The point where experts and best companies meet

Limitless High-tech career opportunities - Expoint

Td Bank Senior Application Security Analyst 
Canada, Ontario, Toronto 
586670102

24.04.2025
Toronto, Ontario, CanadaTechnology Solutions

$76,800 - $115,200 CAD

Job Description:

TD Information Security covers the development and management of security strategies, policies, programs and more. Our focus is to assess, prioritize, and mitigate business risk through the automation of technology controls. We do this through mitigating and managing cyber security threats, ensuring systems availability, aligning with global regulatory risk and compliance requirements, managing systems and network complexity, and partnering with different businesses for better technology delivery by providing advice on technology controls. There is so much to explore and room to grow within TD Information Security.


Meaningful work is fueled by meaningful performance and career development conversations with your manager. Here's some of what you may be asked to perform:

•  Collaborate with Infrastructure, Development Experience and Cloud Security teams to Integrate static application security testing and software composition analysis tools and processes within TD's centralized delivery pipelines.
•  Help perform DevSecOps maturity assessments for various application teams – assess each team's current state and build a roadmap to achieve their target state.
•  Provide support and consulting services around security automation and processes.
•  Lead adoption efforts with developers in various forums to make a cultural shift on security scans. Strategize and formulate automated security processes for application owners to enhance security through development.
•  Influence behavior to reduce risk, foster a strong technology risk management culture.
•  Creation and rollout of security metrics to ensure technology, processes, and governance are in place to monitor, detect, prevent, and react to both current and emerging technology and security threats to TD.
•  Codify and script various AppSec processes for development teams.
•  Manage relationships with othertechnology/business/corporate/controlfunctions.
•  Assess, identify, and escalate issues appropriately.

Job Requirements:

What can you bring to TD? Share your credentials, but your relevant experience and knowledge can be just as likely to get our attention.
Candidate must have:

  • 5+ years of relevant experience in Application Security (SAST, SCA, DAST, WAF, ASPM), or Infrastructure, Container, Cloud security with background in secure code development (DevSecOps, SSDLC).
  • Strong knowledge of application security concepts and practices, including OWASP Top 10, Code scanning tools, Supply chain attacks and Threat modelling.
  • Experience with GitHub Actions/Workflows or Jenkins. Ability to build and automate security touchpoints within GitHub Workflows or Jenkins. Understanding of configuring and leveraging a CI/CD orchestration tool within an organization.
  • Experience with application scanning tools like Veracode, Snyk, GitHub Advanced Security.
  • Python scripting ability – proficient in python.
  • Experience with ServiceNow Application Vulnerability Response or similar tools.
  • Knowledge and understanding of infrastructure and cloud security.
  • Understanding of development methodologies and secure software development lifecycle.
  • Developer experience and understanding of development processes with modernprogramming/scriptinglanguages.
  • Demonstrated ability to participate in projects of moderate to high complexity.
  • Ability and commitment to serve as a subject matter expert on business-specific, cross-functional and enterprise initiatives.
  • University Degree. Computer Science, Information Security or related field or equivalent experience.

It helps if you have:

  • Information Security Certification / Accreditation (CompTIA Security+, CEH, CSSLP, CASE, GSEC)
  • Ability to triage and review technical security vulnerabilities and findings.
  • Firm commitment to staying informed and abreast of emerging security issues, industry trends etc.
  • Advanced knowledge of one or more technology controls or security domains, disciplines, and practices.
  • Experience with information security controls, policies, processes, and industry standards.



Please be advised that this job opportunity is subject to provincial regulation for employment purposes. It is imperative to acknowledge that each province or territory within the jurisdiction of Canada may have its own set of regulations, requirements.

If you’re interested in a specific career path or are looking to build certain skills, we want to help you succeed. You’ll have regular career, development, and performance conversations with your manager, as well as access to an online learning platform and a variety of mentoring programs to help you unlock future opportunities. Whether you have a passion for helping customers and want to expand your experience, or you want to coach and inspire your colleagues, there are many different career paths within our organization at TD – and we’re committed to helping you identify opportunities that support your goals.


We will provide training and onboarding sessions to ensure that you’ve got everything you need to succeed in your new role.


Sans Objet