Director, Application Security and Vulnerability Management

Loblaw Companies LimitedBrampton, ON
CA$128,000 - CA$176,000Hybrid

About The Position

This role will lead the strategy, engineering, and operating model that helps teams build secure software and remediate risk at enterprise scale. Come lead a team that values diverse ideas, embeds practical security into engineering workflows, and develops our talent from within. You will help modernize application security and vulnerability management, enable secure innovation, and make a measurable difference to customers, colleagues, and business operations.

Requirements

  • Proven progressive experience in application security, product security, vulnerability management, cloud security, DevSecOps, or cybersecurity engineering, including leading technical teams or major programs.
  • Demonstrated success leading application security and vulnerability management in a large, complex enterprise, ideally within retail, healthcare, financial services, telecommunications, or another regulated environment.
  • Deep expertise in secure SDLC and DevSecOps, including threat modeling, SAST, DAST, SCA, API security, secret detection, container and Kubernetes security, infrastructure-as-code scanning, and CI/CD controls.
  • Proven experience operating enterprise vulnerability management, including asset and scan governance, finding validation, risk prioritization, remediation SLAs, exceptions, retesting, and executive reporting.
  • Strong understanding of application and API architectures, microservices, authentication flows, cloud-native services, containers, serverless platforms, and software supply-chain risk across AWS, Azure, GCP, and OCI.
  • Experience with platforms such as GitLab Ultimate, Qualys, Cortex Cloud / Prisma Cloud, Veracode, Invicti, Snyk, Checkmarx, API security, attack surface management, or exposure management tools.
  • Experience securing AI/ML, generative AI and agentic applications, AI code assistants, and model or agent supply chains, including prompt injection, data leakage, insecure tool use, and vulnerable dependencies.
  • Ability to apply CVE, CWE, CVSS, EPSS, known-exploited vulnerability data, threat intelligence, asset criticality, and attack-path context to focus remediation on the risks that matter most.
  • Excellent executive communication, stakeholder, financial, and vendor leadership skills, with the ability to translate technical exposure into clear decisions and accountable remediation plans.
  • Bachelor's or Master's degree in Computer Science, Software Engineering, Information Security, Engineering, or a related field. CISSP, CSSLP, CISM, CCSP, GIAC GWEB/GWAPT, OSWE, cloud security, or GitLab credentials are strong assets.

Responsibilities

  • Lead Loblaw's enterprise Application Security and Vulnerability Management strategy, architecture, engineering, and operations across applications, APIs, cloud workloads, endpoints, servers, containers, and infrastructure.
  • Own the secure SDLC and DevSecOps control model, integrating SAST, DAST, SCA, API security, secret detection, container scanning, and infrastructure-as-code scanning into GitLab Ultimate and enterprise CI/CD workflows.
  • Establish risk-based security gates at commit, merge, build, test, and release stages, with clear thresholds, exception governance, developer guidance, and remediation requirements.
  • Build an application-level DAST and API Security coverage model that maps business applications to repositories, microservices, deployed URLs, environments, API specifications, authentication flows, and accountable owners.
  • Lead the enterprise vulnerability management lifecycle, including asset discovery, scan coverage, validation, deduplication, risk prioritization, remediation service levels, exceptions, retesting, and verified closure.
  • Create a unified exposure view that connects vulnerabilities to internet exposure, attack paths, identities, business services, and asset criticality, giving engineering teams and executives clear, actionable risk information.
  • Own the roadmap and reliable operation of platforms such as GitLab Ultimate, Cortex Cloud / Prisma Cloud, Qualys, API security, attack surface management, and exposure management capabilities.
  • Establish security patterns for AI-enabled software, generative AI, models, agents, and AI-assisted development; address prompt injection, sensitive-data leakage, insecure tool use, and model or agent supply-chain risk.
  • Partner with product, development, SRE, cloud, infrastructure, identity, network, data, privacy, SOC, risk, and audit teams to threat model designs, remediate vulnerabilities, respond to events, and provide control evidence.
  • Lead and develop application security engineers, vulnerability analysts, product owners, and platform specialists; manage budgets, vendors, services, roadmaps, automation, runbooks, succession, and two-deep coverage.

Benefits

  • Work Perks Program
  • On-site GoodLife Fitness, Basketball & Volleyball courts, Ice Rink
  • Groceries delivered to work via PC Express, Dry Cleaning services (1PCC Office)
  • Tuition Reimbursement & Online Learning
  • Pension & Benefits
  • Paid Vacation
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service