Senior Information Security Analyst (Secure Code Review)

TDToronto, ON
CA$81,600 - CA$115,200Onsite

About The Position

We are seeking a skilled and experienced Secure Code Reviewer / Penetration Tester to join our team. As a Secure Code Reviewer / Penetration Tester, you will be responsible for identifying and exploiting vulnerabilities in applications and infrastructure to help improve our cybersecurity posture. You will use a range of tools and techniques to conduct secure code reviews and penetration testing and provide actionable recommendations to enhance security controls.

Requirements

  • Proven experience in conducting penetration testing and vulnerability assessments on various systems, networks, and applications.
  • Proven experience in Secure Code Review.
  • Expertise in using a range of penetration testing tools and techniques, including Burp Suite, Metasploit, and Nmap.
  • Solid understanding of web applications, mobile applications, and databases.
  • Experience in detecting, analysing and providing recommendation guidance on security vulnerabilities in at least two of the following languages: Java, C#, PHP, Python, Perl, C/C++ , SQL.
  • Hands-on experience conducting security focused static analysis using commercial SAST tools such as Skyk, Checkmarx, Appscan Source, Veracode, Coverity, Fortify and SonarQube.
  • Experience using ServiceNow.
  • Strong analytical and problem-solving skills.
  • Excellent written and verbal communication skills.
  • Ability to work both independently and as part of a team.
  • University degree
  • 3-5 years of relevant experience
  • 3+ years of experience in application security including secure code review, web application penetration testing or threat modelling.
  • 2+ years of experience in secure code review / static application security testing
  • Detailed understanding of the OWASP Top 10 and CWE Top 25 issues with focus on ability to identify and remediate vulnerability in source code.
  • Ability to explain risk and business impact of security vulnerabilities in source code to variety of audience.

Nice To Haves

  • Relevant industry certifications such as OSCP a plus.
  • Information security certification / accreditation an asset

Responsibilities

  • Deliver secure code review assessment on programming languages such as Java, C#, PHP, Python, Perl, C/C++ , SQL.
  • Analyze and identify security vulnerabilities in source code using both automated and manual static analysis tools and techniques.
  • Train and assist developers in writing secure software and remediating existing vulnerabilities.
  • Develop and review custom vulnerability description, business impact and remediation content.
  • Develop, research, and recommend open-source tools assisting in secure code review.
  • Contribute to development and delivery of secure coding and remediation training.
  • Mentor and assist team members in effectively delivering assessments and enhancing skillsets.
  • Key Lead in Release Based Testing Process and Td Mitigation Proposal Review Process.
  • On Call Position – to approve change requests if needed.
  • Conduct thorough and comprehensive penetration testing on various applications, networks, and infrastructure using both manual and automated techniques.
  • Identify vulnerabilities in a web applications, mobile applications, and manual code reviews.
  • Document and report findings and provide actionable recommendations to improve security posture.
  • Collaborate with other team members and application development teams to assess security risks and assist in remediation and mitigation strategies.
  • Research and stay up to date with the latest trends, threats, and vulnerabilities in the cybersecurity industry.
  • Communicate effectively with technical and non-technical stakeholders, as well as other team members.

Benefits

  • health and well-being benefits
  • savings and retirement programs
  • paid time off
  • banking benefits and discounts
  • career development
  • reward and recognition programs
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service