- Company Name
- Rexall Pharmacy Group Ltd.
- Job Title
- Senior Application Security Architect
- Job Description
-
Job title: Senior Application Security Architect
Role Summary:
Drivers secure application development throughout the SDLC, defines and enforces security standards, collaborates with architects and developers, and manages application risk, testing, and incident response to meet regulatory and industry compliance.
Expactations:
- 10+ years IT experience with a Bachelor’s in Computer Science or related field.
- Demonstrated leadership of secure SDLC practices and compliance (PCI DSS, ISO 27001, HIPAA/PHIPA).
- Strong knowledge of secure coding, architecture, and security frameworks (OWASP, NIST).
- Proven experience with cloud platforms (Azure, AWS, Office 365) and secure application development in .NET, Java, PHP, Python.
- Excellent communication, stakeholder management, and audit evidence delivery.
Key Responsibilities:
- Lead and maintain Rexall Secure Development Lifecycle (SDLC) process and secure software development framework.
- Develop and update application security standards, SOPs, and reference architecture for web, mobile, cloud, SaaS, and PaaS deployments.
- Coordinate and manage application risk assessments, penetration testing, and vulnerability remediation (static and dynamic scanning).
- Serve as primary security liaison for new and existing application development projects, ensuring compliance with security policies and regulatory requirements.
- Manage Web Application Firewall, respond to application security incidents, and maintain scanning platforms.
- Collaborate with enterprise architects, integration teams, auditors, and IT to close gaps and support compliance evidence.
- Participate in new system reviews, approvals, and audits, and provide leadership on security architecture recommendations.
Required Skills:
- Secure SDLC, DevOps, and microservices methodology.
- Application authentication, encryption, key management, IAM, OAuth, SAML.
- Secure web and mobile application development practices.
- Penetration testing, static code analysis, dynamic scanning tools.
- Knowledge of PCI DSS, ISO 27001, NIST, and OWASP frameworks.
- Cloud security best practices for Azure, AWS, Office 365.
- HIPAA/PHIPA compliance knowledge.
- Strong interpersonal, customer‑service orientation, and organizational skills.
Required Education & Certifications:
- Bachelor’s degree in Computer Science, Information Technology, or related discipline.
- Practical experience aligned with PCI DSS, ISO 27001, NIST, OWASP, and cloud security standards.