Application Security Lead ensuring high security standards for Canon's projects and applications. Leading discussions, designs, and testing throughout the IT lifecycle.
Responsibilities
Act as the security representative within project streams for new and upcoming initiatives, translating security policies into risk controls for new and existing projects.
Conduct security architecture and design reviews.
Support project and development teams with relevant security knowledge
Assist with the implementation of security design principles.
Guide development and project teams in the remediation of identified security deficiencies.
Support the planning and execution of application pentests, and the follow-up of remediation measures.
Be accountable to business and IT for the planning and execution of application pentests, and the follow-up of remediation measures.
Recommend and assist in the implementation of security controls in the SDLC of supported applications.
Manage the technical security auditing process within Canon’s internal IT transformation program as well as Canon’s B2C program and ensure auditing follow up and mitigation actions.
Manage risks for the area for which they are responsible for and ensure that the overall risk in the portfolio is known and decreasing.
Be visible in the information security industry, by participating in industry events, driving Canon’s vision to be a thought leader in information security
Requirements
Significant working experience in a technical capacity in a Security or IT department, preferably across multiple security domains.
Demonstrable experience in performing security assessments and security design reviews.
In-depth security knowledge for cloud platforms, mainly Azure and AWS.
Experience in software development and Application Security.
Knowledge and expertise in secure software development lifecycle (SSDLC) is highly desirable.
Ability to understand, follow up and progress mitigation activities for security auditing reports, penetration testing reports and/or configuration reviews.
Good stakeholder management and communication skills.
Experience working in large international organizations and in handling large enterprise projects is a plus.
Attention to detail.
Ability to work independently and as part of a team.
A continuous learning mindset, to stay up to date with the latest developments in the industry.
Degrees and certifications are welcome, but are not required.
Specific security & IT skills:
Secure Architecture and Design principles
Pentesting tools and techniques
Threat Modelling
Secure coding for common languages and platforms
Security frameworks, such as OWASP, NIST CSF, CIS etc.
Understanding of EU and international compliance requirements, such as GDPR, PCI-DSS, CRA etc.
Containers and serverless technologies
Benefits
Performance-Based Bonus of 12.5%
31 Days of Annual Holiday: Enjoy a healthy work-life balance with plenty of time to recharge.
Pension Plan: Secure your future with our comprehensive pension scheme.
Bicycle Plan: Save on transportation costs while staying active and eco-friendly.
Hybrid Working: Flexibility to work 3 days in the office and 2 days from home.
Commuting: Full coverage of public transport costs or partial reimbursement for car expenses (if you commute by car).
Exclusive Discounts: Up to 40% off on Canon products.
Free On-Site Parking: Convenient parking spaces available for those who drive to work.
Teaching and research role in Cybersecurity and AI at De Vinci School. Engaging in course design and research projects in a collaborative academic environment.
Apprentice Fire and Security Engineer installing, commissioning, and maintaining electronic protection systems for Johnson Controls. Collaborating in a team - based environment and gaining hands - on experience in fire and security technology.
Construction Site Superintendent overseeing construction projects for Johnson Controls, ensuring timely completion and adherence to project scope, budget, and schedule. Collaborating with teams and managing site activities in the United States.
Senior Security Architect providing security consulting and risk assessment at The Missing Link. Leading initiatives in security architecture and technology risk support within a hybrid work environment.
Data Protection Security Engineer at Fiserv designing, implementing, and maintaining cybersecurity solutions. Collaborating with teams to safeguard client information and ensure regulatory compliance.
Senior Manager IAM Metric Insights managing metrics and performance in Identity and Access Management. Delivering insights and reporting to enhance security posture for RBC's Global Security team.
HSE Technician I in TechnipFMC's HSE team promoting and supporting an HSE culture. Assisting with investigations, conducting audits, and maintaining safety documentation.
Information Security Officer creating security policies and managing security teams to protect Paytient. Collaborating with internal and external teams to ensure compliance and security posture.
Supplier Manager focused on Microsoft Security products at Arrow. Develops strategies to enhance sales and market share while collaborating with Microsoft and sales teams.
IT Infrastructure and Security Administrator at B&O Bau, managing IT security and infrastructure. Collaborating on innovative projects across multiple German locations.