Company Intro 

e-SKY Solutions,  a business unit operating under SEDRACORP inc., is an innovative business technology company, with a current focus on learning solutions and expanding horizons in various industries. We are a Montreal based company, with multiple international teams to support our global customer base.  

Our company is made up of a small agile team, with big dreams and a BIG vision. Our Vision is to change the world by digitizing learning and supporting our clients to reach their business goals.  We operate by a servant leadership model, that creates an internal family-like culture rooted in humility, team work, collaboration and  a winning appetite.  We are in a growing phase and are expanding our team: looking for brilliant minds that are technically savvy and match our culture. 

About the Role

We are seeking an experienced Senior Web & Internet Security Engineer to strengthen the security of our web applications, infrastructure, and cloud environments. The successful candidate will identify security risks, implement security controls, conduct assessments, and work closely with development teams to ensure security is integrated throughout the software development lifecycle.

Responsibilities

  • Design and implement security strategies for web applications and internet-facing systems.
  • Perform web application security assessments and vulnerability testing.
  • Conduct penetration testing and security reviews.
  • Identify, analyze, and remediate security vulnerabilities.
  • Review application architecture for security risks.
  • Collaborate with developers to implement secure coding practices.
  • Monitor and respond to security incidents.
  • Develop and maintain security policies, standards, and best practices.
  • Conduct threat modeling and risk assessments.
  • Implement authentication, authorization, and identity management solutions.
  • Secure APIs, cloud infrastructure, and web services.
  • Stay informed about emerging cybersecurity threats and recommend mitigation strategies.
  • Support compliance initiatives and security audits.
  • Mentor team members on security best practices.

Required Qualifications

  • Bachelor’s degree in Cybersecurity, Computer Science, Information Security, or a related field (or equivalent experience).
  • 5+ years of experience in application security, web security, or cybersecurity.
  • Strong knowledge of web application security principles.
  • Strong understanding of the OWASP Top 10.
  • Experience performing penetration testing and vulnerability assessments.
  • Experience securing REST APIs.
  • Strong knowledge of authentication and authorization technologies, including OAuth 2.0, OpenID Connect, SSO, JWT, and MFA.
  • Experience with HTTPS, TLS, certificates, and encryption.
  • Experience with cloud security (AWS, Azure, or Google Cloud).
  • Familiarity with SIEM, logging, and monitoring tools.
  • Strong understanding of network protocols and web technologies.
  • Excellent analytical and problem-solving skills.
  • Strong written and verbal communication skills.

Preferred Qualifications

  • Industry certifications such as CISSP, CEH, OSCP, Security+, or GIAC.
  • Experience with DevSecOps and CI/CD security.
  • Experience with Kubernetes and container security.
  • Experience with Infrastructure as Code security.
  • Familiarity with SOC 2, ISO 27001, PCI DSS, or GDPR compliance.
  • Experience working in SaaS or cloud-native environments.

Apply for this position

Allowed Type(s): .pdf, .doc, .docx