Director, Application Security and Vulnerability Management
L’utilisation du masculin à pour but d’alléger le texte
Venez faire votre différence dans les communautés à travers le Canada, où l'authenticité, la confiance et l'établissement de liens sont valorisés - alors que nous façonnons l'avenir du commerce de détail au Canada, ensemble. Notre position unique en tant que l'un des plus grands employeurs du pays, celle associée à notre engagement à avoir un impact positif sur la vie de tous les Canadiens, viens offrir à nos collègues une gamme d'opportunités et d'expériences pour aider les Canadiens à Vivre Bien, Vivre Pleinement.
Chez Les Compagnies Loblaw Limitée, nous réussissons grâce à la collaboration, à l'engagement et nous plaçons la barre haute pour nous-mêmes et ceux qui nous entourent. Que vous débutiez votre carrière, que vous réintégriez le marché du travail ou que vous recherchiez un nouvel emploi, votre place est avec nous.
Come make your difference in communities across Canada, where authenticity, trust and making connections are valued - as we shape the future of Canadian retail, together. Our unique position as one of the country's largest employers, coupled with our commitment to positively impact the lives of all Canadians, provides our colleagues a range of opportunities and experiences to help Canadians Live Life Well®.
At Loblaw Companies Limited, we succeed through collaboration and commitment and set a high bar for ourselves and those around us. Whether you are just starting your career, re-entering the workforce, or looking for a new challenge, this is where you belong.
Does leading application security and vulnerability management across one of Canada's largest and most complex technology ecosystems excite you? Loblaw Technology supports corporate offices, stores, pharmacies, distribution centres, digital commerce, SaaS platforms, APIs, and multi-cloud environments. This role will lead the strategy, engineering, and operating model that helps teams build secure software and remediate risk at enterprise scale.
Come lead a team that values diverse ideas, embeds practical security into engineering workflows, and develops our talent from within. You will help modernize application security and vulnerability management, enable secure innovation, and make a measurable difference to customers, colleagues, and business operations.
What You'll Do
- Lead Loblaw's enterprise Application Security and Vulnerability Management strategy, architecture, engineering, and operations across applications, APIs, cloud workloads, endpoints, servers, containers, and infrastructure.
- Own the secure SDLC and DevSecOps control model, integrating SAST, DAST, SCA, API security, secret detection, container scanning, and infrastructure-as-code scanning into GitLab Ultimate and enterprise CI/CD workflows.
- Establish risk-based security gates at commit, merge, build, test, and release stages, with clear thresholds, exception governance, developer guidance, and remediation requirements.
- Build an application-level DAST and API Security coverage model that maps business applications to repositories, microservices, deployed URLs, environments, API specifications, authentication flows, and accountable owners.
- Lead the enterprise vulnerability management lifecycle, including asset discovery, scan coverage, validation, deduplication, risk prioritization, remediation service levels, exceptions, retesting, and verified closure.
- Create a unified exposure view that connects vulnerabilities to internet exposure, attack paths, identities, business services, and asset criticality, giving engineering teams and executives clear, actionable risk information.
- Own the roadmap and reliable operation of platforms such as GitLab Ultimate, Cortex Cloud / Prisma Cloud, Qualys, API security, attack surface management, and exposure management capabilities.
- Establish security patterns for AI-enabled software, generative AI, models, agents, and AI-assisted development; address prompt injection, sensitive-data leakage, insecure tool use, and model or agent supply-chain risk.
- Partner with product, development, SRE, cloud, infrastructure, identity, network, data, privacy, SOC, risk, and audit teams to threat model designs, remediate vulnerabilities, respond to events, and provide control evidence.
- Lead and develop application security engineers, vulnerability analysts, product owners, and platform specialists; manage budgets, vendors, services, roadmaps, automation, runbooks, succession, and two-deep coverage.
What You'll Bring
- Proven progressive experience in application security, product security, vulnerability management, cloud security, DevSecOps, or cybersecurity engineering, including leading technical teams or major programs.
- Demonstrated success leading application security and vulnerability management in a large, complex enterprise, ideally within retail, healthcare, financial services, telecommunications, or another regulated environment.
- Deep expertise in secure SDLC and DevSecOps, including threat modeling, SAST, DAST, SCA, API security, secret detection, container and Kubernetes security, infrastructure-as-code scanning, and CI/CD controls.
- Proven experience operating enterprise vulnerability management, including asset and scan governance, finding validation, risk prioritization, remediation SLAs, exceptions, retesting, and executive reporting.
- Strong understanding of application and API architectures, microservices, authentication flows, cloud-native services, containers, serverless platforms, and software supply-chain risk across AWS, Azure, GCP, and OCI.
- Experience with platforms such as GitLab Ultimate, Qualys, Cortex Cloud / Prisma Cloud, Veracode, Invicti, Snyk, Checkmarx, API security, attack surface management, or exposure management tools.
- Experience securing AI/ML, generative AI and agentic applications, AI code assistants, and model or agent supply chains, including prompt injection, data leakage, insecure tool use, and vulnerable dependencies.
- Ability to apply CVE, CWE, CVSS, EPSS, known-exploited vulnerability data, threat intelligence, asset criticality, and attack-path context to focus remediation on the risks that matter most.
- Excellent executive communication, stakeholder, financial, and vendor leadership skills, with the ability to translate technical exposure into clear decisions and accountable remediation plans.
- Bachelor's or Master's degree in Computer Science, Software Engineering, Information Security, Engineering, or a related field. CISSP, CSSLP, CISM, CCSP, GIAC GWEB/GWAPT, OSWE, cloud security, or GitLab credentials are strong assets.
What Loblaw Offers You
We offer flexibility and balance, and an environment that sets you up for success no matter where your workspace is located.
Here, you will find a great team to help you achieve your goals as you help us achieve ours!
Work in our fast-paced, exciting Technology environment, helping our stores, colleagues, and customers every day.
Loblaw colleagues also enjoy:
- Work Perks Program
- On-site GoodLife Fitness, Basketball & Volleyball courts, Ice Rink
- Groceries delivered to work via PC Express, Dry Cleaning services (1PCC Office)
- Tuition Reimbursement & Online Learning
- Pension & Benefits
- Paid Vacation
Loblaw recognizes Canada's diversity as a source of national pride and strength. We have made it a priority to reflect our nation's evolving diversity in the products we sell, the people we hire, and the culture we create in our organization. At Loblaw, we celebrate diversity and strive to build a culture of inclusion where differences are embraced, valued, and supported.
We are committed to being an equal opportunity employer and encourage people from all backgrounds and identities to apply. Accommodation in the recruitment, assessment, and hiring process is available upon request for applicants with disabilities.
We thank all candidates for their interest, but please note, only those who meet the minimum requirements will be contacted.
www.Loblaw.ca/careers
Our commitment to Sustainability and Social Impact is integral to how we do business. Our CORE Values - Care, Ownership, Respect, and Excellence - guide our decisions and come to life through our Blue Culture.
Notre engagement envers la durabilité et l'impact social est un élément essentiel de notre façon de faire des affaires. Nous concentrons notre attention sur les domaines où nous pouvons avoir le plus grand impact. Notre approche de la durabilité et de l'impact social repose sur trois piliers - l'environnement, l'approvisionnement et la communauté. Nous recherchons constamment des moyens de faire preuve de leadership dans ces domaines importants. Nos valeurs ÊTRE – Engagement, Tient à coeur, Respect et Excellence – guident toutes nos prises de décision et prennent vie à travers notre culture bleue. Nous offrons à nos collègues des carrières progressives, une formation complète, de la flexibilité ainsi que les nombreux avantages compétitifs - voici quelques-unes des nombreuses raisons pour lesquelles nous sommes classés au palmarès des meilleurs employeurs du Canada, au palmarès des meilleurs employeurs pour la diversité au Canada, au palmarès des employeurs les plus verts au Canada et au palmarès des meilleurs employeurs pour les jeunes au Canada.
Si vous ne savez pas si votre expérience correspond à toutes les exigences ci-dessus, nous vous encourageons à postuler quand même. Nous recherchons des perspectives de candidatures variées, qui incluent des expériences diverses que nous pouvons ajouter à notre équipe.
Nous nous concentrons depuis longtemps sur la diversité, l'équité et l'inclusion, car nous savons que cela fera de notre entreprise un meilleur lieu de travail et de magasinage. Nous nous engageons à créer des environnements accessibles pour nos collègues, candidats et clients. Les demandes d'aménagement en raison d'un handicap (qui peut être visible ou pas, temporaire ou permanent) peuvent être faites à n'importe quel stade de la demande et de l'emploi. Nous encourageons les candidats à faire connaître leurs besoins en matière d'accommodation afin que nous puissions offrir des opportunités équitables.
Veuillez noter:
Les candidats âgés de 18 ans ou plus doivent effectuer une vérification des antécédents criminels. Les détails seront fournis lors du processus d’embauche.
#FR
#SS #LTnA #ON