Querentia®Talent · Trust · Thrive
Cybersecurity

Application Security & Secure SDLC Consultant

Remote · CanadaContract · Remote 2 months ago

Engagement

Contract

Remote

Apply on Ceipal

Quick Apply sends your details straight to our recruiters.

About the role

Job Summary

We are seeking an experienced Application Security & Secure SDLC Consultant to support the design, implementation, and operationalization of a Secure Software Development Lifecycle (SSDLC) program. The ideal candidate will combine application security expertise, governance design, and hands-on security tooling experience to help establish secure development practices and improve software delivery security.

This role will be responsible for defining SSDLC standards, designing governance frameworks, evaluating security tools, and supporting proof-of-value implementations while driving adoption across development and security teams.

Key Responsibilities

Secure SDLC Strategy & Governance

  • Define and establish Secure Software Development Lifecycle (SSDLC) standards, policies, and best practices.
  • Design SSDLC governance frameworks, operating models, and implementation roadmaps.
  • Develop RACI matrices to clearly define ownership, accountability, decision rights, and responsibilities across security and development teams.
  • Create security processes that align with organizational risk management and compliance requirements.

Application Security & Tooling

  • Evaluate, assess, and recommend application security tools including: Static Application Security Testing (SAST)
  • Dynamic Application Security Testing (DAST)
  • Software Composition Analysis (SCA)

DevSecOps & CI/CD Integration

  • Embed security tooling and controls into CI/CD pipelines.
  • Collaborate with engineering teams to implement DevSecOps best practices.
  • Design automated security testing and vulnerability management processes.
  • Ensure secure development practices are integrated throughout the software delivery lifecycle.

Stakeholder Engagement & Adoption

  • Work closely with development, security, architecture, and operations teams to drive SSDLC adoption.
  • Facilitate workshops, presentations, and stakeholder discussions.
  • Provide guidance and training on secure development practices and security tooling.
  • Support organizational change management related to secure development initiatives.

Required Qualifications

  • Strong experience in Application Security and Secure SDLC program design.
  • Expertise in secure software development standards, frameworks, and best practices.
  • Experience developing governance models, operating frameworks, and RACI structures.
  • Hands-on experience evaluating and implementing: SAST tools
  • DAST tools
  • SCA solutions

Preferred Qualifications

  • Experience leading enterprise SSDLC transformation initiatives.
  • Knowledge of cloud-native application security practices.
  • Familiarity with modern DevOps platforms and automation frameworks.
  • Security certifications such as CISSP, CSSLP, GIAC, or equivalent.
  • Experience supporting regulated or large enterprise environments.

Key Skills & Competencies

  • Application Security
  • Secure SDLC (SSDLC)
  • SAST, DAST & SCA Tools
  • DevSecOps & CI/CD Security
  • Security Governance & Operating Models
  • RACI Development & Process Design
  • Security Tool Evaluation & Implementation
  • Vulnerability Management
  • Stakeholder Engagement & Change Adoption
  • Secure Software Development Practices

This engagement is managed end-to-end by Querentia. Our recruiters give you honest feedback at every stage, prepare you for the interview, and support a smooth onboarding once you land the offer.

Skills

Security