Senior Information Security Analyst (Secure Code Review)
Core
Identify and exploit vulnerabilities in applications and infrastructure through secure code reviews and penetration testing to enhance cybersecurity posture.
Role type
Senior Secure Code Reviewer / Penetration Tester
Builds
Secure software and robust security controls for TD Bank Group's retail, wholesale, and investment products
Domain
Financial Services / Application Security
Deliverable
production ML models | product features | dashboards & analysis | research | client delivery | infrastructure | physical/clinical work
Required skills
Secure code review, Penetration testing, Static application security testing (SAST), Vulnerability assessment, Risk analysis, Remediation guidance, Tool development, Threat modeling, OWASP Top 10 knowledge, CWE Top 25 knowledge
Preferred skills
OSCP certification, ServiceNow proficiency
Technologies
Java, C#, PHP, Python, Perl, C/C++, SQL, Burp Suite, Metasploit, Nmap, Skykick, Checkmarx, Appscan Source, Veracode, Coverity, Fortify, SonarQube, ServiceNow
Responsibilities
Analyze source code using automated and manual static analysis tools to identify security vulnerabilities; Conduct comprehensive penetration testing on web, mobile, and network applications; Develop and review custom vulnerability descriptions and remediation content; Train developers on secure coding practices; Mentor team members on assessment delivery; Lead release-based testing and mitigation proposal review processes; Document findings and provide actionable recommendations to improve security posture.
Seniority
Senior, hands-on IC