Responsibilities
- Review products using source-code, dynamic, dependency, manual code, and security architecture reviews.
- Trace source code to validate scanner findings and provide developer-level remediation recommendations.
- Write, maintain, and refactor Bash and Python scripts to automate scanning and reporting workflows.
- Integrate security scanners with CI pipelines, Google Cloud storage, and reporting mechanisms.
- Explain risk assessments to developers, management, and other stakeholders.
- Contribute to secure coding standards and develop security training for developers.
- Prepare assessment reports and vulnerability descriptions for product owners and developers.
- Support secure architecture design and implementation while ensuring security controls and industry-standard compliance.
- Conduct vulnerability assessments, penetration testing, code reviews, and threat modeling.
- Identify security coverage gaps, recommend improvements, and contribute to initiatives that improve product security posture.
- Monitor emerging product-relevant security threats and vulnerabilities.
- Collaborate with development teams to apply security-by-design practices throughout the product lifecycle.
- Handle time-sensitive and confidential vulnerability reports and support global strategic initiatives.
Requirements
- 5–8 years of experience in security evaluation or analysis, security code reviews, or relevant development.
- Bachelor’s degree in Computer Science, Information Management, Engineering, or a related field, or an equivalent combination of education and work experience.
- Experience with source-code, dynamic, and dependency scanners such as Veracode, Fortify, Sentinel, OWASP dependency, NetSparker, and Qualys.
- Knowledge of C, C#, .NET, Python, JavaScript/TypeScript, XML, JSON, SOAP, and dependency package managers such as npm and NuGet.
- Competency with Linux, Windows, Google Compute Engine, Bash, and Python, with the ability to learn additional programming languages quickly.
- Exceptional written and verbal communication, accuracy, attention to detail, analytical problem-solving, and the ability to manage multiple priorities.
- Security certifications and experience in a technical or engineering high-technology industry are assets.
Benefits
- Flexible hybrid working arrangements with support for in-person and virtual work.
- Home office reimbursement program.
- Baby bonus and parental leave top-up program.
- Online learning and networking opportunities.
- Electric vehicle purchase incentive program.
- Competitive medical and dental benefits.
- Retirement savings program.
- Benefits are offered to full-time permanent employees only; remote work requires a reliable internet connection with at least 50 Mbps download and 10 Mbps upload.
Tech Stack
Categories
About Geotab
Geotab is a global leader in connected vehicle and asset management solutions, with headquarters in Oakville, Ontario and Atlanta, Georgia. Our mission is to make the world safer, more efficient, and sustainable. We leverage advanced data analytics and AI to transform fleet performance and operations, reducing cost and driving efficiency. Backed by top data scientists and engineers, we serve over 55,000 global customers, processing 100 billion data points daily from more than 6 million vehicle subscriptions. Geotab is trusted by Fortune 500 organizations, mid-sized fleets, and the largest public sector fleets in the world, including the US Federal government. Committed to data security and privacy, we hold FIPS 140-3 and FedRAMP authorizations. Our open platform, ecosystem of outstanding partners, and Geotab Marketplace deliver hundreds of fleet-ready third-party solutions. This year, we're celebrating 25 years of innovation. Learn more at www.geotab.com and follow us on LinkedIn or visit Geotab News and Views. GEOTAB and GEOTAB MARKETPLACE are registered trademarks of Geotab Inc. in Canada, the United States and/or other countries.
