Senior Application Security Engineer
About the Role
You will embed security principles into the software development lifecycle and partner with engineering to build secure systems. You will perform code reviews, vulnerability assessments, and penetration tests, integrate security tooling into CI/CD, lead threat modeling, triage vulnerabilities, automate security tests, and assist in application security incident response.
Requirements
- 7+ years of professional experience in application security, product security, or offensive security
- Deep understanding of common application vulnerabilities (OWASP Top 10) and mitigations
- Proficiency reading and auditing code in Python, Go, or JavaScript/TypeScript
- Hands-on experience with SAST, DAST, IAST, and SCA tools
- Understanding of cloud security for GCP and AWS
- Experience with containerized services including Docker and Kubernetes
- Proven experience integrating security into the SDLC
- Strong analytical, problem-solving, and incident response skills
- Excellent communication and interpersonal skills
Responsibilities
- Perform security code reviews
- Perform vulnerability assessments
- Perform penetration tests on web applications, mobile applications, and APIs
- Integrate and manage security tools in CI/CD pipelines (SAST, DAST, SCA)
- Lead and conduct threat modeling for new features and services
- Triage, validate, and prioritize discovered vulnerabilities
- Collaborate with engineering and product teams to design secure solutions
- Develop and maintain security standards and documentation
- Manage security training for developers on secure coding practices
- Develop custom scripts and automation to enhance security testing
- Assist in incident response activities related to application security
Benefits
- Generous compensation in cash and equity
- Early exercise for all options, including pre-vested
- Work from anywhere (remote-first)
- Flexible paid time off, year-end break, self care days off
- Health, dental, and vision coverage for employees and dependents (US and Canada)
- 4% matching in 401k / RRSP (US and Canada)
- MacBook Pro provided
- One-time home office setup stipend
- Monthly meal stipend
- Monthly social meet-up stipend
- Annual health and wellness stipend
- Annual learning stipend
- Unlimited access to expert financial advisory
