Senior Application Security Engineer

3 days ago


Old Toronto, Canada Relay Financial Full time

Relay Financial Relay (Relay Financial), is an all-in-one business banking and money management platform helping businesses understand what they're earning, spending & saving.

View company page

Our mission is to increase the success rate of small businesses. Traditional banking has been a growth limiter rather than a growth enabler for business owners, and we’re changing that. Relay is the all-in-one, collaborative money management platform. We’re building for employer SMBs and their finance function, internal and external, and are focused on delivering a human-centric customer experience. Ultimately, we help SMBs be ‘on the money'.
Relay is entering an exciting new chapter of growth and we’re looking for a Senior Application Security Engineer to join our Trust team. Your love of making and contributing to high-impact decisions daily and desire to help shape the future of Relay is going to be crucial. The team’s vision is “Protecting the cathedral while enabling the bazaar” - quite a challenge in a fintech business. This is an opportunity to get in at ground level and help evolve our security posture as we grow.
Our Senior Application Security Engineer will be required to work from our downtown Toronto office (2-days per week).What You'll Be Doing

  • Collaborate with stakeholders across the organization to drive application security maturity
  • Perform application security testing, code reviews, to identify and evaluate security vulnerabilities in applications, APIs
  • Establish secure software development practices that make security an important piece of the SDLC pie
  • Build security tooling and automations to scale the engineering team’s security practices
  • Develop and maintain application security standards and provide guidance to software engineering teams
  • Participate in incident response activities as needed including supporting engineering teams incident remediation efforts
  • Perform threat modeling and security architecture reviews to identify potential security risks and integrate security early in the development process.
  • Be actively involved in Relay’s application security vulnerability management program, triaging and prioritizing vulnerabilities from application security tooling, vulnerability disclosure program, manual testing results
  • Champion developer education initiatives on all things application security, while being an advocate for all things AppSec and Security at Relay. Tell us how you would reduce risk
Who You Are
  • You have 5+ years of experience in Application Security engineering, application security penetration testing, developing and implementing changes. We are looking for builders: incremental changes or major initiatives.
  • You're familiar with our tech stack: Node.js , GitHub (repositories and actions), AWS, HackerOne.
  • You are experienced with programming languages such as JavaScript, Python, etc.
  • You have a deep understanding of application security concepts.
  • You have done some presentations about security subjects/participated in CTFs
  • You're automation-driven. Think small teams, high impact: tell us how to leverage systems to accelerate our velocity.
  • You're self driven to improve security across the core product of the organization
  • You're curious. The AppSec and security landscape isn’t static, and neither should you be
  • You're a team player. Our team is small and mighty, and we collaborate constantly - we want someone who is always willing to pitch in and isn’t afraid to ask for help.
Bonus Points
  • Show us your home lab We have Ubiquity gears everywhere and we like to geek-out on our k8s clusters that control in-house experience. Show us CVE, conference talks, etc.
  • Even when it seems impossible to identify security vulnerabilities, you understand and persevere knowing there is something lurking
  • You’ve joined a company at its early stages and have seen it through scale
  • You have experience working in a fintech startup
    Research shows that women-identifying and other marginalized individuals tend to only apply when they meet 100% of the qualifications; if you don't have all the listed qualifications, we encourage you to apply anyway
Our Commitment To You
  • Competitive salary and meaningful equity: every team member gets a piece of the pie.
  • Comprehensive health benefits: we offer full health benefits + an HSA/WSA starting from day 1 so you get the coverage you need.
  • Considerable vacation/end-of-year holiday shutdown: we take time off to reset and recharge so we come back better for our customers.
  • Hybrid work environment: we love collaborating and connecting in the office two times a week and offer catered lunches and a snack/beverage program for the days we’re in office. Don’t forget to bring in your furry friends
  • Personal and professional growth: support from leaders who care about your growth and success through regular feedback and coaching. Our goal is to make Relay a step-change career opportunity.
  • Top-tier equipment: we’ll make sure you have everything you need to produce your best work.
  • Team-first culture: we’re passionate about working collaboratively, bonding through team events, and most importantly having fun.
The Interview Process
  • Stage 1: A 30-minute Google Meett video call with a member of the Talent Team
  • Stage 2: A 45-minute experience deep dive interview with the Engineering Manager, Application Security
  • Stage 3: A 1-hour Google Meet case study presentation with a member of the trust team and the engineering team
  • Stage 4: A 30-minute Google Meet video call with a member of the executive team at Relay Financial
What’s Important to Us
At Relay, we believe that diversity is key to building high-performing teams, and creating an inclusive work environment is our priority. We are an equal-opportunity employer and we welcome people of diverse backgrounds, perspectives, and skills.
We will work with applicants to provide accommodations at any stage of the hiring process. If you require accommodations during the interview process, please email your People Team contact, and we will work with you to meet your needs.
Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.

#J-18808-Ljbffr

  • Old Toronto, Canada Relay Financial Full time

    Our mission is to increase the success rate of small businesses. Traditional banking has been a growth limiter rather than a growth enabler for business owners, and we’re changing that. Relay is the all-in-one, collaborative money management platform. We’re building for employer SMBs and their finance function, internal and external, and are focused on...


  • Old Toronto, Canada Relay Financial Full time

    Our mission is to increase the success rate of small businesses. Traditional banking has been a growth limiter rather than a growth enabler for business owners, and we’re changing that. Relay is the all-in-one, collaborative money management platform. We’re building for employer SMBs and their finance function, internal and external, and are focused on...


  • Old Toronto, Ontario, Canada Security Bank & Trust Co. Full time

    Location: Toronto, Canada; (Remote from Toronto)The RoleTuneIn, a leading provider of audio streaming services, is seeking an experienced Senior Security Engineer to join our CloudOps team. The CloudOps team plays a pivotal role in the management of production tools such as AWS, CloudFlare, and GitHub self-hosted runners. This role will be instrumental in...


  • Old Toronto, Canada LZ Security & Service GmbH Full time

    Location: Toronto, Canada; (Remote from Toronto)The RoleTuneIn, a leading provider of audio streaming services, is seeking an experienced Senior Security Engineer to join our CloudOps team. The CloudOps team plays a pivotal role in the management of production tools such as AWS, CloudFlare, and GitHub self-hosted runners. This role will be instrumental in...


  • Old Toronto, Canada Security Bank & Trust Co. Full time

    Location: Toronto, Canada; (Remote from Toronto)The RoleTuneIn, a leading provider of audio streaming services, is seeking an experienced Senior Security Engineer to join our CloudOps team. The CloudOps team plays a pivotal role in the management of production tools such as AWS, CloudFlare, and GitHub self-hosted runners. This role will be instrumental in...


  • Old Toronto, Ontario, Canada CadMakers Full time

    We are looking to hire an adaptable Senior Network Security Application Officer to join our cohesive team at CadMakers in Burnaby, British Columbia, Canada.Growing your career as a hybrid Senior Network Security Application Officer is a great opportunity to develop competitive skills.If you are strong in time management, innovation and have the right...


  • Old Toronto, Ontario, Canada CadMakers Full time

    We are desiring to recruit a driven Senior Network Security Application Officer to join our cohesive team at CadMakers in Burnaby, British Columbia, Canada.Growing your career as a hybrid Senior Network Security Application Officer is an outstanding opportunity to develop necessary skills.If you are strong in critical thinking, emotional intelligence and...


  • Old Toronto, Canada Practice Better Full time

    Job Title: Senior Security Engineer Location: Candidate must be located in Canada or the USA. Our office is located in Toronto, ON, Canada, but the role is remote/hybrid/flexible. Reports to: VP, Engineering, Product, Design, Security and IT Position Overview: Practice Better is a leading modern health and wellness management platform dedicated to providing...


  • Old Toronto, Canada Practice Better Full time

    Job Title: Senior Security Engineer Location: Candidate must be located in Canada or the USA. Our office is located in Toronto, ON, Canada, but the role is remote/hybrid/flexible. Reports to: VP, Engineering, Product, Design, Security and IT Position Overview: Practice Better is a leading modern health and wellness management platform dedicated to providing...


  • Old Toronto, Ontario, Canada Practice Better Full time

    Job Title: Senior Security EngineerLocation: Candidate must be located in Canada or the USA. Our office is located in Toronto, ON, Canada, but the role is remote/hybrid/flexible.Reports to: VP, Engineering, Product, Design, Security and ITPosition Overview:Practice Better is a leading modern health and wellness management platform dedicated to providing...


  • Old Toronto, Canada Robinhood Full time

    About the team + role Robinhood is looking for an Application Security Engineering Manager who is passionate about enabling the firm to build and deploy secure applications. A successful Application Security manager will possess a deep understanding of both information security and software engineering and have experience leading a team of engineers from...


  • Old Toronto, Canada Robinhood Full time

    About the team + role Robinhood is looking for an Application Security Engineering Manager who is passionate about enabling the firm to build and deploy secure applications. A successful Application Security manager will possess a deep understanding of both information security and software engineering and have experience leading a team of engineers from...


  • Old Toronto, Canada Scotiabank Full time

    Press Tab to Move to Skip to Content Link Select how often (in days) to receive an alert: Select how often (in days) to receive an alert: Please be advised that our Careers site will be unavailable from November 28 at 12am ET to November 29 12am ET for scheduled system maintenance. Title: Senior Cloud Security Engineer Requisition ID:...


  • Old Toronto, Canada Robinhood Full time

    Robinhood Trade 30+ crypto at the lowest cost on average in the EU. Sign up today and get a reward of up to 1 BTC. View company page Join a leading fintech company that’s democratizing finance for all.Robinhood was founded on a simple idea: that our financial markets should be accessible to all. With customers at the heart of our decisions, Robinhood...


  • Toronto, Canada Abnormal Security] Full time

    Job Description:Job Description About the Role Abnormal Security is looking for a Software Engineer II who is a solid software developer with a strong interest in Security & Privacy to join the Platform Security team. The Platform Security team owns the Security and Privacy platform services and infrastructure to uphold industry standards for the company's...


  • Toronto, Canada Abnormal Security] Full time

    Job Description:Job Description About the Role Abnormal Security is looking for a Software Engineer II who is a solid software developer with a strong interest in Security & Privacy to join the Platform Security team. The Platform Security team owns the Security and Privacy platform services and infrastructure to uphold industry standards for the company's...


  • Toronto, Ontario, Canada Abnormal Security] Full time

    Job Description:Job Description About the Role Abnormal Security is looking for a Software Engineer II who is a solid software developer with a strong interest in Security & Privacy to join the Platform Security team. The Platform Security team owns the Security and Privacy platform services and infrastructure to uphold industry standards for the company's...


  • Old Toronto, Canada Scotiabank Full time

    Press Tab to Move to Skip to Content Link Select how often (in days) to receive an alert: Requisition ID: 193495Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture. The Team Scotiabank’s Cloud Security Engineering Team is responsible for leading security engineering and...


  • Old Toronto, Canada CadMakers Full time

    We are hiring an organized Senior Network Security Application Officer to join our elite team at CadMakers in Burnaby, British Columbia, Canada.Growing your career as a hybrid Senior Network Security Application Officer is an incredible opportunity to develop relevant skills.If you are strong in adaptability, planning and have the right attitude for the job,...


  • Old Toronto, Canada CadMakers Full time

    We are looking to hire an adaptable Senior Network Security Application Officer to join our cohesive team at CadMakers in Burnaby, British Columbia, Canada.Growing your career as a hybrid Senior Network Security Application Officer is a great opportunity to develop competitive skills.If you are strong in time management, innovation and have the right...