Senior Application Security Engineer

2 days ago


Toronto, Ontario, Canada Glassdoor Full time
About the Role

We are seeking a highly skilled Sr Application Security Engineer to join our team at Glassdoor. As a key member of our security team, you will play a critical role in improving our application security posture and ensuring the safety of our platform for millions of users worldwide.

As a Sr Application Security Engineer, you will be responsible for analyzing, testing, and triaging application vulnerabilities, managing our public bug bounty program, participating in code and product security reviews, and helping our Developers bake security into their day-to-day workflows and CICD. You will partner closely with our Product and Engineering teams, our vendors, and external testers, so solid interpersonal skills are a must.

Key Responsibilities
  • Advocate for application security within the organization
  • Develop and maintain a risk-based application security program based on a well-defined application security framework
  • Enhance and manage Glassdoor's public bug bounty program, application security tool stack, and automated security checks in the CICD pipeline to optimize vulnerability and misconfiguration detection
  • Find common patterns and themes within application vulnerabilities and work with Engineering teams to address the root causes
  • Participate in strategic decisions related to the requirements, design, implementation, and operations of application security framework, processes, and technology
  • Execute security-focused code, architecture, and integration reviews
  • Coordinate or conduct penetration testing and drive remediation efforts to completion
  • Stay up-to-date with the latest security issues and technologies
  • Own and improve process and procedural documentation
  • Participate in on-call rotation (nights and weekends) for Security Operations alert response
  • Assist with daily activities and functions of the Security team (including alert & incident response) to maintain security posture as well as policy and compliance commitments
Requirements
  • 5+ years of experience in web application penetration testing or a security-focused application development role
  • AWS Security, CISSP, CEH, GWEB, GCIH, or equivalent certifications are preferred
  • Deep knowledge and familiarity with Cybersecurity Framework, including NIST 800-53, NIST CSF, CIS Top 20, MITRE ATT&CK, and OWASP Top Ten
  • Deep knowledge of crypto, authentication, and authorization protocols and standards, including SSL/TLS, SAML, OAuth, JWT Tokens
  • Ability to automate repetitive tasks using Python or other scripting language
  • Ability to work in a diverse, fast-paced environment and effectively collaborate across teams
  • Outstanding written and oral communication skills with demonstrated ability to clearly articulate to both a technical and functional audience
What We Offer
  • Base salary range: CAD $92,000.00 - $115,000.00
  • Open Paid Time Off policy, in addition to 15-20 paid company holidays/year
  • Flexible hours and a where-to-work policy
  • Opportunities for growth and professional development
  • A diverse and inclusive work environment

Glassdoor is an equal opportunity employer committed to creating a community of inclusion and an environment free from discrimination, harassment, and retaliation. We welcome applications from diverse candidates and are an affirmative action employer.



  • Toronto, Ontario, Canada Amazon Development Centre Canada ULC Full time

    About the RoleWe are seeking a highly skilled Senior AWS Application Security Engineer to join our team at Amazon Development Centre Canada ULC. As a key member of our AWS Security team, you will play a critical role in ensuring the security and integrity of our cloud-based services.Key ResponsibilitiesConduct thorough security reviews of AWS applications...


  • Toronto, Ontario, Canada Amazon Development Centre Canada ULC Full time

    About the RoleWe are seeking a highly skilled Senior AWS Application Security Engineer to join our team at Amazon Development Centre Canada ULC. As a key member of our AWS Security team, you will play a critical role in ensuring the security and integrity of our cloud-based services.Key ResponsibilitiesConduct thorough security reviews of AWS applications...


  • Toronto, Ontario, Canada Amazon Development Centre Canada ULC Full time

    About the RoleWe are seeking a highly skilled Senior AWS Application Security Engineer to join our team at Amazon Development Centre Canada ULC. As a key member of our AWS Security team, you will play a critical role in ensuring the security and integrity of our cloud-based applications and services.Key ResponsibilitiesConduct thorough security reviews of...


  • Toronto, Ontario, Canada Amazon Development Centre Canada ULC Full time

    About the RoleWe are seeking a highly skilled Senior AWS Application Security Engineer to join our team at Amazon Development Centre Canada ULC. As a key member of our AWS Security team, you will play a critical role in ensuring the security and integrity of our cloud-based applications and services.Key ResponsibilitiesConduct thorough security reviews of...


  • Toronto, Ontario, Canada TD Full time

    Job Title: Senior Security EngineerWe are seeking a highly skilled Senior Security Engineer to join our team at TD. As a Senior Security Engineer, you will be responsible for designing and implementing secure solutions to protect our systems and data.Key Responsibilities:Design and implement secure solutions to protect our systems and dataCollaborate with...


  • Toronto, Ontario, Canada TD Full time

    Job Title: Senior Security EngineerWe are seeking a highly skilled Senior Security Engineer to join our team at TD. As a Senior Security Engineer, you will be responsible for designing and implementing secure solutions to protect our systems and data.Key Responsibilities:Design and implement secure solutions to protect our systems and dataCollaborate with...


  • Toronto, Ontario, Canada Robinhood Full time

    **Senior Security Engineer Wanted for Fintech Company** Join a leading fintech company that's democratizing finance for all. We're seeking a Senior Security Engineer to help shape our vision, structures, and systems. **About the Company** Robinhood Markets was founded on a simple idea: that our financial markets should be accessible to all. With customers...


  • Toronto, Ontario, Canada The Toronto-Dominion Bank (Canada) Full time

    About This RoleWe are seeking a seasoned Senior Engineer to join our team as a Security Logging and Monitoring Specialist. As a key member of our security team, you will be responsible for managing the bank's cyber security logging and monitoring systems, providing technical guidance and direction.Key ResponsibilitiesProvide technical guidance and direction...


  • Toronto, Ontario, Canada The Toronto-Dominion Bank (Canada) Full time

    About This RoleWe are seeking a seasoned Senior Engineer to join our team as a Security Logging and Monitoring Specialist. As a key member of our security team, you will be responsible for managing the bank's cyber security logging and monitoring systems, providing technical guidance and direction.Key ResponsibilitiesProvide technical guidance and direction...


  • Toronto, Ontario, Canada TD Full time

    Job Title: Senior Security EngineerWe are seeking an experienced Senior Security Engineer to join our team at TD. As a Senior Security Engineer, you will be responsible for designing and building technical solutions that adhere to engineering and architectural design principles while meeting business requirements.Key Responsibilities:Configure, develop,...


  • Toronto, Ontario, Canada TD Full time

    Job Title: Senior Security EngineerWe are seeking an experienced Senior Security Engineer to join our team at TD. As a Senior Security Engineer, you will be responsible for designing and building technical solutions that adhere to engineering and architectural design principles while meeting business requirements.Key Responsibilities:Configure, develop,...


  • Toronto, Ontario, Canada TD Full time

    Job Title: Senior Security EngineerWe are seeking an experienced Senior Security Engineer to join our team at TD. As a Senior Security Engineer, you will be responsible for designing and building technical solutions that adhere to engineering and architectural design principles while meeting business requirements.Key Responsibilities:Configure, develop,...


  • Toronto, Ontario, Canada TD Full time

    Job Title: Senior Security EngineerWe are seeking an experienced Senior Security Engineer to join our team at TD. As a Senior Security Engineer, you will be responsible for designing and building technical solutions that adhere to engineering and architectural design principles while meeting business requirements.Key Responsibilities:Configure, develop,...


  • Old Toronto, Ontario, Canada Sonrai Security Full time

    Cloud Security Engineer OpportunitySonrai Security is a world-class team modernizing the cloud security industry. We're looking for a cloud engineer to develop core pieces of our innovative platform.Key Responsibilities:Part of a small agile development team.Working with senior engineers building core pieces of the Sonrai Cloud Platform.Implementation,...


  • Old Toronto, Ontario, Canada Sonrai Security Full time

    Cloud Security Engineer OpportunitySonrai Security is a world-class team modernizing the cloud security industry. We're looking for a cloud engineer to develop core pieces of our innovative platform.Key Responsibilities:Part of a small agile development team.Working with senior engineers building core pieces of the Sonrai Cloud Platform.Implementation,...


  • Old Toronto, Ontario, Canada Glassdoor Full time

    About the RoleWe are seeking a highly skilled Sr Application Security Engineer to join our team at Glassdoor. As a key member of our security team, you will play a critical role in improving our application security posture and ensuring the safety of our platform for millions of users worldwide.As a Sr Application Security Engineer, you will be responsible...


  • Old Toronto, Ontario, Canada Glassdoor Full time

    About the RoleWe are seeking a highly skilled Sr Application Security Engineer to join our team at Glassdoor. As a key member of our security team, you will play a critical role in improving our application security posture and ensuring the safety of our platform for millions of users worldwide.As a Sr Application Security Engineer, you will be responsible...


  • Toronto, Ontario, Canada Amazon Development Centre Canada ULC Full time

    About the RoleWe are seeking a highly skilled Senior Cloud Security Engineer to join our team at Amazon Development Centre Canada ULC. As a Senior Cloud Security Engineer, you will play a critical role in ensuring the security and integrity of our cloud-based services and applications.Key ResponsibilitiesConduct thorough security reviews of cloud-based...


  • Toronto, Ontario, Canada Amazon Development Centre Canada ULC Full time

    About the RoleWe are seeking a highly skilled Senior Cloud Security Engineer to join our team at Amazon Development Centre Canada ULC. As a Senior Cloud Security Engineer, you will play a critical role in ensuring the security and integrity of our cloud-based services and applications.Key ResponsibilitiesConduct thorough security reviews of cloud-based...


  • Toronto, Ontario, Canada Glassdoor Full time

    About the RoleWe are seeking a highly skilled Application Security Engineer to join our team at Glassdoor. As a key member of our security team, you will be responsible for improving our application security posture and keeping our platform safe for millions of customers around the world.Key ResponsibilitiesImprove Glassdoor's application security posture...