Senior Application Security Engineer
21 hours ago
Clio is the global leader in legal AI technology, empowering legal professionals and law firms of every size to work smarter, faster, and more securely.
We are transforming the legal experience for all by bettering the lives of legal professionals while increasing access to justice.
Summary:What your team does:
We are currently seeking a Senior Application Security Engineer to join our rapidly growing Security team. The Application Security team is responsible for emulating real-world adversaries to proactively discover, exploit, and help remediate critical security vulnerabilities across our applications. We provide an essential adversarial perspective, challenging our defences and partnering with development teams to eliminate flaws before they can be abused.
This role is for someone who is passionate about building innovative solutions and being exposed to new challenges and technologies while making an impact. This role can be performed from one of our Canadian offices, remotely across Canada, or a combination of both. Some exceptions may apply.
Write, review, debug, and implement tools to help developers avoid security flaws;
Build partnerships with development teams and advise on security best practices;
Contribute to collective developer education by driving security awareness and knowledge amongst the product organization;
Provide detailed guidance and support to teams in vulnerability remediation, and develop frameworks, guidelines, and systematic fixes for recurring vulnerabilities;
Resolve issues, navigate ambiguity, and maintain positive working relationships with researchers in our Bug Bounty program;
Identify and implement tools for automated application scanning, static analysis and related tools;
Perform penetration testing, and offensive campaigns against internal assets;
Perform reactive incident response and forensics when a security event occurs;
Perform proactive research to detect new attack vectors;
Elevate and educate our security culture within Clio, contributing to our cultural values;
Experience in Application Security, with a strong focus on offensive security and penetration testing
hands-on expertise identifying and exploiting complex vulnerabilities (e.g., SSRF, Deserialization, logic bypasses)
Proven ability to lead and conduct formal threat modeling sessions
Strong proficiency in at least one major programming language (e.g., Python, .NET, JavaScript)
Experience securing applications in modern cloud environments (AWS, Azure, or GCP)
Expertise with common application security tools and platforms (e.g., Burp Suite, SAST, SCA)
Experience with log aggregation and SIEM technologies
Ability to identify malicious behaviour and emerging threats via log analysis
Demonstrate a keen interest in improving your craft by using AI
Security certifications such as OSCP or OSWE
Active participation in the security community (e.g., presenting at conferences, contributing to open-source tools).
Experience with Ruby on Rails, Puppet, Kubernetes, Terraform, ELK (Elastic, Logtash and Kibana)
Strong AWS security experience on EC2 and managed services
Infrastructure security (WAF, ACLs, authentication, device hardening)
What you will find here:
Compensation is one of the main components of Clio's Total Rewards Program. We have developed a series of programs and processes to ensure we are creating fair and competitive pay practices that form the foundation of our human and high-performing culture.
Some highlights of our Total Rewards program include:
Competitive, equitable salary with top-tier health benefits, dental, and vision insurance
Hybrid work environment, with expectation for local Clions (Vancouver, Calgary, Toronto, Dublin and Sydney) to be in office min. twice per week.
Flexible time off policy, with an encouraged 20 days off per year.
$2000 annual counseling benefit
RRSP matching and RESP contribution
Clioversary recognition program with special acknowledgement at 3, 5, 7, and 10 years
*Our salary bands are designed to reflect the range of skills and experience needed for the position and to allow room for growth at Clio. For experienced individuals, we typically hire at or around the midpoint of the band. The top portion of the salary band is reserved for employees who demonstrate sustained high performance and impact at Clio. Those who are new to the role may join below the midpoint and develop their skills over time. The final offer amount for this role will be dependent on geographical region, applicable experience, and skillset of the candidate.
Diversity, Inclusion, Belonging and Equity (DIBE) & Accessibility
Our team shows up as their authentic selves, and are united by our mission. We are dedicated to diversity, equity and inclusion. We pride ourselves in building and fostering an environment where our teams feel included, valued, and enabled to do the best work of their careers, wherever they choose to log in from. We believe that different perspectives, skills, backgrounds, and experiences result in higher-performing teams and better innovation. We are committed to equal employment and we encourage candidates from all backgrounds to apply.
Clio provides accessibility accommodations during the recruitment process. Should you require any accommodation, please let us know and we will work with you to meet your needs.
Learn more about our culture at
Disclaimer: We only communicate with candidates through official email addresses.
-
Remote (United States | Canada) 1Password Full time $143,000 - $193,000 per year1Password is growing faster than ever. We've surpassed $400M in ARR and we're continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing and the Utah Mammoth. About 1Password At 1Password, we're building the foundation for a safe, productive digital future. Our...
-
Application Security Engineer
3 days ago
Canada - Remote Certn Full time US$80,000 - US$120,000 per yearWho We AreAt Certn, we're revolutionizing background screening with The World's Easiest Background Check — fast, global, and powered by tech. We're not about outdated processes and red tape. We're about innovation, speed, and impact. If you're looking for a place where ownership, collaboration, and creativity thrive, this is it.The OpportunityWe're looking...
-
Senior Application Security Engineer
4 weeks ago
, , Canada Webflow Full timeAbout the role: At Webflow, our mission is to bring development superpowers to everyone. As the pioneer of the Website Experience Platform (WXP), we’re redefining how teams Build, Manage, and Optimize for the web — combining visual development, powerful content management systems, AI-driven personalization, seamless hosting, and end-to-end analytics in a...
-
Senior Security Engineer, Application Security
2 weeks ago
, , Canada 1Password Full time1Password is growing faster than ever. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle, Red Bull Racing and the Utah Mammoth. About 1Password At 1Password, we’re building the foundation for a safe, productive digital future....
-
Application Security Engineer
2 weeks ago
Remote, Canada N3xt Full time $150,000 - $200,000 per yearLiberating MoneyApplication Security EngineerWe are looking for a highly skilled Application Security Engineer to own the security of our software ecosystem. You will not be writing feature code all day; instead, you will be the bridge between security and engineering.We are specifically looking for a "Builder-turned-Breaker". Someone who started their...
-
, , Canada 1Password Full timeSenior Security Engineer, Application Security Join to apply for the Senior Security Engineer, Application Security role at 1Password. 1Password is growing faster than ever. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle, Red...
-
Security Engineer
2 weeks ago
, , Canada N3XT Full timeSecurity Engineer - Application Security Join to apply for the Security Engineer - Application Security role at N3XT . Liberating Money We're looking for a highly skilled and passionate Security Engineer with a dedicated focus on Application Security to join our team. You'll embed robust security practices throughout the entire software development lifecycle...
-
Senior Application Security Engineer
4 weeks ago
, , Canada GlossGenius Full timeGlossGenius is building an ecosystem enabling entrepreneurs to succeed. We empower small business owners to focus on being creators, not admins, by offering a range of business management tools including booking and scheduling, marketing, analytics, payment processing and much more. Over 100,000 small business owners have chosen to rely on GlossGenius every...
-
Senior Application Security Engineer
4 days ago
, , Canada Sardine Full timeJoin to apply for the Senior Application Security Engineer role at Sardine . Who We Are We are a leader in fraud prevention and AML compliance. Our platform uses device intelligence, behavior biometrics, machine learning, and AI to stop fraud before it happens. Today, over 300 banks, retailers, and fintechs worldwide use Sardine to stop identity fraud,...
-
Senior Security Engineer, Application Security
3 weeks ago
, , Canada GitLab Full timeSenior Security Engineer, Application Security (AMER) Join to apply for the Senior Security Engineer, Application Security (AMER) role at GitLab. GitLab is an open-core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. Our mission is to enable everyone to contribute to and co-create...