Application Security Engineer

1 week ago


Remote, Canada N3xt Full time $150,000 - $200,000 per year

Liberating Money

Application Security Engineer

We are looking for a highly skilled Application Security Engineer to own the security of our software ecosystem. You will not be writing feature code all day; instead, you will be the bridge between security and engineering.

We are specifically looking for a "Builder-turned-Breaker". Someone who started their career as a Software Engineer and transitioned into Application Security (or Pentesting). Because you have built software before, you understand the pressures of the SDLC, and you know exactly how to guide our engineers toward secure architecture without blocking innovation.

You will own our AppSec tooling (SAST/DAST/SCA) and act as the primary gatekeeper for critical code changes, specifically regarding new API routes and services.

Responsibilities
  • Own the AppSec Pipeline: Implement, tune, and manage automated security tools (SAST, DAST, SCA, Secret Scanning) within our CI/CD pipelines. Ensure these tools provide high-value signals, not noise.
  • High-Value Code Reviews: Perform manual code reviews on high-risk PRs, with a specific focus on changes that expose new API routes, network services, or authentication logic.
  • Vulnerability Management & Remediation: Triage results from scans and bug bounties. While you won't write feature code, you must be capable of jumping into the codebase to write patches, create unit tests for regressions, or help a developer structure a fix.
  • Standardize Security Telemetry: Design and enforce structured logging standards across the application stack. You will teach developers what to log (e.g., auth failures, privilege escalation, sensitive data access) and how to log it so that our SecOps/SRE teams can successfully trace user activity during an incident.
  • Security Architecture: Consult with engineering teams during the design phase (RFCs) to ensure security controls are baked in from day one (Threat Modeling).
  • Developer Enablement: Act as a mentor to the Full Stack team. Translate complex security concepts into practical coding advice (e.g., "Here is how we should handle this input validation in TypeScript").
  • Cloud & Infrastructure Security: Partner with DevOps to maintain WAF rules and ensure cloud-native services (GCP, Cloud Armor) are configured correctly.
Required Experience
  • The "Dev-First" Background: You must have prior professional experience working as a Software Engineer (Backend or Full Stack) before transitioning into Security. You need to understand how code is built to secure it.
  • AppSec Expertise: 3+ years of experience specifically in Application Security, Penetration Testing, or Product Security.
  • Code Fluency: Ability to read and understand complex codebases (ideally JavaScript/TypeScript) to identify logic flaws that automated tools miss.
  • Tooling Proficiency: Hands-on experience configuring and managing tools like GitHub Advanced Security, Burp Suite, OWASP ZAP, Snyk, or similar in a CI/CD environment.
  • API Security: Deep understanding of REST, GraphQL, and tRPC security patterns. You know what to look for when a developer opens a new route.
  • Observability & Forensics: Experience designing logging patterns that support incident response. You understand the difference between "debug logs" and "audit logs" and can guide engineers to implement the latter.
  • Communication: You can explain why a vulnerability matters to the business and how to fix it to a Junior Developer.
Preferred Experience
  • Experience transitioning from a developer role to a dedicated security role (e.g., internal transfer, self-taught pentesting).
  • Offensive security experience (Bug Bounties, CTFs, OSCP).
  • Experience with GCP and Kubernetes security.
  • Experience working in regulated industries (FinTech, SOC2, ISO

The pay range for this role is:

150, ,000 CAD per year(Remote (Canada))



  • Canada - Remote Certn Full time US$80,000 - US$120,000 per year

    Who We AreAt Certn, we're revolutionizing background screening with The World's Easiest Background Check — fast, global, and powered by tech. We're not about outdated processes and red tape. We're about innovation, speed, and impact. If you're looking for a place where ownership, collaboration, and creativity thrive, this is it.The OpportunityWe're looking...

  • Security Engineer

    9 hours ago


    Remote, Canada N3xt Full time $150,000 - $200,000 per year

    Liberating MoneySecurity Engineer - Application SecurityWe're looking for a highly skilled and passionate Security Engineer with a dedicated focus on Application Security to join our team. You'll embed robust security practices throughout the entire software development lifecycle (SDLC), from design to deployment. This role is key to building secure,...


  • Remote (United States | Canada) 1Password Full time $143,000 - $193,000 per year

    1Password is growing faster than ever. We've surpassed $400M in ARR and we're continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing and the Utah Mammoth. About 1Password At 1Password, we're building the foundation for a safe, productive digital future. Our...


  • Remote Canada Phreesia Full time $120,000 - $180,000 per year

    Job Description:Are you looking for a team that is energized by the constantly evolving world of application design and security? We are preparing for the future and are looking for a talented, experienced Security Architect - I to join us in building things from inception with deep-rooted security principles and design.As a security expert, you will play a...


  • Remote, Canada Feroot Security Full time $120,000 - $180,000 per year

    100% Remote. Office in Toronto for those who are local and prefer it, but it is not mandatory or expected.Why Feroot, Why Now?We just closed our Series A, and we're scaling fast. Feroot is tackling one of the most urgent challenges in cybersecurity: protecting the client-side of the web, where millions of users interact with businesses every single day...

  • Security Engineer

    1 week ago


    Remote, Canada Jonas Software Full time US$135,000 - US$150,000 per year

    Job Description:Security EngineerCompensation: The expected salary range for this role is between $135,000 and $150,000, depending on experience and qualifications.Reason for Opening: Net New positionAI is not used to screen, assess, or select applicants for this role.The CompanyConstellation Payment Processing is a modern Payment Facilitator (PayFac)...


  • Remote, Canada Cyberwell Full time $80,000 - $120,000 per year

    About usCYBERWELL is the new name behind North America's most trusted cybersecurity brands – Source44, SeekIntoo, Cycura and Proack Security. Now united under one banner and backed by WELL Health Technologies, we are scaling our impact with a fresh vision, a stronger portfolio, and a renewed commitment to helping organizations build lasting resilience in...

  • Security Engineer I

    11 hours ago


    Remote, Canada Cision Full time $90,000 - $120,000 per year

    At Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As part of our global team, you'll thrive in an environment that champions curiosity, collaboration, and innovation, all while making meaningful contributions to the brands we...


  • Remote, Canada Cyberwell Full time $80,000 - $120,000 per year

    About usCYBERWELL is the new name behind North America's most trusted cybersecurity brands – Source44, SeekIntoo, Cycura and Proack Security. Now united under one banner and backed by WELL Health Technologies, we are scaling our impact with a fresh vision, a stronger portfolio, and a renewed commitment to helping organizations build lasting resilience in...


  • Remote, Canada Cision Full time $80,000 - $120,000 per year

    At Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As part of our global team, you'll thrive in an environment that champions curiosity, collaboration, and innovation, all while making meaningful contributions to the brands we...