Security Engineer
18 hours ago
Liberating Money
Security Engineer - Application SecurityWe're looking for a highly skilled and passionate Security Engineer with a dedicated focus on Application Security to join our team. You'll embed robust security practices throughout the entire software development lifecycle (SDLC), from design to deployment. This role is key to building secure, resilient applications while fostering a culture where security is a seamless part of innovation.
We're seeking candidates with a strong background (e.g., 5 years of combined experience) in both software development and application security in a production environment. This isn't just about identifying issues; you'll be on the front lines, directly involved in fixing vulnerabilities and implementing secure code changes. Responsibilities will vary based on experience, with engineers leading strategic initiatives and automation, and others focusing on foundational practices. This is a collaborative role, balancing security with developer velocity and operational efficiency, ensuring security enables fast delivery of secure software.
Responsibilities- Drive security best practices into the SDLC, including security architecture reviews, threat modeling, and secure coding guidance.
- Implement and manage automated application security tools (SAST, DAST, SCA) in CI/CD pipelines for credential scanning, static/dynamic analysis, and dependency scanning, and take direct, hands-on ownership of analyzing the reported vulnerabilities, coding the required fixes, testing the remediation, and ensuring successful deployment.
- Conduct regular application security testing, coordinate third-party assessments, and actively participate in fixing identified vulnerabilities.
- Configure and maintain Web Application Firewalls (WAF) to protect applications.
- Design and implement security controls for APIs, including authentication, authorization, and API gateway policies.
- Implement security controls for cloud-deployed applications, leveraging cloud-native security services for threat detection.
- Deploy and manage application-focused SIEM detections, centralize application log collection, and support security monitoring. Participate in incident response for application-specific threats.
- Develop and maintain application security policies, standards, and guidelines (e.g., OWASP Top 10, NIST, ISO
- Work closely with Full Stack Engineers to educate them on secure coding practices, provide training, and empower them to build secure applications.
- Collaborate with product engineering, DevOps, and SRE teams to implement secure, usable, and efficient security solutions.
- At least 5 years of professional experience, with a strong blend of both software engineering and application security.
- Proficiency in software development and code remediation (ideally JavaScript/TypeScript), as this role contributes directly to codebases for security fixes and features.
- Expertise in SSDLC principles including threat modeling, secure design patterns, and secure coding.
- Hands-on experience with commercial and open source application security scanning tools (e.g., GitHub Advanced Security, Pnpm audit, Nodejsscan, Burp Suite, Invicti, OWASP ZAP, Gitleaks) for SAST, DAST, SCA, and secret detection.
- Strong understanding and practical experience with Web Application Firewalls (WAFs).
- Proficiency in cloud security controls for applications (e.g., GCP, Cloud Armor, Security Command Center, IAM hardening, Cloud Logging).
- Solid understanding of API security best practices and experience securing RESTful, tRPC and GraphQL APIs.
- Proficiency in SIEM & log management for application security, including log aggregation, correlation, visualization and threat detection.
- Proficiency in scripting for automation and integrating security tools into CI/CD pipelines.
- Strong understanding of common application vulnerabilities (e.g., OWASP Top 10).
- Excellent communication and collaboration skills to effectively convey security concepts to developers and other stakeholders.
- Offensive security experience (e.g., bug bounty participation, CTFs) is a plus. Penetration testing experience is welcome but not mandatory.
- Security certifications such as CISSP, CSSLP, OSCP, or GIAC GWEB.
- Hands-on experience with containerization (Docker, Kubernetes) and securing containerized applications.
- Experience with compliance frameworks relevant to application security (SOC 2 Type 2, ISO and supporting related audits.
- Experience in financial services or other regulated industries with stringent application security requirements.
The pay range for this role is:
150, ,000 CAD per year(Remote (Canada))
-
Application Security Engineer
1 week ago
Remote, Canada N3xt Full time $150,000 - $200,000 per yearLiberating MoneyApplication Security EngineerWe are looking for a highly skilled Application Security Engineer to own the security of our software ecosystem. You will not be writing feature code all day; instead, you will be the bridge between security and engineering.We are specifically looking for a "Builder-turned-Breaker". Someone who started their...
-
Senior Full Stack Engineer
6 days ago
Remote, Canada Feroot Security Full time $120,000 - $180,000 per year100% Remote. Office in Toronto for those who are local and prefer it, but it is not mandatory or expected.Why Feroot, Why Now?We just closed our Series A, and we're scaling fast. Feroot is tackling one of the most urgent challenges in cybersecurity: protecting the client-side of the web, where millions of users interact with businesses every single day...
-
Security Engineer
1 week ago
Remote, Canada Jonas Software Full time US$135,000 - US$150,000 per yearJob Description:Security EngineerCompensation: The expected salary range for this role is between $135,000 and $150,000, depending on experience and qualifications.Reason for Opening: Net New positionAI is not used to screen, assess, or select applicants for this role.The CompanyConstellation Payment Processing is a modern Payment Facilitator (PayFac)...
-
Security Engineer, Vulnerability
1 week ago
Remote, Canada Cyberwell Full time $80,000 - $120,000 per yearAbout usCYBERWELL is the new name behind North America's most trusted cybersecurity brands – Source44, SeekIntoo, Cycura and Proack Security. Now united under one banner and backed by WELL Health Technologies, we are scaling our impact with a fresh vision, a stronger portfolio, and a renewed commitment to helping organizations build lasting resilience in...
-
Manager, Security Engineering
7 days ago
Remote, Canada Cyberwell Full time $80,000 - $120,000 per yearAbout usCYBERWELL is the new name behind North America's most trusted cybersecurity brands – Source44, SeekIntoo, Cycura and Proack Security. Now united under one banner and backed by WELL Health Technologies, we are scaling our impact with a fresh vision, a stronger portfolio, and a renewed commitment to helping organizations build lasting resilience in...
-
Security Engineer I
19 hours ago
Remote, Canada Cision Full time $90,000 - $120,000 per yearAt Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As part of our global team, you'll thrive in an environment that champions curiosity, collaboration, and innovation, all while making meaningful contributions to the brands we...
-
Senior Security Engineer
1 day ago
Remote, Canada Cision Full time $80,000 - $120,000 per yearAt Cision, we believe in empowering every individual to make an impact. Here, your voice is heard, your ideas are valued, and your unique perspective fuels our collective success. As part of our global team, you'll thrive in an environment that champions curiosity, collaboration, and innovation, all while making meaningful contributions to the brands we...
-
Senior Security Engineer
1 day ago
Remote - Canada Samsara Full time $120,000 - $180,000 per yearAbout the role:The Senior Security Engineer - Enterprise Security Automation engineer is responsible for building, operating, and maintaining Samsara's core security infrastructure and the automations that power it. You will collaborate with and mentor a global team of engineers to help build a world-class security engineering program utilizing modern...
-
Remote, Canada Vanta Full time $120,000 - $200,000 per yearLocationRemote - CanadaEmployment TypeFull timeLocation TypeRemoteDepartmentEngineeringAt Vanta, our mission is to help businesses earn and prove trust.We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have...
-
Sr. Sales Engineer
20 hours ago
Remote, Canada Rubrik Security Cloud Full time $80,000 - $150,000 per yearRubrik's sales organization is a united group of elite cross-functional sales professionals that help companies & government entities achieve resilience against cyberattacks, malicious insiders, and operational disruptions. We offer continuous professional development through our world class sales enablement program and our One Rubrik selling approach...