Current jobs related to Staff Application Security Engineer - Toronto, Ontario - Thumbtack


  • Toronto, Ontario, Canada Sentry Full time

    About SentryBad software is everywhere, and we're tired of it. Sentry is on a mission to help developers write better software faster so we can get back to enjoying technology.With more than $217 million in funding and 100,000+ organizations that believe we're on to something, we're building performance and error monitoring tools that help companies like...


  • Toronto, Ontario, Canada Emburse Full time

    About The CompanyAt Emburse our mission is to help make our users' lives – and their businesses – better. We are dramatically transforming how organizations manage corporate expenses and invoices. We humanize work by automating manual tasks and saving users' time, so they can focus on what matters most – their family, community, or more rewarding work....

  • Security Team Lead

    3 days ago


    Toronto, Ontario, Canada Paladin Security Full time

    Overview Job Skills / RequirementsSite Description: University Health Networks is Canada's No. 1 hospital and the world's No. 1 publicly funded hospital. The purpose of UHN is to transform lives and communities through excellence in care, discovery and learning. West Park Healthcare Centre one of the hospitals under UHN provides specialized rehabilitative...


  • Toronto, Ontario, Canada Okta Full time

    Get to know OktaOkta is The World's Identity Company. We free everyone to safely use any technology, anywhere, on any device or app. Our flexible and neutral products, Okta Platform and Auth0 Platform, provide secure access, authentication, and automation, placing identity at the core of business security and growth.At Okta, we celebrate a variety of...


  • Toronto, Ontario, Canada Loop Financial Full time $170,000 - $200,000

    About the RoleHi, I'm Yan, Head of Engineering at Loop, and I'm hiring a Staff Software Engineer to be a technical leader across our entire platform. In this role, you'll set architectural direction, mentor engineers, and build critical systems yourself - from our core ledger and money movement infrastructure to the product features that customers interact...


  • Toronto, Ontario, Canada Float Full time

    About FloatFloat is on a mission to simplify finance for Canadian businesses, empowering them to eliminate complexity and unlock new opportunities. Through our innovative platform, Float enables businesses to streamline financial operations and optimize cash flow, so they can focus on what matters most: growth. As one of Canada's fastest growing companies...


  • Toronto, Ontario, Canada Paladin Security Full time

    Overview Job Skills / RequirementsSite Description: North York General Hospital is a leading community hospital in Toronto, recognized for its commitment to providing exceptional patient care. With a comprehensive range of services, including emergency, surgical, and specialized care, NYGH is dedicated to improving the health and well-being of its diverse...


  • Toronto, Ontario, Canada BlueCat Full time

    Have you heard of BlueCat? We're one of those hidden gems that's been disrupting the market as a key player in the rapidly growing space of Intelligent Network Operations. Organizations require a new model of network operations that links foundational core services with a deep, predictive understanding of network health and performance to improve change...

  • Security Guard

    3 days ago


    Toronto, Ontario, Canada Paladin Security Group Ltd Full time

    Overview Job Skills / RequirementsPosition: Security GuardSite: Mount Sinai HospitalCity: 600 University Avenue, TorontoStatus: Full TimeHours: Continental Rotation / Category: Average Agreement - Overtime after 88 hoursPay Rate: $23.87 /hr.Internal Opening Date: December 15, 2025Internal Closing date: December 22, 2025External Closing Date: December 29,...


  • Toronto, Ontario, Canada Thomson Reuters Full time

    This posting is for proactive recruitment purposes and may be used to fill current openings or future vacancies within our organization Staff Software Engineer-AIAre you passionate about pushing the boundaries of AI technology and leading the charge in building intelligent solutions that transform how Tax and Trade products work? Join the Thomson Reuters...

Staff Application Security Engineer

17 minutes ago


Toronto, Ontario, Canada Thumbtack Full time

Thumbtack helps millions of people confidently care for their homes.
Thumbtack is the one app you need to take care of and improve your home — from personalized guidance to AI tools and a best-in-class hiring experience. Every day in every county of the U.S., people turn to Thumbtack to complete urgent repairs, seasonal maintenance and bigger improvements. We help homeowners know which projects to do, when to do them and who to hire from our growing community of 300,000 local service businesses. If making an impact inspires you, join us. Imagine what we'll build together.

About The Cybersecurity Team
The Security Engineering team at Thumbtack is focused on enabling innovation at scale by making the secure path the easiest path. We believe strong security is not a blocker to velocity, but a force multiplier when it is designed into systems, platforms, and developer workflows from the start.

We partner closely with Product, Engineering, Platform, and Data teams to shape system design, guide architectural decisions, and evolve Thumbtack's security posture as the company scales. Through collaboration, automation, and thoughtful tradeoffs, we help ensure Thumbtack can ship fast, innovate boldly, and maintain customer trust.

Challenge
As Thumbtack scales and increasingly incorporates AI-powered features into our products and internal systems, security must evolve without slowing innovation. The number of services, deployment patterns, and data flows continues to grow, and traditional approaches that rely heavily on manual reviews or after-the-fact controls do not scale to meet this need.

Instead, the challenge is to design security into the system itself. This means building secure defaults, paved paths, and reusable building blocks that product and engineering teams can adopt with minimal friction. By embedding security directly into architectures, tooling, and infrastructure, we reduce cognitive load on engineers and enable teams to move quickly and confidently while meaningfully lowering risk.

What You'll Do

  • Own the long-term technical direction for application security across Thumbtack. Build prioritized roadmaps and drive remediation of systemic security risks across the application stack.
  • Lead large, cross-functional security initiatives from problem definition through delivery.
  • Design secure-by-default architectures, standards, and paved paths for engineering teams. Design and implement shared security tooling, libraries, patterns, and services that enable engineering to ship quickly and safely. Embed security into CI/CD pipelines, cloud infrastructure, and developer workflows.
  • Partner with engineering and product leaders to prioritize security investments based on risk, impact, and business goals.
  • Lead application security design reviews, architectural discussions, and threat modeling for critical systems. Contribute code, reviews, and designs to address complex or novel security risks.
  • Mentor engineers and raise the overall security bar through guidance and example.
  • Support security incident response and drive learning through post-incident analysis.

In order to be successful, you must bring

  • 8+ years of experience in software engineering and application security, including a strong understanding of secure coding practices and application security frameworks.
  • Deep expertise in secure system design and architecture as well as modern application security tools, patterns, and practices (e.g. threat modeling, secure design patterns, authentication and authorization, secrets management, vulnerability discovery and remediation workflows).
  • Proven track record leading large, cross-functional technical initiatives with sustained impact.
  • Strong experience securing modern, cloud-native systems (AWS and/or GCP).
  • Strong product intuition and analytical, risk-informed thinking, identifying where security investments will have the highest leverage and measurable impact. Ability to balance pragmatism and rigor, making thoughtful tradeoffs between risk, velocity, and maintainability.
  • Strong sense of ownership and accountability, balancing hands-on technical execution with the ability to mentor others, raise standards, and drive organization-wide improvements in application security.
  • Excellent written and verbal communication skills, with the ability to influence without authority and the ability to explain complex security issues to both technical and non-technical audiences.

Expected salary ranges

  • For candidates living in Ontario and British Columbia, the expected salary range for the role is currently $221, $286,000.00.

Actual offered salaries will vary and will be based on various factors, such as calibrated job level, qualifications, skills, competencies, and proficiency for the role.

Note: Thumbtack uses AI tools to support our resume screening process. However, our Recruiting team's expertise and judgment guide hiring decisions.

Thumbtack embraces diversity. We are proud to be an equal opportunity workplace and do not discriminate on the basis of sex, race, color, age, pregnancy, sexual orientation, gender identity or expression, religion, national origin, ancestry, citizenship, marital status, military or veteran status, genetic information, disability status, or any other characteristic protected by federal, provincial, state, or local law. We also will consider for employment qualified applicants with arrest and conviction records, consistent with applicable law.

Thumbtack is committed to working with and providing reasonable accommodation to individuals with disabilities. If you would like to request a reasonable accommodation for a medical condition or disability during any part of the application process, please contact:

If you are a California resident, please review information regarding your rights under California privacy laws contained in Thumbtack's Privacy policy available at

We put as much craftsmanship into candidate safety as we do into the hiring experience itself. While scammers may try to impersonate our team, we'll never ask you for money, banking info, or SSNs during hiring. Check out our blueprint on how to spot the fakes.