Application Security Engineer
18 hours ago
At Certn, we're revolutionizing background screening with The World's Easiest Background Check — fast, global, and powered by tech. We're not about outdated processes and red tape. We're about innovation, speed, and impact. If you're looking for a place where ownership, collaboration, and creativity thrive, this is it.
The OpportunityWe're looking for an Application Security Engineer to safeguard our customer-facing platforms and internal systems. In this hands-on role, you'll embed security at every stage of the application lifecycle, from architecture and development through deployment and monitoring. This is an ideal opportunity for someone passionate about secure software development, automation, and protecting people's data in a fast-moving, product-centric environment.
Key ResponsibilitiesSecure Application Development
Embed security best practices throughout the software development lifecycle (SDLC) to ensure applications are designed and built with security in mind from the start.
Conduct secure code and architecture reviews to proactively identify and remediate vulnerabilities before they impact production.
Partner with engineering teams to create secure-by-design applications that protect sensitive applicant, client, and employee data while maintaining product performance and usability.
Threat Detection and Vulnerability Management
Identify, assess, and prioritize potential security risks to reduce Certn's exposure to emerging threats and strengthen overall resilience.
Coordinate internal and third-party penetration testing to validate the effectiveness of security controls and ensure vulnerabilities are remediated promptly.
Maintain a structured vulnerability management process to ensure accountability, visibility, and measurable improvement in Certn's security posture over time.
Security Tooling and Automation
Implement and manage security tools (e.g., SAST, DAST, dependency scanning, secrets detection) to continuously monitor and safeguard Certn's applications.
Integrate automated security checks into CI/CD pipelines to enable fast, secure releases without slowing development velocity.
Leverage automation to improve efficiency, consistency, and early detection of security issues, reducing manual overhead and human error.
Governance, Compliance, and Incident Response
Align application security practices with global and regional standards (e.g., SOC 2, ISO 27001, GDPR, PIPEDA) to meet client and regulatory expectations.
Support audit and compliance efforts by maintaining evidence of secure processes and demonstrating control effectiveness to external and internal stakeholders.
Participate in incident response for application-related issues to minimize impact, learn from events, and strengthen future defenses.
Collaboration, Enablement, and Continuous Improvement
Partner with product, engineering, DevOps, and compliance teams to integrate security objectives seamlessly into business and development processes
Promote secure development practices through training, documentation, and coaching, fostering a culture where security is a shared responsibility.
Stay current on evolving threats, technologies, and best practices to continuously enhance Certn's security capabilities and maintain stakeholder trust.
Bachelor's degree in Computer Science, Information Security, Software Engineering, or a related technical discipline; or an equivalent combination of education and practical experience.
Relevant post-secondary coursework or certifications in cybersecurity, secure software development, or cloud security are considered strong assets.
Strong understanding of secure coding principles, web application security, and common vulnerabilities (e.g., OWASP Top 10, SANS top 25).
Proficiency with application security testing tools such as SAST, DAST, SCA, and secrets-scanning platforms.
Working knowledge of authentication and authorization mechanisms, encryption, API security, and identity management.
Ability to interpret and communicate technical security risks to both technical and non-technical audiences.
Experience integrating security into CI/CD pipelines and using automation to improve security coverage.
Analytical thinking, problem-solving, and prioritization skills with strong attention to detail.
Collaborative mindset with the ability to partner effectively across engineering, product, DevOps, and compliance teams.
Demonstrated experience performing threat modeling, code review, and vulnerability remediation within agile development environments.
Hands-on experience with cloud-native architectures and security practices across AWS, Azure, or GCP environments.
Familiarity with security frameworks and compliance standards (e.g., SOC 2, ISO 27001, NIST, GDPR, PIPEDA).
Proven track record of improving security maturity within a fast-paced, product-focused organization.
Flexibility: Remote-first role with teammates across North America and the UK
Global Collaboration: Partner with experienced technical teams in multiple regions
Culture: Collaborative, async-friendly, and innovation-focused.
A Little Bit More About UsCertn is a growing global technology company reinventing the way organizations build trust in people with technology and AI-backed background checks. Having recently been named one of Canada's Companies-to-Watch in Deloitte's Technology Fast 50 Awards, we are one of the fastest-growing start-ups in the sector. Just so you know, the selected candidate will be required to complete a background check — so you'll get to see first-hand what we do. Certn is committed to equal opportunity, inclusion, and diversity. If you have a disability that requires accommodation at any stage of the recruitment process, please let us know how we can best assist you.
Ready to build your career and make an impact? Apply now and start your journey with Certn.
-
Application Security Engineer
1 week ago
Remote, Canada N3xt Full time $150,000 - $200,000 per yearLiberating MoneyApplication Security EngineerWe are looking for a highly skilled Application Security Engineer to own the security of our software ecosystem. You will not be writing feature code all day; instead, you will be the bridge between security and engineering.We are specifically looking for a "Builder-turned-Breaker". Someone who started their...
-
Security Engineer
2 weeks ago
, , Canada N3XT Full timeSecurity Engineer - Application Security Join to apply for the Security Engineer - Application Security role at N3XT . Liberating Money We're looking for a highly skilled and passionate Security Engineer with a dedicated focus on Application Security to join our team. You'll embed robust security practices throughout the entire software development lifecycle...
-
Remote (United States | Canada) 1Password Full time $143,000 - $193,000 per year1Password is growing faster than ever. We've surpassed $400M in ARR and we're continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle Red Bull Racing and the Utah Mammoth. About 1Password At 1Password, we're building the foundation for a safe, productive digital future. Our...
-
Application Security Architect
6 days ago
Remote Canada Phreesia Full time $120,000 - $180,000 per yearJob Description:Are you looking for a team that is energized by the constantly evolving world of application design and security? We are preparing for the future and are looking for a talented, experienced Security Architect - I to join us in building things from inception with deep-rooted security principles and design.As a security expert, you will play a...
-
Information Security
7 days ago
, , Canada Mechanical Orchard Full timeAt Mechanical Orchard, we specialize in safely rewriting the most critical and complex business applications—the software that runs the world as we know it today—so they’re ready to adapt quickly and easily to market challenges and opportunities. Our approach emerged from observing the decades-long failure patterns in modernization efforts and is...
-
Application Security Engineer
4 days ago
, , Canada Fragomen Full timeApplication Security Engineer & Architect Fragomen, an Am Law 100 Firm and the leading global immigration services provider, is seeking an Application Security Engineer & Architect. This Engineer will join our talent Cyber Security team, which plays a pivotal role in Fragomen's Immigration Technology Innovation Lab. Our industry‑leading,...
-
Senior Application Security Engineer
4 weeks ago
, , Canada Webflow Full timeAbout the role: At Webflow, our mission is to bring development superpowers to everyone. As the pioneer of the Website Experience Platform (WXP), we’re redefining how teams Build, Manage, and Optimize for the web — combining visual development, powerful content management systems, AI-driven personalization, seamless hosting, and end-to-end analytics in a...
-
Senior Security Engineer, Application Security
2 weeks ago
, , Canada 1Password Full time1Password is growing faster than ever. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle, Red Bull Racing and the Utah Mammoth. About 1Password At 1Password, we’re building the foundation for a safe, productive digital future....
-
Cloud and Application Security Engineer
3 weeks ago
, , Canada CanCap Group Inc. Full timeJoin to apply for the Cloud and Application Security Engineer role at CanCap Group Inc. The CanCap Group (“CanCap”) is a privately‑owned Canadian national financial services company with multiple verticals across automotive, consumer, and merchant lending portfolios. We manage the entire lifecycle of finance receivables from credit adjudication through...
-
Security Engineer
15 hours ago
Remote, Canada N3xt Full time $150,000 - $200,000 per yearLiberating MoneySecurity Engineer - Application SecurityWe're looking for a highly skilled and passionate Security Engineer with a dedicated focus on Application Security to join our team. You'll embed robust security practices throughout the entire software development lifecycle (SDLC), from design to deployment. This role is key to building secure,...