Staff Application Security Engineer
1 day ago
Thumbtack helps millions of people confidently care for their homes. Thumbtack is the one app you need to take care of and improve your home — from personalized guidance to AI tools and a best-in-class hiring experience. Every day in every county of the U.S., people turn to Thumbtack to complete urgent repairs, seasonal maintenance and bigger improvements. We help homeowners know which projects to do, when to do them and who to hire from our growing community of 300,000 local service businesses. If making an impact inspires you, join us. Imagine what we’ll build together. About the Cybersecurity team The Security Engineering team at Thumbtack is focused on enabling innovation at scale by making the secure path the easiest path. We believe strong security is not a blocker to velocity, but a force multiplier when it is designed into systems, platforms, and developer workflows from the start. We partner closely with Product, Engineering, Platform, and Data teams to shape system design, guide architectural decisions, and evolve Thumbtack’s security posture as the company scales. Through collaboration, automation, and thoughtful tradeoffs, we help ensure Thumbtack can ship fast, innovate boldly, and maintain customer trust. As Thumbtack scales and increasingly incorporates AI-powered features into our products and internal systems, security must evolve without slowing innovation. The number of services, deployment patterns, and data flows continues to grow, and traditional approaches that rely heavily on manual reviews or after‑the‑fact controls do not scale to meet this need. Instead, the challenge is to design security into the system itself. This means building secure defaults, paved paths, and reusable building blocks that product and engineering teams can adopt with minimal friction. By embedding security directly into architectures, tooling, and infrastructure, we reduce cognitive load on engineers and enable teams to move quickly and confidently while meaningfully lowering risk. What you'll do Own the long‑term technical direction for application security across Thumbtack. Build prioritized roadmaps and drive remediation of systemic security risks across the application stack. Lead large, cross‑functional security initiatives from problem definition through delivery. Design secure‑by‑default architectures, standards, and paved paths for engineering teams. Design and implement shared security tooling, libraries, patterns, and services that enable engineering to ship quickly and safely. Embed security into CI/CD pipelines, cloud infrastructure, and developer workflows. Partner with engineering and product leaders to prioritize security investments based on risk, impact, and business goals. Lead application security design reviews, architectural discussions, and threat modeling for critical systems. Contribute code, reviews, and designs to address complex or novel security risks. Mentor engineers and raise the overall security bar through guidance and example. Support security incident response and drive learning through post‑incident analysis. In order to be successful, you must bring 8+ years of experience in software engineering and application security, including a strong understanding of secure coding practices and application security frameworks. Deep expertise in secure system design and architecture as well as modern application security tools, patterns, and practices (e.g. threat modeling, secure design patterns, authentication and authorization, secrets management, vulnerability discovery and remediation workflows). Proven track record leading large, cross‑functional technical initiatives with sustained impact. Strong experience securing modern, cloud‑native systems (AWS and/or GCP). Strong product intuition and analytical, risk‑informed thinking, identifying where security investments will have the highest leverage and measurable impact. Ability to balance pragmatism and rigor, making thoughtful tradeoffs between risk, velocity, and maintainability. Strong sense of ownership and accountability, balancing hands‑on technical execution with the ability to mentor others, raise standards, and drive organization‑wide improvements in application security. Excellent written and verbal communication skills, with the ability to influence without authority and the ability to explain complex security issues to both technical and non‑technical audiences. Expected salary ranges For candidates living in Ontario and British Columbia, the expected salary range for the role is currently $221,000.00 - $286,000.00. Actual offered salaries will vary and will be based on various factors, such as calibrated job level, qualifications, skills, competencies, and proficiency for the role. Note: Thumbtack uses AI tools to support our resume screening process. However, our Recruiting team’s expertise and judgment guide hiring decisions. Thumbtack embraces diversity. We are proud to be an equal opportunity workplace and do not discriminate on the basis of sex, race, color, age, pregnancy, sexual orientation, gender identity or expression, religion, national origin, ancestry, citizenship, marital status, military or veteran status, genetic information, disability status, or any other characteristic protected by federal, provincial, state, or local law. We also will consider for employment qualified applicants with arrest and conviction records, consistent with applicable law. Thumbtack is committed to working with and providing reasonable accommodation to individuals with disabilities. If you would like to request a reasonable accommodation for a medical condition or disability during any part of the application process, please contact: . If you are a California resident, please review information regarding your rights under California privacy laws contained in Thumbtack’s Privacy policy available at . We put as much craftsmanship into candidate safety as we do into the hiring experience itself. While scammers may try to impersonate our team, we’ll never ask you for money, banking info, or SSNs during hiring. Check out our blueprint on how to spot the fakes. #J-18808-Ljbffr
-
Senior Staff Sales Engineer
4 weeks ago
, , Canada Black Duck Software, Inc. Full timeA leading software security company in Canada is looking for a Senior Staff Sales Engineer to bridge technical and commercial aspects of application security solutions. The ideal candidate will have over 8 years of experience in sales engineering, with a robust understanding of SAST, SCA, and DAST technologies. This role involves working closely with...
-
Staff Application Engineer
2 weeks ago
, , Canada Forma.ai Full timeAbout Forma.aiForma.ai is a Series B startup that's revolutionizing how sales compensation is designed, managed and optimized. We handle billions in annual managed commissions for market leaders like Edmentum, Stryker, and Autodesk. About Forma.aiForma.ai is a Series B startup that's revolutionizing how sales compensation is designed, managed and optimized....
-
Staff Security Engineer
3 weeks ago
, , Canada Paxos Full timeJoin to apply for the Staff Security Engineer role at Paxos. About Paxos Today’s financial infrastructure is archaic, expensive, inefficient and risky—supporting a system that leaves out more people than it lets in. So we’re rebuilding it. We’re on a mission to open the world’s financial system to everyone by enabling the instant movement of any...
-
Staff Security Engineer, Security Partnerships
4 weeks ago
, , Canada Stripe Full timeStaff Security Engineer, Security Partnerships Join to apply for the Staff Security Engineer, Security Partnerships role at Stripe. About the Team The Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first‑class consideration in...
-
Staff Security Engineer
1 day ago
, , Canada Shakepay Inc. Full timeAt Shakepay, we’re on a mission to usher in the Bitcoin golden age. We’re reimagining financial services to give every Canadian their fair shake. Our culture is built around doing work that matters, winning as a team, and celebrating success. If you’re the kind of person who values growth, shipping fast, and sharing your ideas openly with a group of...
-
Staff Security Engineer
4 weeks ago
, , Canada Fullscript Full timeStaff Security Engineer – Fullscript Location: Greater Montreal Metropolitan Area (Remote) About Fullscript Founded in 2011, Fullscript started by solving one problem: helping practitioners access and prescribe the products they trust to deliver integrative care. What began as a simple solution has evolved into a health intelligence platform that powers...
-
Application Security Engineer
4 weeks ago
, , Canada N3XT Full timeSecurity Engineer - Application Security Join to apply for the Security Engineer - Application Security role at N3XT . Liberating Money We're looking for a highly skilled and passionate Security Engineer with a dedicated focus on Application Security to join our team. You'll embed robust security practices throughout the entire software development lifecycle...
-
Staff Security Engineer
2 weeks ago
Remote, Canada Shakepay Full timeAt Shakepay, we're on a mission to usher in the Bitcoin golden age. We're reimagining financial services to give every Canadian their fair shake.Our culture is built around doing work that matters, winning as a team, and celebrating success. If you're the kind of person who values growth, shipping fast, and sharing your ideas openly with a group of...
-
Staff Security Engineer
5 days ago
Remote, Canada Shakepay Full timeAt Shakepay, we're on a mission to usher in the Bitcoin golden age. We're reimagining financial services to give every Canadian their fair shake. Our culture is built around doing work that matters, winning as a team, and celebrating success. If you're the kind of person who values growth, shipping fast, and sharing your ideas openly with a group of...
-
Staff Security Engineer
5 days ago
Remote, Canada Shakepay Full timeAt Shakepay, we're on a mission to usher in the Bitcoin golden age. We're reimagining financial services to give every Canadian their fair shake.Our culture is built around doing work that matters, winning as a team, and celebrating success. If you're the kind of person who values growth, shipping fast, and sharing your ideas openly with a group of...