Security Engineer
2 weeks ago
Security Engineer - Application Security Join to apply for the Security Engineer - Application Security role at N3XT . Liberating Money We're looking for a highly skilled and passionate Security Engineer with a dedicated focus on Application Security to join our team. You'll embed robust security practices throughout the entire software development lifecycle (SDLC), from design to deployment. This role is key to building secure, resilient applications while fostering a culture where security is a seamless part of innovation.We're seeking candidates with a strong background (e.g., 5 years of combined experience) in both software development and application security in a production environment. This isn't just about identifying issues; you'll be on the front lines, directly involved in fixing vulnerabilities and implementing secure code changes . Responsibilities will vary based on experience, with engineers leading strategic initiatives and automation, and others focusing on foundational practices. This is a collaborative role, balancing security with developer velocity and operational efficiency, ensuring security enables fast delivery of secure software. Responsibilities Drive security best practices into the SDLC, including security architecture reviews, threat modeling, and secure coding guidance. Implement and manage automated application security tools (SAST, DAST, SCA) in CI/CD pipelines for credential scanning, static/dynamic analysis, and dependency scanning, and take direct, hands‑on ownership of analyzing the reported vulnerabilities, coding the required fixes, testing the remediation, and ensuring successful deployment. Conduct regular application security testing, coordinate third-party assessments, and actively participate in fixing identified vulnerabilities. Configure and maintain Web Application Firewalls (WAF) to protect applications. Design and implement security controls for APIs, including authentication, authorization, and API gateway policies. Implement security controls for cloud-deployed applications, leveraging cloud-native security services for threat detection. Deploy and manage application-focused SIEM detections, centralize application log collection, and support security monitoring. Participate in incident response for application-specific threats. Develop and maintain application security policies, standards, and guidelines (e.g., OWASP Top 10 , NIST, ISO 27001). Work closely with Full Stack Engineers to educate them on secure coding practices, provide training, and empower them to build secure applications. Collaborate with product engineering, DevOps, and SRE teams to implement secure, usable, and efficient security solutions. Required Experience At least 5 years of professional experience, with a strong blend of both software engineering and application security. Proficiency in software development and code remediation (ideally JavaScript/TypeScript), as this role contributes directly to codebases for security fixes and features. Expertise in SSDLC principles including threat modeling, secure design patterns, and secure coding. Hands‑on experience with commercial and open-source application security scanning tools (e.g., GitHub Advanced Security, Pnpm audit, Nodejsscan, Burp Suite, Invicti, OWASP ZAP, Gitleaks) for SAST, DAST, SCA, and secret detection. Strong understanding and practical experience with Web Application Firewalls (WAFs). Proficiency in cloud security controls for applications (e.g., GCP, Cloud Armor, Security Command Center, IAM hardening, Cloud Logging). Solid understanding of API security best practices and experience securing RESTful, tRPC and GraphQL APIs. Proficiency in SIEM & log management for application security, including log aggregation, correlation, visualization and threat detection. Proficiency in scripting for automation and integrating security tools into CI/CD pipelines. Strong understanding of common application vulnerabilities (e.g., OWASP Top 10). Excellent communication and collaboration skills to effectively convey security concepts to developers and other stakeholders. Preferred Experience Offensive security experience (e.g., bug bounty participation, CTFs) is a plus. Penetration testing experience is welcome but not mandatory. Security certifications such as CISSP, CSSLP, OSCP, or GIAC GWEB. Hands‑on experience with containerization (Docker, Kubernetes) and securing containerized applications. Experience with compliance frameworks relevant to application security (SOC 2 Type 2, ISO 27001) and supporting related audits. Experience in financial services or other regulated industries with stringent application security requirements. The Pay Range For This Role Is 150,000 - 210,000 CAD per year (Remote (Canada)) Seniority level Mid-Senior level Employment type Full-time Job function Information Technology Industries Technology, Information and Internet Referrals increase your chances of interviewing at N3XT by 2x Get notified about new Application Security Engineer jobs in Canada . #J-18808-Ljbffr
-
, , Canada Abnormal Security Full timeA leading cybersecurity firm in Canada is seeking a Staff Machine Learning Engineer to enhance its Attack Detection team's capabilities. This role involves architecting advanced ML systems, driving technical roadmaps, and mentorship. The ideal candidate has extensive experience in machine learning applications and a solid understanding of deep learning...
-
Cyber Security Engineer
4 days ago
Vancouver, British Columbia, VCG, Canada D3 Security Management Systems Full time $65,000 - $100,000 per yearCyber Security EngineerLocation: Greater Vancouver area candidates onlyThe Opportunity:D3 Security is transforming SecOps with Morpheus, our AI-driven Autonomous Security Operations Center (ASOC) platform. Morpheus automates Tier 1–3 analyst work with unmatched precision, processing millions of alerts in real time and empowering security teams to respond...
-
Staff Security Engineer, Security Partnerships
2 weeks ago
, , Canada Stripe Full timeStaff Security Engineer, Security Partnerships Join to apply for the Staff Security Engineer, Security Partnerships role at Stripe. About the Team The Stripe Security team is dedicated to improving the security of Stripe and its users. Our users trust us with some of their most sensitive information, and we make security a first‑class consideration in...
-
Senior Security Engineer
2 weeks ago
, , Canada Qualified Full timeJoin to apply for the Senior Security Engineer role at Qualified Qualified is the Agentic Marketing Platform for B2B companies. With Piper the AI SDR Agent, Qualified offers a whole new way to grow inbound pipeline. Piper operates across both the website and email, working to engage website visitors, capture leads, and convert buyers into pipeline around the...
-
Security Infrastructure Engineer
2 days ago
, , Canada TechBrains Full timeSecurity Engineering Golang GCP Cloud Security Terraform Join Coinbase as a Cloud Security Engineer and play a pivotal role in securing the future of finance. You'll be responsible for building security controls and advising engineering teams on secure architecture for our cloud and compute platforms. Your expertise will ensure the safety of these platforms...
-
Director, Security Engineering
3 weeks ago
, , Canada Pantheon Full timeAbout Pantheon Pantheon WebOps Platform powers the open web, running more than 300,000 sites in the cloud for customers including Google, Princeton, Salesloft, and Doctors Without Borders. Every day, thousands of developers and marketers create, iterate, and scale WordPress and Drupal sites to reach billions of people globally. Pantheon’s multitenant,...
-
Senior Sales Engineer
2 days ago
, , Canada Transmit Security Full timeJoin to apply for the Senior Sales Engineer - Canada role at Transmit Security Join to apply for the Senior Sales Engineer - Canada role at Transmit Security Get AI-powered advice on this job and more exclusive features. Transmit Security is a cross-channel identity and orchestration platform designed to simplify, accelerate, and reduce the cost of...
-
Software Security Engineer
2 days ago
, , Canada S4cloud Us Full timeWe are looking for a skilled Security Engineer to analyze software designs and implementations from a security perspective, and identify and resolve security issues. You will include the appropriate security analysis, defences and countermeasures at each phase of the software development lifecycle, to result in robust and reliable software. Responsibilities...
-
Information Security
7 days ago
, , Canada Mechanical Orchard Full timeAt Mechanical Orchard, we specialize in safely rewriting the most critical and complex business applications—the software that runs the world as we know it today—so they’re ready to adapt quickly and easily to market challenges and opportunities. Our approach emerged from observing the decades-long failure patterns in modernization efforts and is...
-
Senior Security Engineer, Cloud Security
7 days ago
, , Canada Webflow Full timeSenior Security Engineer, Cloud Security Argentina Remote At Webflow, our mission is to bring development superpowers to everyone. As the pioneer of the Website Experience Platform (WXP), we’re redefining how teams Build, Manage, and Optimize for the web — combining visual development, powerful CMS, AI-driven personalization, and seamless hosting in a...