Application Security Engineer

5 days ago


Canada Fragomen Full time

Application Security Engineer & Architect Fragomen, an Am Law 100 Firm and the leading global immigration services provider, is seeking an Application Security Engineer & Architect. This Engineer will join our talent Cyber Security team, which plays a pivotal role in Fragomen's Immigration Technology Innovation Lab. Our industry‑leading, immigration‑specific applications and technology is undergoing tremendous transformation and security is on the critical path to success in that endeavor. This is an excellent opportunity for a cyber security professional who is passionate about security, capable of effecting change, and ready to take on new challenges. How will you make a difference as an Application Security Engineer & Architect at Fragomen? Evaluate, propose, and test security verification tools to integrate into development pipelines (e.g., SAST, DAST, SCA, and code‑scanning tools for secrets and API keys). Lead web application reconnaissance efforts, including understanding underlying technology stacks, risk posture, data handling, authentication/authorization, and proprietary controls. Manage SDLC initiatives around Fragomen’s DAST processes, including Invicti integration, discovery scanning, triaging results, and risk reporting. Conduct application security penetration testing engagements, manually assessing risk surfaces of both existing and emerging web applications; document findings and assist with remediation advice. Perform architectural reviews of applications to ensure secure design and implementation. Secure source code through in‑depth analysis (.NET, Python, Java, etc.), assisting with SAST/SCA triage, reporting, and addressing development team remediation queries. Collaborate with 3rd‑party security firms by providing credentials, demos, and evaluating the accuracy and proficiency of penetration testing reports. Act as the proactive security liaison between AppSec and key stakeholders (Software Development, DevOps, Compliance teams), including potential external customer‑facing communications. Automate security workflows and integrate security checks into build and release pipelines, optimizing security testing based on policy, code changes, and risk. Design and recommend gating strategies to enforce security controls at appropriate SDLC stages. Operate and maintain security tools while participating in tasks across other IT Security domains (threat detection, security engineering, architecture, incident response). Stay ahead of the dynamic security landscape by securing and architecting protections for emerging technologies, including AI, tooling, and frameworks, aligned with business needs. Leverage your valuable skills and experience to make an impact at Fragomen: 3+ years of experience in web application development and cybersecurity. Strong scripting and coding skills with frameworks such as .NET, Python, Bash, PowerShell. Experience with CICD tools (e.g., Jenkins, GitLab, Bamboo, Octopus, Proget). Knowledge of SDLC best practices. Familiarity with cloud‑native security tools and Kubernetes is a plus. Strong communication skills, capable of maintaining professionalism under pressure. Relevant certifications such as GWEB, OSCP preferred. BA degree in related field or equivalent experience. All offers and/or employment contracts are contingent upon the successful completion of the Firm’s pre‑employment screening process. This process may include verifying the candidate’s identity, confirming legal authorization to work in the offered position’s location, and conducting a comprehensive background check, where permitted by local regulations. #J-18808-Ljbffr


  • Security Engineer

    2 weeks ago


    , , Canada N3XT Full time

    Security Engineer - Application Security Join to apply for the Security Engineer - Application Security role at N3XT . Liberating Money We're looking for a highly skilled and passionate Security Engineer with a dedicated focus on Application Security to join our team. You'll embed robust security practices throughout the entire software development lifecycle...


  • , , Canada Mechanical Orchard Full time

    At Mechanical Orchard, we specialize in safely rewriting the most critical and complex business applications—the software that runs the world as we know it today—so they’re ready to adapt quickly and easily to market challenges and opportunities. Our approach emerged from observing the decades-long failure patterns in modernization efforts and is...


  • Canada - Remote Certn Full time US$80,000 - US$120,000 per year

    Who We AreAt Certn, we're revolutionizing background screening with The World's Easiest Background Check — fast, global, and powered by tech. We're not about outdated processes and red tape. We're about innovation, speed, and impact. If you're looking for a place where ownership, collaboration, and creativity thrive, this is it.The OpportunityWe're looking...


  • , , Canada Webflow Full time

    About the role: At Webflow, our mission is to bring development superpowers to everyone. As the pioneer of the Website Experience Platform (WXP), we’re redefining how teams Build, Manage, and Optimize for the web — combining visual development, powerful content management systems, AI-driven personalization, seamless hosting, and end-to-end analytics in a...


  • , , Canada 1Password Full time

    1Password is growing faster than ever. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle, Red Bull Racing and the Utah Mammoth. About 1Password At 1Password, we’re building the foundation for a safe, productive digital future....


  • , , Canada CanCap Group Inc. Full time

    Join to apply for the Cloud and Application Security Engineer role at CanCap Group Inc. The CanCap Group (“CanCap”) is a privately‑owned Canadian national financial services company with multiple verticals across automotive, consumer, and merchant lending portfolios. We manage the entire lifecycle of finance receivables from credit adjudication through...


  • , , Canada Sardine Full time

    Join to apply for the Senior Application Security Engineer role at Sardine . Who We Are We are a leader in fraud prevention and AML compliance. Our platform uses device intelligence, behavior biometrics, machine learning, and AI to stop fraud before it happens. Today, over 300 banks, retailers, and fintechs worldwide use Sardine to stop identity fraud,...


  • , , Canada 1Password Full time

    Senior Security Engineer, Application Security Join to apply for the Senior Security Engineer, Application Security role at 1Password. 1Password is growing faster than ever. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle, Red...


  • , , Canada GlossGenius Full time

    GlossGenius is building an ecosystem enabling entrepreneurs to succeed. We empower small business owners to focus on being creators, not admins, by offering a range of business management tools including booking and scheduling, marketing, analytics, payment processing and much more. Over 100,000 small business owners have chosen to rely on GlossGenius every...


  • , , Canada GitLab Full time

    Senior Security Engineer, Application Security (AMER) Join to apply for the Senior Security Engineer, Application Security (AMER) role at GitLab. GitLab is an open-core software company that develops the most comprehensive AI-powered DevSecOps Platform, used by more than 100,000 organizations. Our mission is to enable everyone to contribute to and co-create...