
Senior Application Security Engineer
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Canada.
• Execute manual penetration tests on company systems.
• Develop AI-assisted tools and automation to enhance penetration testing coverage.
• Establish and apply testing methodologies for LLM applications, agents, and code generated by agents.
• Assess SAST findings, address genuine vulnerabilities, and fine-tune rules for false positives.
• Conduct secure code reviews for web applications, APIs, and AWS infrastructure.
• Create tools and security services within the Forward application ecosystem.
• Facilitate test-to-production reviews to ensure AI-generated work undergoes security evaluations prior to deployment.
• Articulate security risks to engineers, enabling them to prioritize and address identified issues.
• Minimum of 5 years of experience in application security, offensive security, or product security.
• Practical experience in penetration testing and code reviews for web applications, APIs, and AWS cloud infrastructure.
• A hacker mindset with an inquisitive nature regarding system vulnerabilities.
• Keen interest in leveraging AI for problem-solving.
• Knowledge of AI/LLM attack vectors, such as prompt injection, insecure agent tool usage, and vulnerabilities typical of AI-generated code.
• Proficiency in Ruby, Python, TypeScript, or Go.
• Familiarity with secure Software Development Life Cycle (SDLC) practices.
• Capable of conveying risk and priorities to both security and software engineers.
• Typically holds a Bachelor's Degree in Computer Science or a relevant technical field, or possesses equivalent industry experience.
• Flexible work arrangements: employees can choose to work from home, in the office, or a mix of both.
• Flexible working hours.
• Comprehensive medical insurance.
• Dental insurance coverage.
• Vision insurance options.
• Flexible time-off policy.
• Paid parental leave.
• RRSP matching program.
• Wellness reimbursement available.
• Days allocated for volunteering.
• Annual budget for professional development.
• Charitable donation matching program.
• Both virtual and in-person team events and celebrations.
• Target annual bonus of 10%.
Nord Security
Bugcrowd
PowerSchool
PowerSchool
Get handpicked remote jobs straight to your inbox weekly.