
Senior Engineer, Application Security
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Canada.
• Act as a key pillar within the AppSec team.
• Drive the strategic transition towards developer-embedded security and the operationalization of Secure by Design.
• Create, develop, and expand AppSec methodologies.
• Work collaboratively with Vulnerability Operations to enhance vulnerability triage and remediation processes.
• Integrate security measures into feature designs, pull requests, Infrastructure as Code (IaC) checks, and daily engineering practices.
• Design threat models for features and infrastructure.
• Assess and improve AI-generated threat modeling workflows.
• Set up, refine, and manage SAST, DAST, SCA, Secrets, and LLM scanner rule sets.
• Establish and stabilize new AppSec protocols while preserving existing security controls.
• Initiate AI-driven automation for vulnerability triage and remediation.
• Offer technical remediation guidance for structural issues and web application vulnerabilities.
• Promote developer security and advocate for the Security Champions program.
• Conduct secure coding workshops.
• Collaborate with Platform and Infrastructure Security teams to develop automated CI/CD safeguards.
• Extensive hands-on experience in Application Security, Product Security, or Secure Software Engineering within high-growth cloud environments.
• Bachelor’s degree in Computer Science, Cybersecurity, or Software Engineering, or equivalent practical experience.
• Profound knowledge of web application vulnerabilities (OWASP Top 10), business logic flaws, and secure coding standards.
• Proven experience in tuning SAST, DAST, SCA, Secrets, and LLM scanner pipelines in CI/CD settings.
• Demonstrated expertise in threat modeling techniques, Secure by Design principles, and guiding developers through code fixes.
• Established experience in utilizing AI/LLM tools to automate security evaluations, enhance triage processes, and streamline developer security practices.
• Proficiency in modern software development languages (e.g., Python, Go, JavaScript/TypeScript, Java).
• Strong cross-functional influence and communication skills to effectively lead the Security Champions program.
• Applicants must disclose any criminal convictions.
• A criminal record check is required as part of the hiring process.
• Must have legal eligibility to work in the country where the position is advertised.
• Exceptional benefits and perks, including equity for all Lightspeeders.
• Continuous development of both your skills and business knowledge with boundless growth opportunities.
• Significant autonomy and a flexible work culture.
• Innovation time allocated for exploration and learning during work hours.
• Influence the company culture by participating in cultural and technical committees.
• Numerous growth opportunities into technical or management positions.
• Lightspeed equity scheme (we are all owners).
• Flexible paid time off and remote work policies.
• Health insurance coverage.
• Contributions to your pension plan - RRSP.
• Health and wellness benefit of $500 annually.
• Paid leave and support for new parents.
• Access to a mental health online platform, counseling, and coaching services.
• Training opportunities to enhance your skills and advance your career.
• Designated volunteer day.
• Fully stocked kitchen (hot and cold beverages, meals provided).
• Happy hours to foster relationships with colleagues after work.
• Ongoing opportunities for learning.
• Global mobility options.
• Benefits tailored to support you.
• A diverse and inclusive workplace.
• Accommodations available upon request for candidates participating in all facets of the selection process.
Intuitive
Intuitive
Applied Research Solutions
Quanata
Get handpicked remote jobs straight to your inbox weekly.