Senior Security Engineer, Application Security
Offre en anglaisThe role focuses on identifying and remediating vulnerabilities in first and third-party code while building shift-left tooling and CI/CD guardrails. Responsibilities include leading threat modeling, managing the bug bounty program, and hardening AI-assisted code generation workflows.
- Hybride
- Kitchener, ON
- Publié 27 août 2026
- Postuler avant le 26 sept. 2026
- 1 poste
D’autres postes auxquels postuler directement
Des possibilités semblables publiées par des employeurs qui recrutent sur Jobs.ca, sans formulaire externe.
Forgeahead Solutions Corporation
Technical Lead and Senior Software Engineer
- Sur place
City of Toronto
Senior Project Manager CS
- Hybride
Revenu Québec
Cheffe ou chef du Service des produits liés à la facturation obligatoire
- Hybride
Résumé du poste
About Faire Faire is a technology wholesale platform built on the belief that the future is local. Independent retailers around the globe collectively represent a multi-hundred-billion-dollar wholesale market that has historically been fragmented and offline. At Faire, we're using the power of tech, data, and machine learning to connect this thriving community of entrepreneurs across the globe. Picture your favorite boutique in town — we help them discover the best products from around the world to sell in their stores. With the right tools and insights, we believe that we can level the playing field so businesses can grow and local communities can thrive. We’re looking for smart, resourceful and passionate people to join us as we power the shop local movement. If you believe in community, come join ours. About This Role Our Engineering organization owns the software that makes our marketplace work. Our Application Security function is focused on keeping vulnerabilities out of the code and software as it's built and shipped, owning the SDLC from commit to production. We care about good engineering practice and love to write software that is secure, tested, easy to maintain, and can scale to millions of users. We build scalable, reusable frameworks; consult with product teams; listen to the data; and iterate. As a Senior Security Engineer, Application Security, you'll collaborate with us to: Find and fix vulnerabilities in first-party code and third-party dependencies using AI-powered detection, SAST, DAST, SCA, and secret scanning tooling. Build shift-left tooling and CI/CD guardrails that make the secure path the default in the build pipeline. Own offensive security engagements such as penetration tests with external vendors. Evaluate and harden the security of AI-assisted code generation workflows. Own the bug bounty program and the vulnerability management lifecycle end to end, from intake through remediation and closure. Lead threat modeling and secure design reviews for new products and high-risk platform changes, shaping the architecture before the code is written rather than reviewing it after. Conduct security reviews and consultations with product and platform teams and develop secure coding standards and scaling frameworks for recurring vulnerability classes. We're Excited About You Because You Have Hands-on experience integrating security into the software development lifecycle. Experience driving vulnerability remediation across teams you do not own, with a point of view on how to set severities, hold SLAs, and get things actually closed. Exposure to offensive security, whether that is running a bug bounty program, scoping penetration tests with external vendors, or finding and reporting real vulnerabilities yourself. A passion for coding and solving security problems scalably with code and automation, rather than with process and policy. Comfort writing and reviewing code in OOP languages such as Kotlin, Java, Python, or TypeScript, enough to read an unfamiliar service, judge whether a finding is real, and open the pull request that fixes it. Practical experience with AppSec detection tooling (SAST, DAST, SCA, or secret scanning), including the unglamorous parts: deploying it, tuning the rules, and cutting the false positives so engineers trust the results. A thorough understanding of web application security principles and common vulnerabilities, including OWASP Top 10, with an instinct for the systemic fix behind the individual finding. Experience leading threat models on systems you did not build, and the judgement to know which designs need one and which do not. Experience working in modern cloud computing environments such as AWS or GCP. The ability to explain risk to product engineers in a way that makes them want to fix it, and the credibility to be invited into design discussions rather than added as a gate. Curiosity about the security of AI-assisted development, and interest in figuring out what changes when a meaningful share of the code is machine-generated. Technologies We Use And Teach Kotlin, Typescript, Python AppSec tooling - SAST/DAST/SCA/secret scanning AWS, OCI, Terraform, Kubernetes AI tooling - Cursor, Claude Salary Range Canada: the pay range for this role is $160,000 to $220,000 per year. This role will also be eligible for equity and benefits. Actual base pay will be determined based on permissible factors such as transferable skills, work experience, market demands, and primary work location. The base pay range provided is subject to change and may be modified in the future. Faire uses Artificial Intelligence (AI) to screen and select applicants for this position. This job posting is for an existing vacancy. Hybrid Faire employees currently go into the office 3 days per week on Tuesdays, Thursdays, and a third flex day of their choosing (Monday, Wednesday, or Friday). Additionally, hybrid in-office roles will have the flexibility to work remotely up to 4 weeks per year. Specific Workplace and Information Technology positions may require onsite attendance 5 days per week as will be indicated in the job posting. Why you’ll love working at Faire Move fast: You'll own meaningful problems that serve customers around the globe with the agency to move fast and see your results clearly. Equipped to scale: We invest in what matters, including the latest enterprise AI tools, to help you work smarter and get more out of every day. Best in class: Our team is full of sharp, kind, and generous colleagues who care about their craft and about helping you grow in yours. Real rewards. Competitive pay, equity, and comprehensive benefits designed to support your life inside and outside of work. Belonging: We're intentional about building an environment where every Faire employee has equal access to opportunities, growth, and success. Faire was founded in 2017 by a team of early product and engineering leads from Square. We’re backed by some of the top investors in retail and tech including: Y Combinator, Lightspeed Venture Partners, Forerunner Ventures, Khosla Ventures, Sequoia Capital, Founders Fund, and DST Global. We have headquarters in San Francisco and Kitchener-Waterloo, and a global employee presence across offices in Toronto, London, and New York. To learn more about Faire and our customers, you can read more on our blog. Faire provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, genetics, sexual orientation, gender identity or gender expression. Faire is committed to providing access, equal opportunity and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. Accommodations are available throughout the recruitment process and applicants with a disability may request to be accommodated throughout the recruitment process. We will work with all applicants to accommodate their individual accessibility needs. To request reasonable accommodation, please fill out our Accommodation Request Form (https://bit.ly/faire-form) Privacy For information about the type of personal data Faire collects from applicants, as well as your choices regarding the data collected about you, please visit Faire’s Privacy Notice (https://www.faire.com/privacy) 244 results found No results found Afghanistan+93 Åland Islands+358 Albania+355 Algeria+213 American Samoa+1 Andorra+376 Angola+244 Anguilla+1 Antigua & Barbuda+1 Argentina+54 Armenia+374 Aruba+297 Ascension Island+247 Australia+61 Austria+43 Azerbaijan+994 Bahamas+1 Bahrain+973 Bangladesh+880 Barbados+1 Belarus+375 Belgium+32 Belize+501 Benin+229 Bermuda+1 Bhutan+975 Bolivia+591 Bosnia & Herzegovina+387 Botswana+267 Brazil+55 British Indian Ocean Territory+246 British Virgin Islands+1 Brunei+673 Bulgaria+359 Burkina Faso+226 Burundi+257 Cambodia+855 Cameroon+237 Canada+1 Cape Verde+238 Caribbean Netherlands+599 Cayman Islands+1 Central African Republic+236 Chad+235 Chile+56 China+86 Christmas Island+61 Cocos (Keeling) Islands+61 Colombia+57 Comoros+269 Congo - Brazzaville+242 Congo - Kinshasa+243 Cook Islands+682 Costa Rica+506 Côte d’Ivoire+225 Croatia+385 Cuba+53 Curaçao+599 Cyprus+357 Czechia+420 Denmark+45 Djibouti+253 Dominica+1 Dominican Republic+1 Ecuador+593 Egypt+20 El Salvador+503 Equatorial Guinea+240 Eritrea+291 Estonia+372 Eswatini+268 Ethiopia+251 Falkland Islands+500 Faroe Islands+298 Fiji+679 Finland+358 France+33 French Guiana+594 French Polynesia+689 Gabon+241 Gambia+220 Georgia+995 Germany+49 Ghana+233 Gibraltar+350 Greece+30 Greenland+299 Grenada+1 Guadeloupe+590 Guam+1 Guatemala+502 Guernsey+44 Guinea+224 Guinea-Bissau+245 Guyana+592 Haiti+509 Honduras+504 Hong Kong SAR China+852 Hungary+36 Iceland+354 India+91 Indonesia+62 Iran+98 Iraq+964 Ireland+353 Isle of Man+44 Israel+972 Italy+39 Jamaica+1 Japan+81 Jersey+44 Jordan+962 Kazakhstan+7 Kenya+254 Kiribati+686 Kosovo+383 Kuwait+965 Kyrgyzstan+996 Laos+856 Latvia+371 Lebanon+961 Lesotho+266 Liberia+231 Libya+218 Liechtenstein+423 Lithuania+370 Luxembourg+352 Macao SAR China+853 Madagascar+261 Malawi+265 Malaysia+60 Maldives+960 Mali+223 Malta+356 Marshall Islands+692 Martinique+596 Mauritania+222 Mauritius+230 Mayotte+262 Mexico+52 Micronesia+691 Moldova+373 Monaco+377 Mongolia+976 Montenegro+382 Montserrat+1 Morocco+212 Mozambique+258 Myanmar (Burma)+95 Namibia+264 Nauru+674 Nepal+977 Netherlands+31 New Caledonia+687 New Zealand+64 Nicaragua+505 Niger+227 Nigeria+234 Niue+683 Norfolk Island+672 North Korea+850 North Macedonia+389 Northern Mariana Islands+1 Norway+47 Oman+968 Pakistan+92 Palau+680 Palestinian Territories+970 Panama+507 Papua New Guinea+675 Paraguay+595 Peru+51 Philippines+63 Poland+48 Portugal+351 Puerto Rico+1 Qatar+974 Réunion+262 Romania+40 Russia+7 Rwanda+250 Samoa+685 San Marino+378 São Tomé & Príncipe+239 Saudi Arabia+966 Senegal+221 Serbia+381 Seychelles+248 Sierra Leone+232 Singapore+65 Sint Maarten+1 Slovakia+421 Slovenia+386 Solomon Islands+677 Somalia+252 South Africa+27 South Korea+82 South Sudan+211 Spain+34 Sri Lanka+94 St. Barthélemy+590 St. Helena+290 St. Kitts & Nevis+1 St. Lucia+1 St. Martin+590 St. Pierre & Miquelon+508 St. Vincent & Grenadines+1 Sudan+249 Suriname+597 Svalbard & Jan Mayen+47 Sweden+46 Switzerland+41 Syria+963 Taiwan+886 Tajikistan+992 Tanzania+255 Thailand+66 Timor-Leste+670 Togo+228 Tokelau+690 Tonga+676 Trinidad & Tobago+1 Tunisia+216 Turkey+90 Turkmenistan+993 Turks & Caicos Islands+1 Tuvalu+688 U.S. Virgin Islands+1 Uganda+256 Ukraine+380 United Arab Emirates+971 United Kingdom+44 United States+1 Uruguay+598 Uzbekistan+998 Vanuatu+678 Vatican City+39 Venezuela+58 Vietnam+84 Wallis & Futuna+681 Western Sahara+212 Yemen+967 Zambia+260 Zimbabwe+263
Ce que vous ferez
The role focuses on identifying and remediating vulnerabilities in first and third-party code while building shift-left tooling and CI/CD guardrails. Responsibilities include leading threat modeling, managing the bug bounty program, and hardening AI-assisted code generation workflows.
Exigences
Candidates need hands-on experience integrating security into the SDLC and proficiency in OOP languages like Kotlin, Java, Python, or TypeScript. Practical experience with AppSec detection tools and a deep understanding of OWASP Top 10 and cloud environments (AWS/GCP) are required.
Avantages
• Equity • Comprehensive benefits
Compétences indiquées
- KubernetesSouhaitée
- TypeScriptSouhaitée
- Amazon Web ServicesSouhaitée
- KotlinSouhaitée
- JavaSouhaitée
- Google CloudSouhaitée
- PythonSouhaitée
Autres compétences pertinentes
Relevées dans la description du poste. Confirmez les exigences importantes ci-dessus.
- Application Security
- SAST
- DAST
- SCA
- Secret Scanning
- Threat Modeling
- Penetration Testing
- Vulnerability Management
- Secure Coding Standards
- Kotlin
- Java
- Python
- TypeScript
- AWS
- GCP
- Kubernetes
Domaines d’emploi
- Security & Safety
- Software
- Technology
- Engineering
Renseignements supplémentaires
- Expérience minimale
- 5+ ans
- Postuler avant le
- 26 sept. 2026
- Langue de l’offre
- anglais
- Heures de travail
- 40 heures par semaine
- Présence au bureau
- 3 jours par semaine
- Niveau d’expérience
- Mid-Senior level