Live opening · Posted 12 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
Senior Application Security Engineer
Remote across the US and Canada | Full-time | Salary range: $150,000 to $230,000.
There are plenty of security roles where you identify a problem, write a report and hand it to engineering.
I’m working with a remote-first software company looking for a Senior Application Security Engineer who can work directly in the codebase and actually ship the fix.
You’ll contribute across a Node.js and React application, alongside Python, Terraform, AWS and Cloudflare infrastructure.
They need a strong application security engineer who is also a credible software engineer. Someone developers will want involved before something reaches production, not just when a scanner starts shouting afterwards.
What you’ll be doing
Writing production code to fix vulnerabilities and harden the application and infrastructure
Building security tooling and automation into CI/CD, making the secure route the easiest route
Reviewing RFCs and technical designs before problems become considerably more annoying
Defining secure patterns for authentication, authorization and API security
Leading threat modelling and turning the results into practical controls
Improving SAST, DAST, software composition analysis and secrets detection, with an emphasis on useful signals rather than burying engineers in alerts
Testing web applications and reviewing Node.js and React code using OWASP methodology
Running the bug bounty programme, from validating reports through to shipping fixes
Securing AI-powered product features against prompt injection, data leakage and overly broad access to tools, tokens or data
Using AI coding tools and agentic workflows in your own work, sensibly and with your eyes open
What they need to see
This role needs genuine software engineering ability. It is not enough to know what developers should change. You need to be comfortable opening the codebase and changing it yourself.
You should bring:
Strong application and web security experience
Production software engineering experience, ideally with Node.js and React
The ability to read, review and write code that other engineers respect
Experience integrating and maintaining SAST and DAST tooling within CI/CD
Hands-on AWS security experience
Infrastructure-as-code experience, ideally Terraform
A practical understanding of common application and network vulnerabilities, including how to remediate them
Applied knowledge of cryptography, PKI and TLS
Experience using AI development tools, plus a realistic understanding of the security problems they can introduce
Python and Cloudflare experience would be useful.
Experience securing AI or experience securing AI or LLM-powered features, running a bug bounty programme or contributing to SOC 2 controls would also be helpful.
Why consider it?
The company builds software used by people working across science and research. It is remote-first, well-backed and has teams across Canada and the US.
The interesting bit is the remit. You won’t be joining to police engineering from the sidelines. You’ll help decide how security is built into the product, the infrastructure and the way engineers work, then write the code to make it happen.
Work arrangement
No
More openings worth a look
Recently tracked roles with full details and direct application links.