1 день назад
Application Security Engineer II (Fintech)
126 000 - 154 000CAD
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Application Security Engineer II (TypeScript/Node.js/AWS): Securing a digital banking platform through threat modeling, white-box penetration testing, vulnerability assessment, and direct code fixes with an accent on application security, software supply chain controls, and security tooling. Focus on testing previously uncovered platform services, determining exploitability, building guardrails, and extending security automation across the stack.
Location: Toronto, Canada; hybrid
Annual salary: 126,000–154,000 CAD; typical starting salary for full readiness is 140,000 CAD.
Company
is a digital banking platform providing self-made business owners with tools and visibility to manage cash flow and build stronger businesses.
What you will do
- Threat-model technical design documents and perform white-box penetration tests in testing environments.
- Own security testing for a defined portion of the platform, assess exploitability, and help remediate vulnerabilities.
- Triage bug bounty and vulnerability disclosure reports, reproduce findings, assess impact, coordinate fixes, and communicate outcomes.
- Contribute production code and write security patches directly when appropriate.
- Operate and extend security tooling, including Datadog security, secrets scanning, logging, Burp Suite, and internal tools.
- Enforce software supply chain controls such as SBOMs, dependency pinning, owner verification, private registries, and runtime SCA detection.
Requirements
- 2–4 years of professional experience in application security, penetration testing, product security engineering, or a similar field.
- Production software development experience and the ability to understand and modify unfamiliar codebases.
- Deep knowledge of the OWASP Top 10 and real-world exploitation and mitigation techniques.
- Experience building with AI tools in daily work, including understanding their limitations.
- Strong communication, collaboration, ownership, and mentoring skills.
Culture & Benefits
- Autonomous work on complex application security problems with meaningful impact.
- Regular collaboration through two weekly standups, a biweekly security champions session, and a weekly Hack The Box session.
- AI tools such as Claude Code and Cursor are used as daily development tools.
- Compensation can change as impact increases and is not limited to an annual review cycle.
- Accommodations are available at every stage of the hiring process.
Hiring process
- 60-minute video call with the hiring manager.
- 60-minute live session with the team.
- 60-minute secure code review and coaching session with two Customer Experience team members.
- 45-minute video call with a leadership team member.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →