Назад
Company hidden
2 дня назад

Senior Application Security Engineer II (Fintech)

180 000 - 220 000CAD
Формат работы
hybrid
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Application Security Engineer II (TypeScript/Node.js/AWS): Testing Relay’s platform services, identifying exploitable vulnerabilities, and shipping security fixes with an accent on threat modeling, white-box penetration testing, and software supply chain security. Focus on extending security tooling, assessing bug bounty reports, building durable application guardrails, and securing systems from design to deployment.

Location: Hybrid in Toronto, Ontario, Canada

Salary: CAD 180,000–220,000 annually; typical starting salary is CAD 200,000 for candidates fully ready for the defined scope.

Company

hirify.global is a digital banking platform that helps self-made business owners manage cash flow and build stronger businesses.

What you will do

  • Threat-model technical design documents and conduct white-box penetration tests in testing environments.
  • Own security testing for a defined portion of hirify.global’s platform, determine exploitability, and address vulnerabilities.
  • Triage bug bounty and vulnerability disclosure reports, reproduce issues, assess impact, and coordinate remediation.
  • Contribute directly to the production codebase by writing security patches and durable controls.
  • Extend and operate security tooling, including Datadog security, secrets scanning, logging, Burp Suite, and internal tools.
  • Enforce software supply chain controls such as SBOMs, dependency pinning, owner verification, private registries, and runtime SCA detection.

Requirements

  • 5–6 years of professional experience in application security, penetration testing, product security engineering, or a similar field.
  • Experience shipping production software and reading unfamiliar codebases well enough to implement fixes.
  • Deep knowledge of the OWASP Top 10 and real-world exploitation and mitigation techniques.
  • Experience with TypeScript, Node.js, Postgres, and AWS-based systems.
  • Daily use of AI development tools and experience building with AI, including understanding their limitations.
  • Strong communication, collaboration, ownership, and mentoring skills.

Culture & Benefits

  • Autonomous work on high-impact application security challenges.
  • Collaboration with senior engineers maintaining the authentication system and building DAST tooling.
  • Two weekly standups, a biweekly security champions session, and a weekly Hack The Box session.
  • Impact-based compensation with salary changes not limited to an annual review cycle.
  • Accommodations are available at every stage of the hiring process.

Hiring process

  • 60-minute video call with the hiring manager.
  • 60-minute live session with the team.
  • 60-minute secure code review and coaching session with two Customer Experience team members.
  • 45-minute video call with a member of the leadership team.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →