2 дня назад
Senior Application Security Engineer II (Fintech)
180 000 - 220 000CAD
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Текст:
TL;DR
Senior Application Security Engineer II (TypeScript/Node.js/AWS): Testing Relay’s platform services, identifying exploitable vulnerabilities, and shipping security fixes with an accent on threat modeling, white-box penetration testing, and software supply chain security. Focus on extending security tooling, assessing bug bounty reports, building durable application guardrails, and securing systems from design to deployment.
Location: Hybrid in Toronto, Ontario, Canada
Salary: CAD 180,000–220,000 annually; typical starting salary is CAD 200,000 for candidates fully ready for the defined scope.
Company
is a digital banking platform that helps self-made business owners manage cash flow and build stronger businesses.
What you will do
- Threat-model technical design documents and conduct white-box penetration tests in testing environments.
- Own security testing for a defined portion of ’s platform, determine exploitability, and address vulnerabilities.
- Triage bug bounty and vulnerability disclosure reports, reproduce issues, assess impact, and coordinate remediation.
- Contribute directly to the production codebase by writing security patches and durable controls.
- Extend and operate security tooling, including Datadog security, secrets scanning, logging, Burp Suite, and internal tools.
- Enforce software supply chain controls such as SBOMs, dependency pinning, owner verification, private registries, and runtime SCA detection.
Requirements
- 5–6 years of professional experience in application security, penetration testing, product security engineering, or a similar field.
- Experience shipping production software and reading unfamiliar codebases well enough to implement fixes.
- Deep knowledge of the OWASP Top 10 and real-world exploitation and mitigation techniques.
- Experience with TypeScript, Node.js, Postgres, and AWS-based systems.
- Daily use of AI development tools and experience building with AI, including understanding their limitations.
- Strong communication, collaboration, ownership, and mentoring skills.
Culture & Benefits
- Autonomous work on high-impact application security challenges.
- Collaboration with senior engineers maintaining the authentication system and building DAST tooling.
- Two weekly standups, a biweekly security champions session, and a weekly Hack The Box session.
- Impact-based compensation with salary changes not limited to an annual review cycle.
- Accommodations are available at every stage of the hiring process.
Hiring process
- 60-minute video call with the hiring manager.
- 60-minute live session with the team.
- 60-minute secure code review and coaching session with two Customer Experience team members.
- 45-minute video call with a member of the leadership team.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →