Loading...

Senior Application Security Engineer

  • Company: Get A Job.ai
  • Location: Canada, USA
  • Salary: Pay not listed
  • Work type: Remote

Website Get A Job.ai

Represented by Get A Job.ai

About This Opportunity

Our talent team is representing a confidential SaaS organization seeking a Senior Application Security Engineer to strengthen their secure software development lifecycle and reduce application risk across product, platform, and AI-powered features. This is a senior individual contributor role that blends deep code-level application security work with strong cross-functional partnership.

This position is calibrated at a senior IC level: owning semi-annual or annual goals, solving ambiguous problems with sound judgment, improving operational processes, and driving meaningful cross-team collaboration and influence.

Responsibilities

  • Secure SDLC and Threat Modeling: Own and continuously improve the secure software development lifecycle. Perform application security reviews, threat modeling, and deep code-level analysis for high-impact product, platform, and AI features before launch. Provide practical security architecture guidance and help define application-security guardrails, secure design expectations, and risk models.
  • Vulnerability Management: Drive execution-heavy vulnerability management across internal reviews, bug bounty, pentests, SCA/runtime findings, and other research signals. Go beyond identifying issues—read the code, explain root cause, propose the safest fix, and directly implement or support remediation when needed for complex vulnerabilities.
  • Hands-on Validation: Perform hands-on validation and offensive security testing of applications and fixes, including exploit development, bypass testing, adversarial thinking, and focused red-team-style exercises. Work across common application security issues including authentication and authorization weaknesses, access control risks, OAuth and CSRF design flaws, SSRF, cryptographic issues, unsafe execution patterns, and dependency vulnerabilities.
  • Tooling and Automation: Configure and improve AppSec tooling and integrations, including SAST configuration, dashboards, and controls. Select, build, or refine security tooling and workflow enrichments that reduce manual effort and scale AppSec operations. Use AI to automate and scale security processes where it materially improves speed, consistency, or signal quality.
  • AI Security: Embed AI-specific security checks into SDLC reviews and code analysis, including input and output handling, AI-exposed APIs, prompt and response guardrails, and abuse or data-exfiltration paths. Partner cross-functionally on AI security requirements and controls.
  • Engineering Enablement: Support and scale security enablement for engineers and security champions. Provide actionable remediation guidance, secure patterns, and examples. Produce clear documentation, metrics, and written narratives that improve AppSec visibility and decision-making.

What We're Looking For

Required Experience and Skills:

  • 5+ years of software engineering or application security experience, with meaningful hands-on AppSec depth in modern SaaS environments
  • Strong software development skills and the ability to read, write, and ship production code; Ruby experience is highly valuable, Python or similar scripting ability is a plus
  • Strong Linux and cloud fundamentals, ideally with experience in GCP-backed environments
  • Deep familiarity with common AppSec issues, secure design, secure authentication and authorization patterns, vulnerability management, and developer security tooling
  • Demonstrated ability to perform deep code review, penetration testing, and exploit-oriented validation, and to either fix vulnerabilities directly or work closely with engineers to land durable remediations
  • Experience handling findings from bug bounty, pentests, internal reviews, or automated security tooling through closure and verification
  • Experience using AI-assisted tools, automations, APIs, or structured workflows to improve engineering or security processes at scale
  • Experience securing AI-powered systems or features, including AI API exposure, prompt and response handling, data protection, misuse scenarios, and monitoring expectations
  • Strong written and verbal communication, stakeholder management, and influencing skills across technical and non-technical partners

Preferred Qualifications:

  • Experience supporting or leading security reviews for AI-native products, internal agents, or AI-assisted engineering workflows
  • Experience improving secure-by-design practices and AppSec observability in a fast-moving engineering organization
  • Experience with security training, developer enablement, or security champions programs
  • Relevant security certifications

Location: Canada or USA (remote)

How We Work With You

Candidates apply directly through Get A Job.ai. Our recruiting team will screen qualified applicants and coordinate interviews with the client organization. If you're selected to move forward, we'll submit your profile to the client and guide you through their interview process. Please do not contact the client directly—all communication should flow through our team to ensure the best experience for everyone involved.

Pay

Compensation details will be discussed during the screening process based on location and experience level.

Equal Employment Opportunity: Get A Job.ai is committed to providing equal employment opportunities to all applicants regardless of race, color, religion, sex, national origin, age, disability, genetics, veteran status, sexual orientation, gender identity, or any other legally protected status.

Apply with Get A Job.ai

A recruiter will review your profile and submit you to the client. Do not contact the client directly.

More options

Apply with Get A Job.ai

Apply through Get A Job.ai. A recruiter will review your profile and submit you. Do not contact the client directly.

Apply through Get A Job.ai. A recruiter will review your profile and submit you.

Local insights for this role are preparing — this section updates automatically in a few seconds (or refresh).

Listing facts

  • Role Senior Application Security Engineer
  • Employer Get A Job.ai
  • Location Canada, USA · Remote-friendly
  • Type Full Time
  • Pay (from listing) Pay not listed
  • Posted August 31, 2026
  • Apply by October 1, 2026
  • Country United States
  • Overview Full job description on this page (699 words)

Facts above come from this job record on Get A Job.AI — not copied from third-party review sites.

Limited public data for this employer

We only show facts we can ground in public sources (Wikidata, O*NET, news/discussion links, or this listing). We do not invent Glassdoor-style ratings, salaries, or testimonials when data is thin. Use the listing facts, occupation context, and related openings below while we continue researching.

Explore related openings

Occupation family: Application Security Engineer

Keep exploring on Get A Job.ai

Not quite the right fit? Your next opportunity is a click away.

Hiring instead? Post a job and reach candidates searching right now.

Senior Application Security Engineer Get A Job.ai · Canada, USA