30 Jul
|
Highspring
|
Canada
We are seeking a Senior Application Security Developer to join a strategic enterprise Application Security transformation initiative. This role will play a key part in strengthening application security capabilities while contributing to the evaluation, integration, and enhancement of modern security tooling across the software delivery lifecycle.
This is a highly technical role requiring strong software development expertise in Python, combined with practical experience in application security, secure development practices, and vulnerability management.
The ideal candidate is first and foremost a strong developer, with a security mindset and the ability to build, customize, and optimize security solutions that align with business requirements.
Key Responsibilities
- Application Security Development
- Design, develop, and maintain custom Python-based security solutions and integrations.
- Build automation scripts and internal tooling to support secure software delivery pipelines.
- Develop custom connectors, APIs, and integrations between AppSec platforms and enterprise environments.
- Enhance and extend existing security tooling to better align with business and operational needs.
- Security Tooling & Platform Integration
- Support the implementation, configuration, and optimization of application security tools such as Snyk, Aqua Security, or JFrog Xray, or similar tools.
- Contribute to the analysis and selection of the best-fit AppSec tooling strategy.
- Integrate security tooling into CI/CD pipelines and software delivery workflows.
- Assist in building proof-of-concepts and validating tooling capabilities against business needs.
- Secure Development Practices
- Collaborate with development teams to implement secure-by-design principles.
- Analyze vulnerabilities and provide remediation recommendations.
- Improve application security posture across modern cloud-native and enterprise applications.
- Contribute to threat modeling, secure code reviews, and vulnerability triage.
Collaboration & Enablement
- Work closely with the AppSec Architect, DevSecOps Engineers, and Software Developers.
- Support the ramp-up and knowledge transfer within the AppSec squad.
- Help bridge the gap between security and software engineering teams.
Required Qualifications
- 5+ years of enterprise software development experience, with strong expertise in Python.
- Strong experience building APIs, automation, integrations, and backend services.
- Solid understanding of secure development practices and application security principles.
- Experience integrating tools into CI/CD pipelines (GitHub Actions, Jenkins, GitLab CI, Azure DevOps, etc.).
- Experience working in cloud environments (AWS, Azure, or GCP).
- Solid problem-solving skills and ability to build custom solutions when off-the-shelf tools are insufficient.
Nice-to-Have
- Hands-on experience with Snyk, Aqua Security, JFrog Xray or similar tools.
- Experience with Software Composition Analysis (SCA), container security, or SBOM management.
- Familiarity with secrets detection and dependency scanning.
- Knowledge of modern DevSecOps practices.
- Experience in regulated enterprise environments.
Profile We're Looking For
- Strong developer-first profile with a security mindset.
- Able to build and adapt security solutions rather than only operate tools.
- Comfortable working in ambiguous environments where tooling and strategy are still evolving.
- Capable of balancing development speed, security requirements, and business realities.
📌 Senior Application Security Developer (Canada)
🏢 Highspring
📍 Canada