17 Aug
|
Doist
|
Montreal
Workleap is a Montreal-based tech company, founded in 2006.
Workleap
Agent , our newest solution built to make every manager more effective, and ShareGate , the world's leading solution for Microsoft 365 migration and governance. More than 15,000 companies worldwide trust us to do exactly that. If you're the kind of person who gets excited by a hard problem and wants to help shape what comes next, there's a place for you here.
You will build the security layer for how Workleap writes software, and then you will teach it to run itself. SAST, DAST, SCA, and secret scanning wired into GitHub Actions so findings land where developers already work, with the noise tuned out rather than tolerated. Threat modeling on architectural changes.
Where it goes next is the actual reason this role exists. We are moving toward agentic security review, where agents perform the first pass on every pull request, reason about the change in context, and escape what matters to a human. Build the security guardrails for AI assisted and agentic development so speed and safety stop being a tradeoff Move security review from human bottleneck to automated first pass with human judgment reserved for what is genuinely ambiguous Achieve near-zero developer friction on security signals by wiring SAST/DAST/SCA into CI/CD with noise tuned low enough that findings actually get fixed.
Lead threat modeling on new features and architectural changes Drive real remediation of application security vulnerabilities, measured by risk retired and not tickets closed Harden Azure environments and deployment patterns alongside Infrastructure SecOps You will join LeapSec and report to the Director of Infrastructure and Security. We're a small team with broad reach covering product security, cloud security, and governance across Workleap and ShareGate. That means your work ships, you own it end to end, and you set the priorities that matter.
You will partner closely with the AI SDLC team,
which builds the internal platform that lets AI agents operate across the development lifecycle, and with product engineering across the organization. Five or more years in application security, DevSecOps, or security focused software development, with a real engineering background behind it Deep working knowledge of web application security, OWASP Top 10, and CWE Top 25 Proven experience building security automation into CI/CD pipelines, GitHub Actions preferred Built and shipped real agent tooling, not just used it. MCP servers, Claude skills, subagents, and custom tools that other people depend on Understanding of the security model of agentic systems themselves.
Proficiency in Python for building tooling, not just scripting around it Hands on experience with AI assisted and agentic development workflows and a clear view of where they break Solid grasp of Azure services, infrastructure security, and deployment patterns The ability to explain a risk tradeoff to an engineer and to an executive in the same week and be understood by both Robust assets Secure code review experience in C#/.NET Experience running vulnerability discovery and triage with a developer community Annual bonus program. LTIP program, share in Workleap's long-term growth. RRSP + Family health insurance + telemedicine + annual wellness budget.
Flexible vacation policy. Remote work, with access to our Montreal office. At Workleap, we build software that sits at the center of how people experience work, every day, at every level. Priorities shift, decisions get made with the information we have, and we iterate.
If you thrive on intensity and ambiguity doesn't slow you down, you'll feel right at home. AI is part of our toolkit. We use it to go faster and decide smarter, not to replace judgment. Here's how it works: a first call with a recruiter, then a virtual interview with the hiring manager.
We use AI to support certain steps of the process, but every hiring decision remains human.
📌 Staff Application Security Specialist (Montreal)
🏢 Doist
📍 Montreal