Application Security Developer - C$80,000 - C$116,600 A Year (Toronto)

Application Security Developer - C$80,000 - C$116,600 A Year (Toronto)

27 Aug
|
Autodesk
|
Toronto

27 Aug

Autodesk

Toronto

Position Overview Our team of security experts helps Autodesk design, build, deploy, and maintain secure products. We embed security across the full software development lifecycle—from inception and design to development, testing, and cloud operations—while proactively addressing emerging threats.Our mission is to stay ahead of adversaries and protect our customers’ data and investments by strengthening applications, services, and infrastructure. As an Application Security Developer (DAST & API Security), you will help secure Autodesk’s web applications and APIs by identifying and validating vulnerabilities in real-world execution environments. You will partner with product and engineering teams to perform dynamic testing, triage findings, and support remediation, while helping integrate security testing into CI/CD pipelines.This is a mid-level, hands‑on role focused on execution and collaboration, with opportunities to grow your expertise across up-to-date architectures (microservices, SPAs, and API‑driven systems) at scale.ResponsibilitiesPerform dynamic application security testing (DAST) against web applications and APIs to identify runtime vulnerabilities, including authentication, authorization, and business logic flawsConduct API security assessments (REST, GraphQL, gRPC), validating authentication flows, authorization models, rate limiting, and data exposure risksExecute and support web application security testing, including manual testing and automated scanning aligned with OWASP Top 10 and API Top 10Analyze and triage findings from DAST tools and scanners,



tuning configurations to improve signal quality and reduce false positivesPartner with engineering teams to remediate vulnerabilities, providing clear, actionable guidance on fixes and secure design patternsIntegrate DAST and API security testing into CI/CD pipelines, enabling continuous and automated security validationCollaborate with teams to implement and optimize security controls such as WAFs, API gateways, and runtime protectionsContribute to security testing strategies, including automation, tooling selection, and coverage improvements across servicesProvide developer education and guidance on web and API security risks, exploitation techniques, and remediation best practicesTrack, prioritize, and report on security findings and trends to improve overall application and API security postureMinimum Qualifications3–5 years of experience in application security, penetration testing, or a related fieldHands‑on experience with DAST tools (e.G., Burp Suite, OWASP ZAP, Netsparker, Acunetix), combined with the ability to manually validate findingsStrong understanding of web application security (OWASP Top 10) and API security risks (OWASP API Top 10)Experience testing modern architectures (microservices, SPAs, API‑driven systems)Practical knowledge of authentication and authorization mechanisms (OAuth, OIDC, JWT,



session management)Familiarity with API protocols and formats (REST, GraphQL, JSON, XML, gRPC)Experience supporting security testing within CI/CD pipelines or DevSecOps workflowsAbility to identify and exploit common vulnerabilities such as injection, XSS, CSRF, and broken access controlWorking knowledge of HTTP/S and web protocolsProficiency in scripting or programming (e.G., Python, JavaScript, or Go)Strong analytical and problem‑solving skills with the ability to triage and prioritize vulnerabilitiesEffective communication skills to explain risks and remediation steps to engineering teamsPreferred QualificationsExperience performing manual penetration testing of web applications and APIsFamiliarity with advanced DAST techniques (e.G., fuzzing, parameter discovery)Knowledge of runtime security controls such as WAFs, RASP, or API security platformsExperience with cloud environments (AWS, Azure, GCP) and securing cloud‑native applicationsFamiliarity with security testing automation frameworksExperience with bug bounty programs or vulnerability disclosure processesContributions to security standards, playbooks, or developer trainingSalary transparency Salary is one part of Autodesk’s competitive compensation package. For Canada based roles, we expect a starting base salary between $80,000 and $116,600. Offers are based on the candidate’s experience and geographic location, and may exceed this range. In addition to base salaries, our compensation package may include annual cash bonuses, commissions for sales roles, stock grants, and a comprehensive benefits package.#J-18808-Ljbffr

📌 Application Security Developer - C$80,000 - C$116,600 A Year (Toronto)
🏢 Autodesk
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: application security developer - c$80,000 - c$116,600 a year (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: application security developer - c$80,000 - c$116,600 a year (toronto) / toronto