29 Aug
|
Beacon Software
|
Toronto
29 Aug
Beacon Software
Toronto
You will be Beacon's first dedicated application security engineer. You will set the strategy for product security and start to build the program. Beacon's application security surface spans both Beacon's own engineering and our portfolio companies' products, each independently built with its own stack and engineering team.
You will embed with the teams that own the code, whether at Beacon HQ or within a portfolio company, working inside their design reviews and planning, and own the technical roadmap for product security as Beacon grows.
What Application
Security owns This is the full remit of Application Security at Beacon.
Secure design and architecture: lead threat modeling and security architecture review for current product work and platform initiatives, and define standards for authentication, authorization, encryption, and tenant isolation.
Acquisition assessment: own the product security review of newly acquired codebases and cloud environments, establishing baseline posture, material risk, and the remediation path.
Code and security review: perform secure code review, targeting authorization and business logic flaws that automated tooling does not catch. Identify and manage the external partner who runs penetration testing against our products and infrastructure, and drive remediation of what they find.
AI security: assess AI features across our products, including agent architectures, model and tool access, delegated credentials, and the data reachable through them.
Vulnerability management: own the end-to-end program, including intake, severity, prioritization, remediation SLAs, and reporting, and drive fixes through engineering teams in a way they can sustain.
Own the security of any internal tools you build, including their access to credentials, source code, and production systems.
Enablement: write the secure coding standards and training that engineering teams consult before they build.
Incident response: serve as the product security expert during incidents, from investigation through remediation and postmortem.
Compliance partnership: work with GRC to produce the evidence audit and customer security review require, without letting compliance drive the security roadmap. Already uses AI as part of how you work, with real opinions on where it helps and where it doesn't, including judgment on when to build tooling versus buy it. Ships production code yourself.
You should be able to author a fix, not only specify it. Expert knowledge of web and API security, identity and access design (authentication, authorization, RBAC/ABAC), and applied cryptography. A track record of driving security work to completion in engineering organizations outside your reporting line.
Our Values at Beacon Software Business is a repeat game and we believe that human relationships generate alpha. We take pride in having a deep sense of responsibility to ourselves, each other, our partners, and our customers. We seek to build a generational software company.
How We Use AI in Our Hiring Process: To ensure transparency, we want candidates to know that Beacon Software uses Artificial Intelligence and AI-enabled tools to assist with screening, reviewing, organizing and highlighting profiles and applications that match the key requirements for each role.
AI does not make hiring decisions: We use AI to support efficiency and consistency, not to replace human judgment.
📌 Staff/Lead Application Security Engineer (Toronto)
🏢 Beacon Software
📍 Toronto