Senior Security Engineer (Application Security) (Kitchener)

Senior Security Engineer (Application Security) (Kitchener)

08 Sep
|
Faire
|
Kitchener

08 Sep

Faire

Kitchener

- Our Engineering organization owns the software that makes our marketplace work.

Our Application

Security function is focused on keeping vulnerabilities out of the code and software as it’s built and shipped, owning the SDLC from commit to production

- We care about good engineering practice and love to write software that is secure, tested, easy to maintain, and can scale to millions of users. We build scalable, reusable frameworks; consult with product teams; listen to the data; and iterate

- Find and fix vulnerabilities in first-party code and third-party dependencies using AI-powered detection, SAST, DAST, SCA, and secret scanning tooling

- Build shift-left tooling and CI/CD guardrails that make the secure path the default in the build pipeline

- Own offensive security engagements such as penetration tests with external vendors

- Evaluate and harden the security of AI-assisted code generation workflows

- Own the bug bounty program and the vulnerability management lifecycle end to end, from intake through remediation and closure

- Lead threat modeling and secure design reviews for new products and high-risk platform changes, shaping the architecture before the code is written rather than reviewing it after

- Conduct security reviews and consultations with product and platform teams and develop secure coding standards and scaling frameworks for recurring vulnerability classes

Advantages

- Comprehensive healthcare: Including Health, Dental, Vision and Disability for all our locations.

- Time off: Paid time off, holidays and company-wide “Faire Fundays”.

- Parental leave: Generous parental and family leave, as well as fertility support benefits.

- Productivity support: Monthly stipends to help cover work from home connectivity needs.

- Annual learning grant: For personal and professional development, as well as unlimited access to training courses through LinkedIn Learning.

- Thoughtfully designed spaces: All of our offices have been designed with local in mind – from our architects to our coffee blends.

- Fitness and well-being benefits:



Including monthly credit towards your wellness-related programmes.

- Mental health benefits: Including free access to Up-to-date Health therapists and resources.

- Charitable matching: Faire will match up to £250 of your charity donations, every year.

- Career planning: Whether you want to grow as a leader, hone your craft or explore a new discipline, our career framework allows space for you to explore.
- Curiosity about the security of AI-assisted development, and interest in figuring out what changes when a meaningful share of the code is machine-generated

- Experience driving vulnerability remediation across teams you do not own, with a point of view on how to set severities, hold SLAs, and get things actually closed
- A passion for coding and solving security problems scalably with code and automation, rather than with process and policy

- Comfort writing and reviewing code in OOP languages such as Kotlin, Java, Python, or TypeScript, enough to read an unfamiliar service, judge whether a finding is real, and open the pull request that fixes it

- Experience leading threat models on systems you did not build, and the judgement to know which designs need one and which do not

- Exposure to offensive security, whether that is running a bug bounty program, scoping penetration tests with external vendors, or finding and reporting real vulnerabilities yourself
- A thorough understanding of web application security principles and common vulnerabilities, including OWASP Top 10, with an instinct for the systemic fix behind the individual finding

- Hands-on experience integrating security into the software development lifecycle

- Practical experience with AppSec detection tooling (SAST, DAST, SCA, or secret scanning), including the unglamorous parts: deploying it, tuning the rules, and cutting the false positives so engineers trust the results
- The ability to explain risk to product engineers in a way that makes them want to fix it, and the credibility to be invited into design discussions rather than added as a gate

- Experience working in modern cloud computing environments such as AWS or GCP

📌 Senior Security Engineer (Application Security) (Kitchener)
🏢 Faire
📍 Kitchener

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior security engineer (application security) (kitchener) / kitchener

Subscribe to this job alert:

Get the latest job offers by email for: senior security engineer (application security) (kitchener) / kitchener