Our client is revolutionizing how science is communicated, one graphic at a time (you can think of them as the Adobe or Canva for science!). They are on a mission to accelerate science by empowering all scientists to quickly and easily communicate their research.
Role Overview
Our client is looking for a Senior Application Security Engineer with 6+ years of experience to join a small but high-impact security team and bring an engineering-first mindset to application security. You are someone who started as a software engineer or has always been hands-on with code; you read it fluently, write production-quality fixes, and ship them yourself rather than throwing findings over the fence.
Key Responsibilities
- Contribute production-quality code directly to the application (Node.js/Python), shipping security fixes and hardening features yourself.
- Build AI-powered automation to eliminate manual security work (such as PR analysis and vulnerability triage) to help the team scale faster and focus on high-leverage architecture.
- Manage the HackerOne bug bounty program end-to-end by evaluating submissions, reproducing issues, and closing findings by shipping fixes.
- Define secure-by-design patterns and drive security standards across the application architecture, including AI-integrated product features.
- Act as a security reviewer on RFCs and design documents, pairing with engineers to resolve issues at the source rather than blocking them.
Qualifications
- 6 to 10 years of experience in application security engineering.
- Proven track record of owning application-level security at a VC-backed startup.
- Experience actively shipping production security code rather than working in a purely advisory capacity.
- Solid proficiency in Node.js and/or Python.
- Active use of AI coding assistants (such as Claude, Copilot, or Codex) in daily engineering workflows.
- Cloud security experience (AWS preferred) or solid GRC/compliance knowledge.
- Must be located in Canada or the USA with no visa sponsorship required.
Education & Experience
- Experience shipping code as a traditional software engineer at a strong company, transitioning into a security-focused software engineer at a startup with under 1,000 employees.
- Experience managing or contributing to a bug bounty program such as HackerOne.
- Bachelor's degree in Computer Science or a related field is preferred.