Talent.com
Segment (Twilio)
Application Security EngineerSegment (Twilio) • Toronto, ON, Canada
Application Security Engineer

Application Security Engineer

Segment (Twilio) • Toronto, ON, Canada
Il y a 26 jours
Type de contrat
  • Temps plein
Description de poste

Requirements

  • Deep conviction that AI and automation should eliminate manual work humans shouldn't be doing anyway. You're excited to replace developer toil and reactive vuln triage with automated systems, guardrails, and agents
  • Business enablement security mindset — you measure success by business impact and informed risk-taking, not by tickets opened or pen test reports filed
  • 5+ years of application security or software engineering experience with a security focus, with strong skills in at least one of Python, Go, TypeScript, or Ruby — and the ability to read and write code across the others
  • Hands‑on expertise across the SAST/DAST/SCA toolchain, with real deployment experience using GitHub Advanced Security, Semgrep, or equivalent
  • Strong grasp of common application vulnerability classes (OWASP Top 10, OWASP API Security Top 10), with particular fluency in GraphQL, REST, and gRPC security pitfalls — broken authorization, mass assignment, introspection exposure, IDORs
  • Practical threat modeling skills — you can take an architecture diagram and a 30‑minute conversation and walk out with the three things that actually matter
  • Experience with cloud and container security on AWS and Kubernetes, including IAM, secrets management, and CI/CD pipeline security
  • Humility and genuine curiosity — you're as excited to learn from product engineers and enable their work as you are to break things
  • (Desirable) Offensive security experience — pentesting web apps, APIs, or mobile, and/or red team operations
  • (Desirable) Experience running a bug bounty or coordinated disclosure program at scale
  • (Desirable) Mobile application security review experience (iOS and Android)
  • (Desirable) Experience securing AI/ML pipelines, agent frameworks, or MCP‑style integrations
  • (Desirable) OSCP, OSWE, or similar offensive certifications

What the job involves

  • Our Security Engineering team is building intelligent systems that protect Opendoor and our customers while enabling unprecedented engineering velocity
  • We apply software engineering and AI to solve security problems across product, infrastructure, and operations by building guardrails where they matter, not gates where they don't
  • As our Application Security Engineer, you'll own the security of everything we ship — from the consumer flows that put cash offers in homeowners' hands, to the GraphQL APIs that power our products, to the AI agents and vibe‑coded tools our engineers and operators build every week
  • You'll be the technical owner of how we find, fix, and prevent application‑layer risk at Opendoor scale
  • Find and fix application vulnerabilities across our consumer products, internal admin tools, and the GraphQL APIs powering home acquisition, resale, mortgage, title, and escrow
  • Own and evolve our AppSec tooling stack — SAST/DAST, SCA and secrets scanning — and integrate findings into developer workflows where engineers already live (pull requests, Linear, Slack)
  • Run our HackerOne program: triage incoming reports, validate exploits, route fixes to product engineering teams, and determine root causes so we can stamp them out at the source
  • Lead threat modeling and security design reviews for new services, APIs, and mobile features — and turn the patterns you see into rules, lint checks, and CI guardrails so the next team doesn't make the same mistake
  • Build AI agents and automated workflows that triage vulnerability reports, validate exploit reproductions, and draft remediation PRs — replacing manual security review with high‑signal automation
  • Partner with engineering teams to harden authentication, authorization, and input validation across our Ruby monolith and Go/Python/TypeScript services, including the GraphQL gateway (Apollo) and our EKS workloads - while driving a shift‑left strategy to identify vulnerabilities earlier in the development lifecycle
  • Stand up a credible offensive security capability — internal pentesting, red team exercises, and adversarial analysis of high‑risk flows (wire fraud, agent unlocks, identity verification) -- leveraging purple team exercises to ensure offensive findings are directly translated into hardened detection and response capabilities
  • Set the bar for what "secure by default" looks like for AI‑maximalist engineering, including vibe‑coded apps, MCP servers, and agent‑driven workflows that touch production data
  • Mentor engineers across the company in secure design, code review, and how to think like an attacker
  • Tech Stack:
  • Languages: Go, Python, TypeScript, Ruby, Terraform
  • Cloud: AWS, GCP, Azure, Kubernetes / EKS
  • AppSec Tooling: GitHub Advanced Security (CodeQL, Dependabot, secret scanning)
  • Semgrep, HackerOne, Burp Suite, Cloudflare WAF
  • AI Tooling: Claude, OpenAI, various agent frameworks, MCP — used heavily for vuln triage, exploit verification, and remediation drafting
#J-18808-Ljbffr
Créer une alerte emploi pour cette recherche

Application Security Engineer • Toronto, ON, Canada

Offres similaires

Lead Application Security Engineer at Opendoor

Segment (Twilio)Toronto, ON, CA
Temps plein

Step into a leadership position as a Lead Application Security Engineer at Opendoor, where you'll shape the future of secure software development.Automate security processes while mentoring enginee... Voir plus

 • Offre sponsorisée

Application Security Engineer - C$100,000 - C$150,000 A Year

TcsEast York, Canada
Temps plein

Application Security Engineer needed to perform web application and API penetration tests, identify vulnerabilities, and drive remediation. Voir plus

 • Offre sponsorisée

Application Engineer - Security Tech Solutions (Remote)

SICK Sensor IntelligenceToronto, ON, CA
Télétravail

Sie entwickeln Applikationslösungen im Bereich Sicherheitstechnik.Bewerber benötigen ein Studium in Elektrotechnik und Erfahrung in der Elektrokonstruktion sowie gute Englischkenntnisse. Voir plus

 • Offre sponsorisée

Opendoor Enterprise Security Engineer Role

OpendoorToronto, ON, CA
Temps plein

Be part of Opendoor’s mission as an Enterprise Security Engineer.This hands-on role is focused on identity systems and enhancing endpoint security through automation.In your role at Opendoor, you w... Voir plus

 • Offre sponsorisée

Application Security Software Engineer

PointClickCareToronto, ON, CA
Temps plein

This range is provided by PointClickCare.Your actual pay will be based on your skills and experience — talk with your recruiter to learn more.PointClickCare is a leading North American healthcare t... Voir plus

 • Offre sponsorisée

Application Security Engineer - $169,000 - $194,025 A Year

PaxosEast York, Canada
Temps plein

Application Security Engineer to secure financial and blockchain ecosystem by reviewing code, developing security tools, and integrating security into the development lifecycle. Voir plus

 • Offre sponsorisée

Senior Application Security Engineer Position

NasdaqToronto, ON, CA
Temps plein

Take charge as a Senior Application Security Engineer at Nasdaq, focusing on securing innovative cloud solutions.Collaborate in a hybrid setting to tackle complex security challenges across global ... Voir plus

 • Offre sponsorisée

Senior Security Engineer, Application & Platform Security - $180,000 - $280,000 A Year

SentryEast York, Canada
Temps plein

Senior Security Engineer to secure Sentry's cloud-based applications and Kubernetes platform, driving security solutions, and collaborating with engineering teams. Voir plus

 • Offre sponsorisée

Senior Application Security Engineer

CognizantToronto, ON, CA
Temps plein

Job Title - App Security Specialist.DevOps, with at least 2 - 3 years hands-on security exposure (secure coding, pipeline security, API security, threat modeling).Seniority level: Mid-Senior level.... Voir plus

 • Offre sponsorisée

Application Security Engineer - C$100,000 - C$150,000 A Year

Tata Consultancy ServicesEast York, Canada
Temps plein

Application Security Engineer needed to perform penetration testing on web applications and APIs, identify vulnerabilities, and drive remediation efforts. Voir plus

 • Offre sponsorisée

Application Security Engineer - C$60 - C$67 An Hour

HireTalent - Staffing & Recruiting FirmNorth York, Canada
Temps plein

Seeking a Cyber Security expert to recertify third-party connections, ensuring compliance with encryption requirements by supporting IT Application owners and investigating data flow. Voir plus

 • Offre sponsorisée

Senior Application Security Engineer - C$192,000 - C$240,000 A Year

BrexNorth York, Canada
Temps plein

Seeking a Senior Application Security Engineer to identify and respond to security vulnerabilities across the Brex platform.Responsibilities include code reviews, penetration testing, and developin... Voir plus

 • Offre sponsorisée

Staff Application Security Engineer - $221,000 - $286,000 A Year

ThumbtackToronto County, Canada
Temps plein

Lead application security initiatives, design secure architectures, and mentor engineers to enhance Thumbtack's security posture and enable innovation at scale. Voir plus

 • Offre sponsorisée

Security Engineer I (Application Security Engineer) - C$41.6 - C$52.4 An Hour

WorkSafeBCNorth York, Canada
Temps plein

Join WorkSafeBC as a Security Engineer I to protect millions of British Columbians by ensuring secure applications.You will provide guidance on application security design, develop secure coding st... Voir plus

 • Offre sponsorisée

Senior Application Security Engineer

Paymentusrichmond hill, york region, Canada
Temps plein

Senior Application Security Engineer.Paymentus SaaS platform by partnering directly with software engineering, product, cloud infrastructure, DevOps, and security teams to identify, assess, and rem... Voir plus

 • Offre sponsorisée

Senior Application Security Engineer

HelloFreshToronto
Temps plein

We're looking for a new teammate to join us on the journey of keeping HelloFresh a trusted name - someone with a passion for security and appetite for new challenges.Security Engineers work in a va... Voir plus

 • Offre sponsorisée

Senior Security Engineer in Healthcare

LeagueToronto, ON, CA
Temps plein

Join League as a Senior Security Engineer, focusing on building innovative security tooling and maintaining a secure development ecosystem in healthcare.Drive technology improvements and enhance pl... Voir plus

 • Offre sponsorisée

Senior Application Security Engineer - C$131,500 - C$155,000 A Year

Spring FinancialNorth York, Canada
Temps plein

Senior Application Security Engineer responsible for leading technical efforts to secure software systems, embedding security best practices, and mentoring engineers.Focuses on secure development l... Voir plus

 • Offre sponsorisée

Application Security Developer - C$116,500 - C$157,500 A Year

ClioToronto County, Canada
Temps plein

Seeking an Application Security Engineer to find and fix security vulnerabilities, partner with development teams, and improve security culture.Focus on offensive security and penetration testing. Voir plus

 • Offre sponsorisée

Senior Application Security Engineer: Ci/Cd & Tooling - C$146,200 - C$197,800 A Year

Themis Solutions Inc.Toronto County, Canada
Temps plein

Develop security tools and advise on best practices at a legal tech company. Voir plus