Overview
Clio is a global leader in legal AI technology, empowering law firms and legal professionals of all sizes. We are looking for an Application Security Engineer to join our rapidly growing Security team. The team emulates real‑world adversaries to proactively discover, exploit, and help remediate critical security vulnerabilities across our applications.
Responsibilities
- Write, review, debug, and implement tools that help developers avoid security flaws.
- Build partnerships with development teams and advise on security best practices.
- Contribute to developer education by driving security awareness and knowledge across the product organization.
- Provide guidance and support to teams in vulnerability remediation, and develop frameworks, guidelines, and systematic fixes for recurring vulnerabilities.
- Resolve issues, navigate ambiguity, and maintain positive working relationships with researchers in our Bug Bounty program.
- Identify and implement tools for automated application scanning, static analysis, and related automated security checks.
- Perform penetration testing and offensive campaigns against internal assets.
- Conduct reactive incident response and forensics when a security event occurs.
- Conduct proactive research to detect new attack vectors.
- Elevate and educate our security culture within Clio, contributing to our cultural values.
Qualifications
Experience in Application Security with a strong focus on offensive security and penetration testing.Hands‑on expertise identifying and exploiting complex vulnerabilities (e.g., SSRF, deserialization, logic bypasses).Proven ability to lead and conduct formal threat‑modeling sessions.Experience securing applications in modern cloud environments (AWS, Azure, or GCP).Expertise with common application security tools and platforms (e.g., Burp Suite, SAST, SCA).Experience with log aggregation and SIEM technologies.Ability to identify malicious behaviour and emerging threats via log analysis.Demonstrated interest in improving your craft by using AI.Bonus (Optional)
Security certifications such as OSCP or OSWE.Active participation in the security community (e.g., presenting at conferences, contributing to open‑source tools).Experience with Ruby on Rails, Puppet, Kubernetes, Terraform, ELK (Elastic, Logstash, Kibana).Strong AWS security experience on EC2 and managed services.Experience with infrastructure security (WAF, ACLs, authentication, device hardening).Compensation & Benefits
The expected salary range for this role is CAD $116,500 to $157,500, depending on experience and geographic region.Competitive, equitable salary with top‑tier health, dental, and vision insurance.Hybrid work environment with an expectation for local Clions to be in office at least twice per week.Flexible time‑off policy, encouraged 20 days off per year.$2,000 annual counseling benefit.RRSP matching and RESP contribution.Clioversary recognition program with special acknowledgement at 3, 5, 7, and 10 years.Diversity, Inclusion & Accessibility
Clio is committed to diversity, equity, and inclusion. We encourage candidates from all backgrounds to apply. We provide accessibility accommodations during the recruitment process and respect all requests for assistance.
#J-18808-Ljbffr