Talent.com
IFS
Senior Lead Application Security EngineerIFS • Vancouver, British Columbia, CA
Senior Lead Application Security Engineer

Senior Lead Application Security Engineer

IFS • Vancouver, British Columbia, CA
30+ days ago
Job type
  • Full-time
Job description

Job Description

We are looking for an Application Security Engineer to join the Agentic Platform pillar, working within the Cloud Platform team. This team owns the secure, governed foundation that enables all of Copperleaf’s R&D teams to build and ship faster. In this role you will embed security directly into the platform and across every CI/CD pipeline, shifting our posture from reactive to proactive. You will bring traditional application security depth into our DevSecOps culture and, critically, use AI agents to continuously and autonomously improve our security posture. Our operating premise is simple: agentic attacks require agentic defense. You will build the agents, skills, and guardrails that detect, triage, and remediate security risk at machine speed, staying ahead of threats rather than responding to them after the fact. This is a hands-on, implementation-first role: you will personally build, ship, and operate the security changes you design, working directly in the code and the pipelines rather than advising from the sidelines.

Key Responsibilities

  • Embed application security into the Cloud Platform and across all CI/CD pipelines, making secure-by-default the path of least resistance for every R&D team.
  • Design, build, and operate AI-driven security agents that proactively scan, triage, and remediate vulnerabilities across source code, dependencies, containers, and infrastructure-as-code, turning point-in-time reviews into continuous, autonomous coverage.
  • Establish secure software development lifecycle (SSDLC) practices, threat modeling, and secure-coding standards, and integrate automated enforcement (SAST, SCA, DAST, secrets scanning, IaC scanning) as native pipeline gates rather than bolt-on checks.
  • Lead the security of our own agentic systems: defend against prompt injection, tool/MCP abuse, data exfiltration, excessive agency, and supply-chain risk in line with frameworks such as the OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Drive proactive vulnerability management: remediate HIGH and CRITICAL CVEs across platform infrastructure and container images in line with contractual and compliance commitments, and automate the toil out of it.
  • Partner with engineering teams to harden Azure Kubernetes Service (AKS) workloads, identity and access (Keycloak, Azure AD, Managed Identities, workload identity), network segmentation, and secrets management.
  • Contribute security evidence and controls to compliance programs (SOC 2, ISO 27001, Cyber Insurance), and automate evidence collection and continuous control monitoring with agentic tooling.
  • Define and maintain security runbooks, detection logic, and incident response procedures, and build the agents that execute and accelerate them.
  • Act as the security skill set within the platform team raising the bar through code review, pairing, and sharing pragmatic, developer-friendly guidance.
  • Contribute to improving the Agentic Operating Model through development of security-focused agent skills, prompts, and tooling that other teams can reuse.

Technical Focus Areas

  • Application security fundamentals: secure SDLC, threat modeling, OWASP Top 10, secure code review, and remediation across multiple languages and stacks.
  • Agentic and AI security: securing LLM- and agent-based systems (prompt injection, tool/MCP security, sandboxing, guardrails), plus building autonomous agents that perform security work. OWASP Top 10 for LLMs and MITRE ATLAS a strong asset.
  • DevSecOps and pipeline security with Azure DevOps: SAST, SCA, DAST, secrets and IaC scanning, SBOM generation, container signing and attestation, and pipeline access controls.
  • Security scanning and tooling: Mend (SCA/SAST), Azure Defender for Cloud, and MDR/SOC platforms.
  • Hands-on with modern agentic and AI-security tooling: agentic coding and security assistants ( Claude Code with custom agent skills and MCP), AI-assisted code analysis and autofix ( Semgrep, Snyk / DeepCode AI, GitHub Copilot Autofix / CodeQL), LLM and agent red-teaming ( garak, Microsoft PyRIT, Promptfoo), and runtime guardrails and model supply-chain protection ( Lakera Guard, NVIDIA NeMo Guardrails, Protect AI).
  • Cloud-native security on Azure Kubernetes Service (AKS): RBAC, network policies, admission controllers ( Kyverno), workload identity, and cluster hardening.
  • Identity and access management: Keycloak, Azure Active Directory, Managed Identities, and secrets management ( CSI secrets driver, Key Vault).
  • Infrastructure-as-code: Bicep or Terraform for security configuration, policy-as-code, and drift management.
  • Compliance frameworks and automated evidence collection: SOC 2, ISO 27001, and Cyber Insurance requirements.
  • Scripting and automation ( Python, PowerShell, or C#) to build security tooling and orchestrate agents.

Qualifications

Area of specialization: Application Security & DevSecOps – Agentic Defense

About you

  • You think proactively: you anticipate how systems will be attacked and build defenses ahead of the threat, rather than waiting to respond.
  • You are a do-er, not just an advisor: you implement the fixes yourself and measure success by what ships and what is provably more secure, not by recommendations handed to someone else.
  • You demonstrate strong ownership of technical outcomes and a commitment to quality.
  • You apply sound engineering judgment when making design and implementation decisions, balancing security rigor with developer velocity.
  • You communicate clearly and effectively with both technical and non-technical stakeholders.
  • You continuously develop technical and domain expertise in application security, cloud security, and the rapidly evolving field of agentic/AI security.
  • You collaborate effectively within cross-functional, outcome-oriented teams.
  • You leverage AI to accelerate projects and improve overall quality of output, and you are excited to push the frontier of what agentic defense can do.

Create a job alert for this search

Senior Lead Application Security Engineer • Vancouver, British Columbia, CA

Similar jobs

Senior Security Engineer Focused on Detection and Response Frameworks

1PasswordVancouver, Metro Vancouver Regional District, CA
Full-time

Join as a Senior Security Engineer to strengthen detection and incident response frameworks.Lead initiatives that optimize security measures and enhance organizational resilience in a remote enviro... Show more

 • Promoted

Senior Security Engineer

fispanVancouver, Metro Vancouver Regional District, CA
Permanent

As a Senior Security Engineer, you will provide leadership, expertise, and advanced security analysis capabilities within the organization’s security operations.Operating at a senior level, you wil... Show more

 • Promoted

Senior Analyst, Security Compliance

P2PVancouver, Metro Vancouver Regional District, CA
Full-time

Our Krakenites are a world-class team with crypto conviction, united by our desire to discover and unlock the potential of crypto and blockchain technology.Kraken is a mission-focused company roote... Show more

 • Promoted

Information Security Engineer - $100,000 - $120,000 A Year

Finning InternationalSurrey, Canada
Full-time

Position Overview The Information Security Engineer role is responsible for managing and optimizing endpoint security and threat intelligence capabilities to strengthen Finning Canada’s cyber defen... Show more

 • Promoted

Senior Application Security Developer - C$149,600 - C$202,400 A Year

ClioWest End, Canada
Full-time

Seeking a Senior Application Security Developer to join Clio's Defensive Security team.Responsibilities include developing tools, remediating vulnerabilities, and advising on security best prac... Show more

 • Promoted

Senior Security Engineer

TigeraVancouver, Canada
Full-time

Tigera provides Calico, a unified network security and observability platform to prevent, detect and mitigate security breaches in Kubernetes clusters.Tigera’s open-source offering, Calico Open Sou... Show more

 • Promoted

Senior Lead Application Security Engineer Vancouver, British Columbia, Canada Research and Deve[...]

Industrial and Financial SystemsVancouver, Metro Vancouver Regional District, CA
Full-time +1

Senior Lead Application Security Engineer.We are looking for an Application Security Engineer to join the Agentic Platform pillar, working within the Cloud Platform team.This team owns the secure, ... Show more

 • Promoted

Staff Security Engineer: Remote Lead & AppSec Architect

Super.comVancouver, Metro Vancouver Regional District, CA
Remote
Full-time

A technology company in Canada is seeking a Staff Software Engineer specializing in Security to lead and mentor engineers within the Security & Privacy team.The successful candidate will drive appl... Show more

 • Promoted

Senior IT Security Engineer

Zema Global Data CorporationVancouver, Metro Vancouver Regional District, Canada
Full-time +1

Position Type: Full-time, Permanent.Industry: Commodities & Energy.Work model: Hybrid (8 days in office per month).Founded in 1995, Zema Global Data Corporation empowers organizations to simplify c... Show more

 • Promoted

Senior Security Operations Engineer I

Samsaravancouver, metro vancouver regional district, Canada
Full-time

As a member of our Security Operations Team, you will collaborate with a global team of engineers to monitor and respond to security events, lead security incidents as Incident Commander, and lead ... Show more

 • Promoted

Senior Security Operations Engineer

CohereVancouver, Metro Vancouver Regional District, CA
Full-time

Our mission is to scale intelligence to serve humanity.We’re training and deploying frontier models for developers and enterprises who are building AI systems to power magical experiences like cont... Show more

 • Promoted

Senior Security Engineer - Cloud Identity

MQ Referrals OnlyVancouver, Metro Vancouver Regional District, Canada
Full-time

We’re seeking an experienced Senior Security Engineer with a strong passion for.Identity and Access Management(IAM).In this role, you’ll help shape and implement modern identity strategies to secur... Show more

 • Promoted

Application Engineer - Security Tech Solutions (Remote)

SICK Sensor IntelligenceVancouver, Metro Vancouver Regional District, CA
Remote

Sie entwickeln Applikationslösungen im Bereich Sicherheitstechnik.Bewerber benötigen ein Studium in Elektrotechnik und Erfahrung in der Elektrokonstruktion sowie gute Englischkenntnisse. Show more

 • Promoted

Cloud Application Security Engineer Role

TruliooVancouver, Metro Vancouver Regional District, Canada
Full-time

Become a pivotal Cloud Application Security Engineer at Trulioo in Vancouver, focusing on cloud application security and automation.Contribute to securing a trusted digital identity verification pl... Show more

 • Promoted

IT Security & Infrastructure Manager Role

District of Squamishsquamish, squamish lillooet regional district, Canada
Full-time

Join the District of Squamish as the Manager of IT Security and Infrastructure, leading initiatives in a hybrid tech environment.This dynamic full-time role emphasizes IT security and infrastructur... Show more

 • Promoted

Senior Cloud Security Engineer, Information Security

Peoples GroupVancouver
Full-time

We are hiring for this position out of our Toronto, Vancouver and Calgary offices.Successful candidates who apply outside of these areas will be expected to relocate and reside in a location that i... Show more

 • Promoted

Remote Security Architect - Cloud & App Security Lead

AGFA HealthCareVancouver, Metro Vancouver Regional District, Canada
Remote
Full-time

A healthcare technology company is seeking an experienced Security Architect responsible for designing and implementing security within their architecture.The role involves collaborating with cross... Show more

 • Promoted

Security Implementation Engineer Ii — Onboarding & Guidance - C$96,975 - C$120,427 A Year

Leading Cybersecurity FirmNorth Vancouver, Canada
Full-time

Seeking a Security Implementation Engineer in Canada to deliver advanced security product implementations and integrations, mentor junior engineers, conduct technical assessments, and collaborate w... Show more

 • Promoted

Cloud Security Solutions Engineering Lead

Wizvancouver, metro vancouver regional district, Canada
Full-time

Join Wiz as the Cloud Security Solutions Engineering Lead in Western Canada.Guide a talented team to enhance cloud security for enterprise clients and drive impactful solutions.Wiz is at the forefr... Show more

 • Promoted

Senior Cloud Security Delivery Lead - $126,000 - $210,400 A Year

Amazon Web Services (AWS)North Vancouver, Canada
Full-time

Senior role to enhance customer security using AWS solutions.Requires experience in cloud architecture and security. Show more