Application Security Engineer — AI-Driven Secure DevOps

Capital Factory

Montreal (administrative region)

Hybrid

CAD 90,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Annual bonus program.
LTIP program, share in Workleap's long
RRSP + Family health insurance + tele/

Job summary

Workleap is building the security layer for how we write software, integrating SAST, DAST, SCA and secret scanning into GitHub Actions. We aim for agentic security review where agents perform the first pass on pull requests and escalate to humans when needed.

You will lead threat modeling on architectural changes, write tooling in Python, and strengthen Azure environments, collaborating with the AI SDLC team and LeapSec to ship secure software.

Qualifications

  • Five or more years in application security, DevSecOps, or security focused software development.
  • Deep working knowledge of web application security, OWASP Top 10, CWE Top 25.
  • Proven experience building security automation into CI/CD pipelines, GitHub Actions preferred.
  • Proficiency in Python for building tooling, not just scripting.
  • Solid grasp of Azure services, infrastructure security, and deployment patterns.
  • Ability to explain risk tradeoffs to engineers and execs.

Responsibilities

  • Build the security guardrails for AI assisted and agentic development so speed and safety stop being a tradeoff.
  • Move security review from human bottleneck to automated first pass with human judgment for ambiguity.
  • Lead threat modeling on new features and architectural changes.
  • Drive real remediation of application security vulnerabilities based on risk retirement, not tickets.
  • Harden Azure environments and deployment patterns alongside Infrastructure SecOps.

Skills

Web application security
DevSecOps
CI/CD security automation
Python
GitHub Actions
Azure
Threat modeling

Tools

SAST tooling
DAST tooling
SCA tooling

Job description

Workleap is building the security layer for how we write software, integrating SAST, DAST, SCA and secret scanning into GitHub Actions. We aim for agentic security review where agents perform the first pass on pull requests and escalate to humans when needed.

You will lead threat modeling on architectural changes, write tooling in Python, and strengthen Azure environments, collaborating with the AI SDLC team and LeapSec to ship secure software.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Application Security Specialist
Staff Application Security Specialist

Workleap Inc. • Canada

Hybrid
CAD 120,000 - 180,000
LTIP program
RRSP + health insurance
Flexible vacation
+3
Staff Application Security Specialist
Staff Application Security Specialist

Capital Factory • Montreal (administrative region)

Hybrid
CAD 90,000 - 130,000
Annual bonus program.
LTIP program, share in Workleap's long
RRSP + Family health insurance + tele/
Product Security Architect
Product Security Architect

BeyondTrust • Ottawa

On-site
CAD 140,000 - 200,000
Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Oakville

On-site
CAD 120,000 - 180,000
Senior Security Engineer: Secure AI & Cloud, Remote
Senior Security Engineer: Secure AI & Cloud, Remote

Visa Hunt • Toronto

Hybrid
CAD 110,000 - 170,000
Lunch stipend
Health & dental benefits
RRSP matching
+5
Secure Automation Engineer | DevSecOps Engineer
Secure Automation Engineer | DevSecOps Engineer

MDAEdge • Montreal (administrative region)

On-site
CAD 120,000 - 150,000
Senior AppSec Engineer — End-to-End Security & AI Tooling
Senior AppSec Engineer — End-to-End Security & AI Tooling

Relay • Toronto

On-site
CAD 180,000 - 220,000
Application Security Engineer
Application Security Engineer

Segment (Twilio) • Toronto

On-site
CAD 100,000 - 130,000
Senior AI-Driven AppSec Engineer
Senior AI-Driven AppSec Engineer

IFS • Vancouver

Hybrid
CAD 117,000 - 167,000
Hybrid work opportunities
Platform Security Engineer Build Secure AI & Drive Trust
Platform Security Engineer Build Secure AI & Drive Trust

LiveKit Incorporated • Canada

On-site
CAD 110,000 - 150,000
Competitive salary
Equity package
Health, dental, and vision benefits
+1