Application Security Researcher

OX Security

Toronto

On-site

CAD 120,000 - 180,000

Full time

21 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health Coverage
Unlimited PTO
Birthday/anniversary gifts

Job summary

OX Security is seeking an Application Security Researcher to join our Security Research group in Toronto. You will push the boundaries of modern AppSec, building autonomous, agentic security capabilities and redefining offensive security at scale.

You’ll collaborate with engineers, researchers, and data scientists to design detection engines, measure AI model performance, and ship production-ready security features that protect the AI-driven SDLC.

Qualifications

  • M.Sc. in Computer Science, Cyber Security, or a related field.
  • 5+ years hands-on experience in offensive security, vulnerability research, or application security.
  • Deep understanding of web application and API vulnerabilities, including business-logic flaws and multi-step attack chains.
  • Strong coding skills in Python, Go, or a similar language, with production-grade code shipping.
  • Experience building or tuning detection logic (SAST, DAST, SCA, secrets, or custom rule engines) and reducing false positives.
  • Solid grasp of CI/CD, containers, Kubernetes, and at least one major cloud provider.
  • Hands-on experience using LLMs or AI models for security tasks.
  • Comfort working with large datasets (SQL, BigQuery, or similar) to drive research and measure detection accuracy.
  • Ability to take a research idea from prototype to production with minimal guidance and to communicate attack paths clearly to engineers and product managers.

Responsibilities

  • Research vulnerability chaining, business-logic flaws, and complex attack paths across applications and infrastructure.
  • Design and build detection engines and decision-making logic for autonomous security systems.
  • Evaluate AI models for application security use cases, measuring where they perform and where they fall short.
  • Prototype, build, and ship security capabilities into production environments.
  • Analyze large-scale security data to uncover exploitable attack paths and improve detection accuracy.
  • Partner with Product, Engineering, and Data teams to shape the next generation of security features.
  • Help set the team's research direction and own initiatives end to end, from idea to shipped capability.

Skills

Python
Go
Offensive security
Vulnerability research
Clear written communication

Education

M.Sc. in Computer Science or Cyber Security

Tools

SAST
DAST
SCA
Custom rule engines
CI/CD
Kubernetes
Cloud providers
BigQuery

Job description

About The Position

OX Security secures the AI-driven SDLC from prompt to production. We eliminate critical, real-time risks from AI code generation through cloud runtime by doing what conventional tools can’t: unifying development and cloud context to stop vulnerabilities right at the source. At OX, we’re building the future of cyber security for the AI era. If you’re looking to work on disruptive technology with an amazing team, you belong here.

About The Position

OX Security secures the AI-driven SDLC from prompt to production. We eliminate critical, real-time risks from AI code generation through cloud runtime by doing what conventional tools can’t: unifying development and cloud context to stop vulnerabilities right at the source. At OX, we’re building the future of cyber security for the AI era. If you’re looking to work on disruptive technology with an amazing team, you belong here.

We’re looking for a highly skilled Application Security Researcher to join our Security Research group and help us push the boundaries of modern AppSec. This is a critical, hands‑on role where you’ll work closely with engineers, researchers, and AI & data scientists to build the next generation of application security - including autonomous, agentic pen testing capabilities.

This is not a typical AppSec role. You’ll be building, breaking, and redefining how offensive security works at scale.

What You’ll Be Doing
  • Research vulnerability chaining, business-logic flaws, and complex attack paths across applications and infrastructure
  • Design and build detection engines and decision-making logic for autonomous security systems
  • Evaluate AI models for application security use cases, measuring where they perform and where they fall short
  • Prototype, build, and ship security capabilities into production environments
  • Analyze large-scale security data to uncover exploitable attack paths and improve detection accuracy
  • Partner with Product, Engineering, and Data teams to shape the next generation of security features
  • Help set the team's research direction and own initiatives end to end, from idea to shipped capability
Requirements
  • M.Sc. in Computer Science, Cyber Security, or a related field
  • 5+ years of hands‑on experience in offensive security, vulnerability research, or application security
  • Deep understanding of web application and API vulnerabilities, including business-logic flaws and multi‑step attack chains
  • Strong coding skills in Python, Go, or a similar language, with experience shipping production‑quality code
  • Experience building or tuning detection logic (SAST, DAST, SCA, secrets, or custom rule engines) and reducing false positives
  • Solid grasp of modern application and infrastructure stacks: CI/CD pipelines, containers, Kubernetes, and at least one major cloud provider
  • Hands‑on experience using LLMs or AI models for security tasks, and the judgment to measure where they help and where they fail
  • Comfort working with large datasets (SQL, BigQuery, or similar) to drive research and measure detection accuracy
  • Ability to take a research idea from prototype to production with minimal guidanceClear written communication: you can explain a complex attack path to engineers and product managers
Nice to Have
  • Published research, CVEs, conference talks, or bug bounty track record
  • Experience building AI agents or evaluation frameworks for LLMs
  • Background in exploit development, red teaming, or penetration testing
  • Experience with code analysis techniques (taint analysis, call graphs, reachability)
  • Contributions to open-source security tools
Benefits Package (via Vensure)

We partner with Vensure to provide top-tier benefits for our Canada-based team members:

  • Comprehensive Health Coverage: Medical, Dental, and Vision plans to keep you and your family healthy.
  • Unlimited Paid Time Off (PTO): We offer unlimited vacation because we trust you to take time when you need it and to manage your time effectively. We value work‑life balance and want you to recharge.
  • Gifts on your birthday & anniversary, & Holidays.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Software Engineer (Security)
Senior Software Engineer (Security)

Super • Toronto

On-site
CAD 90,000 - 120,000
Competitive salary
Learning & development allowance
Generous equity options
+2
Senior Backend Engineer - Agentic Pentest
Senior Backend Engineer - Agentic Pentest

OX Security • Canada

Hybrid
CAD 110,000 - 150,000
Health Coverage
Unlimited PTO
Birthday gifts
Application Security Researcher
Application Security Researcher

Team8 • Toronto

On-site
CAD 90,000 - 130,000
AI-Driven AppSec Researcher: Autonomous Pen Testing
AI-Driven AppSec Researcher: Autonomous Pen Testing

OX Security • Toronto

On-site
CAD 120,000 - 180,000
Health Coverage
Unlimited PTO
Birthday/anniversary gifts
Application Security Engineer
Application Security Engineer

Segment (Twilio) • Toronto

On-site
CAD 100,000 - 130,000
Principal Application Security Architect
Principal Application Security Architect

OpenText • Southwestern Ontario

On-site
CAD 140,000 - 190,000
Principal Product Security Architect
Principal Product Security Architect

OpenText • Southwestern Ontario

On-site
CAD 140,000 - 190,000
Principal Product Security Architect
Principal Product Security Architect

OpenText • Richmond Hill

On-site
CAD 150,000 - 190,000
Senior Application Security Analyst
Senior Application Security Analyst

Purolator Inc. • Mississauga

On-site
CAD 110,000 - 140,000
Senior Backend Engineer - Vibesec
Senior Backend Engineer - Vibesec

OX Security • Toronto

On-site
CAD 120,000 - 180,000
Health Coverage
Unlimited PTO
Birthday & Anniversary Gifts