Enable job alerts via email!

Senior Application Security Engineer

Webflow

Canada

Remote

CAD 80,000 - 100,000

Full time

Today
Be an early applicant

Job summary

A leading tech company is seeking a Senior Application Security Engineer to enhance secure development practices. This remote role involves collaborating with engineering teams, implementing security best practices, and evaluating applications for security improvements. Ideal candidates will have significant experience in application security, secure coding, and communication skills. The position offers competitive benefits including equity and comprehensive health coverage.

Benefits

Equity ownership
100% employer-paid healthcare
Flexible PTO
Access to mental wellness resources

Qualifications

  • 3+ years of application security experience.
  • Proficiency with security tooling and experience writing code.
  • Evaluating applications to improve security design.

Responsibilities

  • Secure Webflow’s web application platform.
  • Champion security standards in business strategies.
  • Find and mitigate security vulnerabilities.

Skills

Application security experience
Web application security
Secure coding
Penetration testing
Security tooling proficiency
Bug bounty program experience
Strong communication skills

Tools

SCA
SAST
DAST
API security
Job description
About the role:

At Webflow, our mission is to bring development superpowers to everyone. As the pioneer of the Website Experience Platform (WXP), we’re redefining how teams Build, Manage, and Optimize for the web — combining visual development, powerful content management systems, AI-driven personalization, seamless hosting, and end-to-end analytics in a single, unified platform. With AI at the core, Webflow helps teams move faster, create more performant digital experiences, and scale without heavy engineering support. From independent designers and creative agencies to global enterprises, hundreds of thousands of organizations use Webflow to turn ideas into reality — and to power what’s possible on the web.

We’re looking for a Senior Application Security Engineer to help us level up Webflow’s secure development practices ranging from secure coding, tooling, and improving procedures.

About the role
  • Location: Remote-first (Argentina)
  • Full-time
  • Permanent

This role is also eligible to participate in Webflow's company-wide bonus program. Target amounts are a percentage of base salary and vary by career level. Payouts are based on company performance against established financial and operational goals.

  • Reporting to the Manager of Application Security

As an Application Security Engineer, you’ll …

  • Collaborate with the Webflow engineering team to secure Webflow’s web application platform and ecosystem.
  • Bring security best practices to the software development lifecycle.
  • Work as part of a team to champion security standards while balancing business strategies and requirements.
  • Support Webflow’s security current and future compliance frameworks
  • Work to find security vulnerabilities through grey-box techniques, and propose solutions at the architecture and code level to mitigate findings.
  • Contribute code and architecture improvements to enable security within Webflow’s application for engineers.
  • Cross-train entry and mid-level application security engineers

In addition to the responsibilities outlined above, at Webflow we will support you in identifying where your interests and development opportunities lie and we'll help you incorporate them into your role.

About you

You will thrive as a Senior Application Security Engineer if you...

  • Have 3+ years of application security experience with a solid background in web application security, secure coding, penetration testing, and insecure engineering practices.
  • Proficiency with security tooling (SCA, SAST, DAST, API security) and experience writing code to build tools, create exploit scripts, or remediate production vulnerabilities.
  • Experience evaluating applications to improve security design, conducting threat modeling, and driving risk reduction through secure SDLC processes, tooling, and automation.
  • Hands-on experience with bug bounty programs, including setup, exploit reproduction, and coordinating remediation.
  • Familiarity with leveraging AI for security reviews and coding assistance to enhance application security practices.
  • Strong communication skills with a passion for security, continuous learning, and the ability to clearly share knowledge and mentor colleagues.
  • Business-level fluency to read, write and speak in English
Our Core Behaviors
  • Build lasting customer trust. We build trust by taking action that puts customer trust first.
  • Win together. We play to win, and we win as one team. Success at Webflow isn't a solo act.
  • Reinvent ourselves. We don't just improve what exists, we imagine what's possible.
  • Deliver with speed, quality, and craft. We move fast because the moment demands it, and we do so without lowering the bar.
Benefits & wellness
  • Equity ownership (RSUs) in a growing, privately-owned company
  • 100% employer-paid healthcare, vision, and dental insurance coverage for full-time employees (working 30+ hours per week) and their dependents. Full-time employees may also be eligible for voluntary insurance options where applicable in the respective country of employment
  • 12 weeks of paid parental leave for both birthing and non-birthing caregivers, as well as an additional 6-8 weeks of pregnancy disability leave for birthing parents to be used before child bonding leave (note: where local requirements are more generous, employees receive the greater benefit); full-time employees also have access to family planning care and reimbursement
  • Flexible PTO for all locations and sabbatical program
  • Access to mental wellness and professional coaching, therapy, and Employee Assistance Program
  • Monthly stipends to support work and wellness
  • 401k plan or pension schemes (in countries where statutorily required), and other financial wellness benefits, like CPA and financial advisor coverage

Temporary employees may be eligible for paid holiday and time off, statutory leaves of absence, and company-sponsored medical benefits depending on their Fixed Term Contract and their country/state of employment.

Remote, together

At Webflow, equality is a core tenet of our culture. We are an Equal Opportunity (EEO)/Veterans/Disabled Employer and are committed to building an inclusive global team that represents a variety of backgrounds, perspectives, beliefs, and experiences. Employment decisions are made on the basis of job-related criteria without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other classification protected by applicable law. Pursuant to the San Francisco Fair Chance Ordinance, Webflow will consider for employment qualified applicants with arrest and conviction records.

We will ensure that individuals with disabilities are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Upon interview scheduling, instructions for confidential accommodation requests will be administered.

To join Webflow, you'll need a valid right to work authorization depending on the country of employment.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.