- You’ll join an Application Security team that is deliberately moving away from the advisory model most AppSec functions are stuck in
- You’ll work across our stack (from TypeScript and Node.js, to Postgres and AWS cloud infrastructure) ensuring our applications are secure from design to deployment
- You’ll blend technical depth with systems thinking, working across teams to identify risks, build guardrails, and evolve our security practices as Relay scales
- That coverage number is where you come in. Right now, most of Relay’s platform has never been properly tested — and closing that gap is the single highest-leverage thing our team can do this year
- Your mission is to own a defined slice of it end to end: testing the services in scope, working out what’s actually exploitable, and fixing what you can yourself
- This is a role with room to grow. You’ll be working next to senior engineers who are maintaining our auth system and building our DAST tooling from scratch. The Relay AppSec team genuinely enjoys Application Security and is looking to make an impact on the field
- Threat modeling & offensive testing: Threat model technical design documents (TDDs) and run white-box penetration tests on our testing environment to identify vulnerabilities from an attacker’s point of view
- VDP & bug bounty: Triage researcher reports, reproduce/assess impact, coordinate fixes with owners, and close the loop with clear comms and durable controls
- Shipping the fixes you can: Contributing directly to Relay’s code base when it makes sense — writing the patch, not filing the ticket
- Working in our security tooling and extending it: Datadog security, secrets scanning and logging, Burp Suite, and in-house tools you’ll be expected to modify rather than just operate
- Building with AI as a default: Claude Code and Cursor are daily drivers on this team, not a pilot program
- Joining the team’s rhythms: Two weekly standups, a biweekly security champions session with product engineers, and a weekly Hack The Box session
- Software supply chain: Enforce provenance: SBOM on every build, dependency pinning/owner verification, private registries/proxies, and runtime SCA detections
Benefits
- Competitive salary and meaningful equity: Relay employees are Relay owners, complete with equity and a competitive salary. Since 2023, 66%+ of employees have received salary increases, with multiple new team members joining just last year.
- Social connection: We believe in celebrating our wins with two annual company-wide get-togethers, quarterly team events, happy hours, and special events and networking opportunities with industry leaders.
- Personal and professional growth: Through ongoing feedback, mentorship, and coaching, work with peers and leaders who are invested in your growth and success. Even with more than half of our team joining in the last 12 months, almost 20% have received promotions in the last year alone.
- Parental leave with top-up: We offer 12 weeks off with a 100% salary top-up for all full-time employees, regardless of location, and accessible for all parents: birthing, non-birthing, and adoptive
- Comprehensive health benefits: Enjoy full health benefits from day one: no probation period required. We offer flexible Health or Wellness Spending Accounts and medical, dental, and vision coverage for you and your dependents.
- Hybrid work environment: We value meaningful collaboration and connection at our Toronto office three days per week, with lunch, snacks, and beverages on us.
- Top-tier equipment: As a Mac-first company, our Toronto offices have everything you need to produce your best work comfortably, from multiple screens to ergonomic seating.
- Flexible vacation and time off: Every team member starts with 15 vacation days and 5 flex days to use as needed, plus an extra week of office closure during the end-of-year holidays.
- Dog-friendly space: Can dogs really make you happy and healthy? We don’t know for sure, but since we don’t want to chance it, our office is 100% floof-friendly.
- Award-winning workplace: As a winner of CB Insights’ Fintech 100, Deloitte Canada’s Technology Fast 50, Forbes Fintech 50, and the CIX Top 10 Growth Award, Relay is a recognized innovative and high-growth company.
We’re looking for an Senior Application Security Engineer II who thrives on autonomy, curiosity, and impact
Ownership: You have a sense of responsibility towards problems and take ownership over them making sure nothing is forgotten and stakeholders stay informed
Security fundamentals: Deep understanding of OWASP Top 10 and real-world exploitation/mitigation techniques
You build with AI. You use AI tooling in your daily work and you’ve built something with it. You can talk about where it gets things wrong, not just that it’s fast
You have 5 to 6 years of professional security experience. Application security, penetration testing, or product security engineering or similar roles
You’ve shipped production code: Production-level software real users depended on. And you can read an unfamiliar codebase well enough to fix something in it, which is most of this job
Clear communicator & collaborator: you are a collaborator who loves to partner with developers to bring value to customers in the most secure way possible
Mentorship: You are comfortable mentoring team members and members of other teams on security best practices
You push relentlessly for reinvention: You’re always asking \"how can this be better?\" — in your work, in your craft, in yourself. Comfort is a signal to push harder, not coast. You’d rather build something better than defend something familiar
Small businesses are why we’re here: Relay exists to help them thrive — and that mission has to resonate with you
You’re energized by complexity and ambiguity: You enjoy tackling problems that don’t come with a playbook. You’re comfortable building from scratch, iterating as you go, and collaborating to shape the best path forward
You care about impact, not noise: You care deeply about the substance of your work. You measure success by results, not recognition, and you let your work speak for itself
You seek out feedback: You see directness as respect, not criticism. You actively seek input, sit with hard truths, and use feedback as fuel for improvement
You own your work: You take pride in your work, follow through on commitments, and feel a deep sense of responsibility for outcomes, not just tasks
You crave autonomy: We trust our team with big challenges and the freedom to solve them. If you’re someone who takes initiative, is comfortable taking risks, and seeks input when needed, you’ll find the freedom here empowering
You build with AI, not just use it: You’re actively embedding AI into how you work, pushing what’s possible, and bringing your team along with you
We’re looking for people who are relentless, curious, and care deeply about the work. You’re encouraged to apply even if your experience doesn’t perfectly match the job description — your perspective and drive matter more
","IsExpired":false}