Senior Application Security Engineer

Relay

Toronto

On-site

CAD 120,000 - 180,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Equity
Hybrid work
Health benefits
Parental leave
Flexible vacation

Job summary

Relay is seeking a Senior Application Security Engineer II in Canada to own security across the stack from design to deployment. You’ll conduct threat modeling, white-box testing, and coordinate fixes with engineering teams. You’ll contribute to our DAST tooling and improve security guardrails as Relay scales.

You’ll ship production fixes, mentor teammates, and work with AI tooling to accelerate secure development. This role offers hybrid work from our Toronto office and equity opportunities.

Qualifications

  • Security-focused mindset across design, development, and deployment stages.
  • Hands-on experience with penetration testing and vulnerability remediation.
  • Deep understanding of OWASP Top 10 and secure coding practices.

Responsibilities

  • Perform threat modeling and offensive testing to identify vulnerabilities.
  • Triage and reproduce researcher reports; coordinate fixes with owners.
  • Contribute to Relay’s DAST tooling and extend security capabilities in-house.

Skills

Application Security
Penetration Testing
OWASP Top 10
Code Reading
Mentorship
AI tooling

Tools

Burp Suite
Datadog security
Secrets scanning
CI/CD security tooling

Job description


  • You’ll join an Application Security team that is deliberately moving away from the advisory model most AppSec functions are stuck in

  • You’ll work across our stack (from TypeScript and Node.js, to Postgres and AWS cloud infrastructure) ensuring our applications are secure from design to deployment

  • You’ll blend technical depth with systems thinking, working across teams to identify risks, build guardrails, and evolve our security practices as Relay scales

  • That coverage number is where you come in. Right now, most of Relay’s platform has never been properly tested — and closing that gap is the single highest-leverage thing our team can do this year

  • Your mission is to own a defined slice of it end to end: testing the services in scope, working out what’s actually exploitable, and fixing what you can yourself

  • This is a role with room to grow. You’ll be working next to senior engineers who are maintaining our auth system and building our DAST tooling from scratch. The Relay AppSec team genuinely enjoys Application Security and is looking to make an impact on the field

  • Threat modeling & offensive testing: Threat model technical design documents (TDDs) and run white-box penetration tests on our testing environment to identify vulnerabilities from an attacker’s point of view

  • VDP & bug bounty: Triage researcher reports, reproduce/assess impact, coordinate fixes with owners, and close the loop with clear comms and durable controls

  • Shipping the fixes you can: Contributing directly to Relay’s code base when it makes sense — writing the patch, not filing the ticket

  • Working in our security tooling and extending it: Datadog security, secrets scanning and logging, Burp Suite, and in-house tools you’ll be expected to modify rather than just operate

  • Building with AI as a default: Claude Code and Cursor are daily drivers on this team, not a pilot program

  • Joining the team’s rhythms: Two weekly standups, a biweekly security champions session with product engineers, and a weekly Hack The Box session

  • Software supply chain: Enforce provenance: SBOM on every build, dependency pinning/owner verification, private registries/proxies, and runtime SCA detections


Benefits


  • Competitive salary and meaningful equity: Relay employees are Relay owners, complete with equity and a competitive salary. Since 2023, 66%+ of employees have received salary increases, with multiple new team members joining just last year.

  • Social connection: We believe in celebrating our wins with two annual company-wide get-togethers, quarterly team events, happy hours, and special events and networking opportunities with industry leaders.

  • Personal and professional growth: Through ongoing feedback, mentorship, and coaching, work with peers and leaders who are invested in your growth and success. Even with more than half of our team joining in the last 12 months, almost 20% have received promotions in the last year alone.

  • Parental leave with top-up: We offer 12 weeks off with a 100% salary top-up for all full-time employees, regardless of location, and accessible for all parents: birthing, non-birthing, and adoptive

  • Comprehensive health benefits: Enjoy full health benefits from day one: no probation period required. We offer flexible Health or Wellness Spending Accounts and medical, dental, and vision coverage for you and your dependents.

  • Hybrid work environment: We value meaningful collaboration and connection at our Toronto office three days per week, with lunch, snacks, and beverages on us.

  • Top-tier equipment: As a Mac-first company, our Toronto offices have everything you need to produce your best work comfortably, from multiple screens to ergonomic seating.

  • Flexible vacation and time off: Every team member starts with 15 vacation days and 5 flex days to use as needed, plus an extra week of office closure during the end-of-year holidays.

  • Dog-friendly space: Can dogs really make you happy and healthy? We don’t know for sure, but since we don’t want to chance it, our office is 100% floof-friendly.

  • Award-winning workplace: As a winner of CB Insights’ Fintech 100, Deloitte Canada’s Technology Fast 50, Forbes Fintech 50, and the CIX Top 10 Growth Award, Relay is a recognized innovative and high-growth company.


We’re looking for an Senior Application Security Engineer II who thrives on autonomy, curiosity, and impact


Ownership: You have a sense of responsibility towards problems and take ownership over them making sure nothing is forgotten and stakeholders stay informed


Security fundamentals: Deep understanding of OWASP Top 10 and real-world exploitation/mitigation techniques


You build with AI. You use AI tooling in your daily work and you’ve built something with it. You can talk about where it gets things wrong, not just that it’s fast


You have 5 to 6 years of professional security experience. Application security, penetration testing, or product security engineering or similar roles


You’ve shipped production code: Production-level software real users depended on. And you can read an unfamiliar codebase well enough to fix something in it, which is most of this job


Clear communicator & collaborator: you are a collaborator who loves to partner with developers to bring value to customers in the most secure way possible


Mentorship: You are comfortable mentoring team members and members of other teams on security best practices


You push relentlessly for reinvention: You’re always asking \"how can this be better?\" — in your work, in your craft, in yourself. Comfort is a signal to push harder, not coast. You’d rather build something better than defend something familiar


Small businesses are why we’re here: Relay exists to help them thrive — and that mission has to resonate with you


You’re energized by complexity and ambiguity: You enjoy tackling problems that don’t come with a playbook. You’re comfortable building from scratch, iterating as you go, and collaborating to shape the best path forward


You care about impact, not noise: You care deeply about the substance of your work. You measure success by results, not recognition, and you let your work speak for itself


You seek out feedback: You see directness as respect, not criticism. You actively seek input, sit with hard truths, and use feedback as fuel for improvement


You own your work: You take pride in your work, follow through on commitments, and feel a deep sense of responsibility for outcomes, not just tasks


You crave autonomy: We trust our team with big challenges and the freedom to solve them. If you’re someone who takes initiative, is comfortable taking risks, and seeks input when needed, you’ll find the freedom here empowering


You build with AI, not just use it: You’re actively embedding AI into how you work, pushing what’s possible, and bringing your team along with you


We’re looking for people who are relentless, curious, and care deeply about the work. You’re encouraged to apply even if your experience doesn’t perfectly match the job description — your perspective and drive matter more

","IsExpired":false}
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Application Security Engineer II
Application Security Engineer II

Better Tomorrow Ventures • Toronto

On-site
CAD 126,000 - 154,000
Senior Application Security Engineer II
Senior Application Security Engineer II

Relay • Toronto

On-site
CAD 180,000 - 220,000
Senior Application Security Engineer II
Senior Application Security Engineer II

Relay Fi • Toronto

On-site
CAD 180,000 - 220,000
Application Security Engineer II
Application Security Engineer II

Relay Fi • Toronto

On-site
CAD 126,000 - 154,000
Application Security Engineer II
Application Security Engineer II

Relay • Toronto

On-site
CAD 126,000 - 154,000
Senior Application Security Engineer II
Senior Application Security Engineer II

Better Tomorrow Ventures • Toronto

On-site
CAD 180,000 - 220,000
Senior Design Engineer
Senior Design Engineer

Relay • Toronto

Hybrid
CAD 130,000 - 160,000
Health benefits from day one
15 vacation days and 5 flex days
Parental leave with salary top‑up
+3
Senior Software Engineer
Senior Software Engineer

Relay • Toronto

On-site
CAD 148,000 - 182,000
Senior Data Engineer
Senior Data Engineer

Relay • Toronto

Hybrid
CAD 120,000 - 155,000
Equity
Hybrid work Toronto
Health benefits
+2
Engineering Manager, Growth
Engineering Manager, Growth

Better Tomorrow Ventures • Toronto

On-site
CAD 207,000 - 253,000