Senior Application Security Researcher

Kibbi

Toronto

On-site

CAD 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Kibbi seeks a senior, hands-on Application Security Researcher to push modern AppSec forward. You will work with engineers, researchers and AI/data scientists on next-generation detection, including autonomous, agentic pen-testing capabilities.

This is a build-and-break role, not a typical AppSec position. 5+ years in offensive security or vulnerability research, with strong coding in Python/Go and production-ready results.

Qualifications

  • 5+ years hands-on in offensive security, vulnerability research, or application security.
  • Deep understanding of web application and API vulnerabilities, including business-logic flaws and multi-step attack chains.
  • Strong coding in Python, Go, or similar, with production-quality code shipped.
  • Experience building or tuning detection logic (SAST/DAST/SCA/secret detection) and reducing false positives.
  • Solid grasp of CI/CD pipelines, containers, Kubernetes, and at least one major cloud provider.
  • Hands-on use of LLMs/AI models for security tasks with good judgment on applicability.
  • Comfort with large datasets (SQL, BigQuery) to drive research and detection accuracy.
  • Ability to take research ideas from prototype to production with minimal guidance.
  • Clear written communication—explain complex attack paths to engineers and product managers.
  • M.SC. in Computer Science, Cyber Security, or related field.

Responsibilities

  • Lead hands-on offensive security and vulnerability research.
  • Develop and tune detection logic across SAST/DAST/SCAs and reduce false positives.
  • Collaborate with engineers, researchers and AI/data scientists on next-generation detection.

Skills

Offensive security
Web/API vulnerabilities
Python
Go
Detection logic
CI/CD
Containers
Kubernetes
Cloud platforms
LLMs for security
SQL
BigQuery
Technical communication
Research-to-production

Education

M.Sc. in Computer Science, Cyber Security, or related field

Tools

Open-source security tools

Job description

The company secures the AI-driven SDLC from prompt to production, unifyingdevelopment and cloud context to stop vulnerabilities at the source. TheSecurity Research group is hiring a senior, hands-on Application SecurityResearcher to push modern AppSec forward — working with engineers, researchersand AI/data scientists on next-generation detection, including autonomous,agentic pen-testing capabilities. This is a build-and-break role, not a typicalAppSec position.

Requirements
  • 5+ years hands-on in offensive security, vulnerability research, orapplication security
  • Deep understanding of web application and API vulnerabilities, includingbusiness-logic flaws and multi-step attack chains
  • Strong coding in Python, Go, or similar, with production-quality code shipped
  • Experience building or tuning detection logic (SAST, DAST, SCA, secrets, orcustom rule engines) and reducing false positives
  • Solid grasp of modern stacks: CI/CD pipelines, containers, Kubernetes, and atleast one major cloud provider
  • Hands-on use of LLMs / AI models for security tasks, with the judgment tomeasure where they help and where they fail
  • Comfort with large datasets (SQL, BigQuery, or similar) to drive research andmeasure detection accuracy
  • Takes research ideas from prototype to production with minimal guidance
  • Clear written communication — can explain a complex attack path to engineersand product managers
  • M.Sc. in Computer Science, Cyber Security, or a related field
Nice to have
  • Published research, CVEs, conference talks, or a bug bounty track record
  • Experience building AI agents or evaluation frameworks for LLMs
  • Background in exploit development, red teaming, or penetration testing
  • Code analysis techniques (taint analysis, call graphs, reachability)
  • Contributions to open-source security tools
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Application Security Researcher
Senior Application Security Researcher

Commit • Toronto

On-site
CAD 120,000 - 190,000
Application Security Researcher
Application Security Researcher

OX Security • Toronto

On-site
CAD 120,000 - 180,000
Health Coverage
Unlimited PTO
Birthday/anniversary gifts
Senior AppSec Researcher — Build & Break AI-Driven Defenses
Senior AppSec Researcher — Build & Break AI-Driven Defenses

Commit • Toronto

On-site
CAD 120,000 - 190,000
Security Research Engineer - AI Security, Agentic AI & Emerging Cybersecurity
Security Research Engineer - AI Security, Agentic AI & Emerging Cybersecurity

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision! • Toronto

On-site
CAD 140,000 - 210,000
Senior Software Engineer (Security)
Senior Software Engineer (Security)

Super • Toronto

On-site
CAD 90,000 - 120,000
Competitive salary
Learning & development allowance
Generous equity options
+2
(DEV) Java developer - Application security
(DEV) Java developer - Application security

Vaco Recruiter Services • Montreal (administrative region)

On-site
CAD 120,000 - 150,000
Senior Security Engineer - AI Focus
Senior Security Engineer - AI Focus

Euna Solutions • Oakville

On-site
CAD 120,000 - 180,000
Senior Security Engineer
Senior Security Engineer

Metrics Recruitment • Vancouver

On-site
CAD 90,000 - 130,000
Senior Offensive Security Engineer -SAST, DAST, SCA, IAST
Senior Offensive Security Engineer -SAST, DAST, SCA, IAST

Astra-North Infoteck Inc. ~ Conquering today’s challenges, achieving tomorrow’s vision! • Toronto

On-site
CAD 120,000 - 160,000
Security Engineer
Security Engineer

Atos • Toronto

On-site
CAD 110,000 - 150,000