Senior Security Engineer - Application Security

Faire

Toronto

Hybrid

CAD 160,000 - 220,000

Full time

4 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Equity
Benefits

Job summary

Faire seeks a Senior Security Engineer specializing in Application Security to harden our software supply chain and secure our AI-assisted development workflows. You will own vulnerability management, perform threat modeling, and lead security reviews across product teams in a hybrid work model.

Bring hands-on experience with SAST/DAST/SCA, cloud security in AWS/GCP, and a passion for coding security problems at scale. Equity and comprehensive benefits are offered in a fast-growing marketplace.

Qualifications

  • Experience integrating security into the software development lifecycle.
  • Experience driving vulnerability remediation across teams you do not own, with severities, SLAs, and closure.
  • Exposure to offensive security, such as bug bounty or external pentests.
  • Passion for coding and automating security problems over relying on process.
  • Comfort reading and reviewing code in Kotlin, Java, Python, or TypeScript.
  • Hands-on with AppSec tooling (SAST/DAST/SCA/secret scanning) and tuning rules to reduce false positives.
  • Strong understanding of web app security and OWASP Top 10; focus on systemic fixes.
  • Experience leading threat models on unfamiliar systems and determining when they are needed.
  • Experience in AWS or GCP cloud environments.
  • Ability to explain risk to engineers to encourage fixes.
  • Curiosity about AI-assisted development security.

Responsibilities

  • Find and fix vulnerabilities in first-party code and third-party dependencies.
  • Build shift-left tooling and CI/CD guardrails for secure default paths.
  • Own offensive security engagements with external vendors.
  • Evaluate and harden security of AI-assisted code generation workflows.
  • Own the bug bounty program and vulnerability lifecycle from intake to closure.
  • Lead threat modeling and secure design reviews for new products and high-risk changes.
  • Conduct security reviews with product teams and develop secure coding standards and scaling frameworks.

Skills

Security engineering
SDLC integration
Vulnerability remediation
Offensive security
Automated tooling
Cloud (AWS/GCP)
Code reviews

Education

Bachelor's degree in Computer Science or related field

Tools

SAST
DAST
SCA
Secret scanning

Job description

Senior Security Engineer - Application Security

Faire is a technology wholesale platform built on the belief that the future is local. Independent retailers around the globe collectively represent a multi-hundred-billion-dollar wholesale market that has historically been fragmented and offline. At Faire, we're using the power of tech, data, and machine learning to connect this thriving community of entrepreneurs across the globe. Picture your favorite boutique in town - we help them discover the best products from around the world to sell in their stores. With the right tools and insights, we believe that we can level the playing field so businesses can grow and local communities can thrive.

We're looking for smart, resourceful and passionate people to join us as we power the shop local movement. If you believe in community, come join ours.

About this role

Our Engineering organization owns the software that makes our marketplace work. Our Application Security function is focused on keeping vulnerabilities out of the code and software as it's built and shipped, owning the SDLC from commit to production. We care about good engineering practice and love to write software that is secure, tested, easy to maintain, and can scale to millions of users. We build scalable, reusable frameworks; consult with product teams; listen to the data; and iterate.

As a Senior Security Engineer, Application Security, you'll collaborate with us to:

  • Find and fix vulnerabilities in first-party code and third-party dependencies using AI-powered detection, SAST, DAST, SCA, and secret scanning tooling.
  • Build shift-left tooling and CI/CD guardrails that make the secure path the default in the build pipeline.
  • Own offensive security engagements such as penetration tests with external vendors.
  • Evaluate and harden the security of AI-assisted code generation workflows.
  • Own the bug bounty program and the vulnerability management lifecycle end to end, from intake through remediation and closure.
  • Lead threat modeling and secure design reviews for new products and high-risk platform changes, shaping the architecture before the code is written rather than reviewing it after.
  • Conduct security reviews and consultations with product and platform teams and develop secure coding standards and scaling frameworks for recurring vulnerability classes.

We're excited about you because you have:

  • Hands-on experience integrating security into the software development lifecycle.
  • Experience driving vulnerability remediation across teams you do not own, with a point of view on how to set severities, hold SLAs, and get things actually closed.
  • Exposure to offensive security, whether that is running a bug bounty program, scoping penetration tests with external vendors, or finding and reporting real vulnerabilities yourself.
  • A passion for coding and solving security problems scalably with code and automation, rather than with process and policy.
  • Comfort writing and reviewing code in OOP languages such as Kotlin, Java, Python, or TypeScript, enough to read an unfamiliar service, judge whether a finding is real, and open the pull request that fixes it.
  • Practical experience with AppSec detection tooling (SAST, DAST, SCA, or secret scanning), including the unglamorous parts: deploying it, tuning the rules, and cutting the false positives so engineers trust the results.
  • A thorough understanding of web application security principles and common vulnerabilities, including OWASP Top 10, with an instinct for the systemic fix behind the individual finding.
  • Experience leading threat models on systems you did not build, and the judgement to know which designs need one and which do not.
  • Experience working in modern cloud computing environments such as AWS or GCP.
  • The ability to explain risk to product engineers in a way that makes them want to fix it, and the credibility to be invited into design discussions rather than added as a gate.
  • Curiosity about the security of AI-assisted development, and interest in figuring out what changes when a meaningful share of the code is machine-generated.

Technologies we use and teach:

  • Kotlin, Typescript, Python
  • AppSec tooling - SAST/DAST/SCA/secret scanning

Salary Range

Canada: the pay range for this role is $160,000 to $220,000 per year.

This role will also be eligible for equity and benefits. Actual base pay will be determined based on permissible factors such as transferable skills, work experience, market demands, and primary work location. The base pay range provided is subject to change and may be modified in the future.

Faire uses Artificial Intelligence (AI) to screen and select applicants for this position.

This job posting is for an existing vacancy.

Hybrid Faire employees currently go into the office 3 days per week on Tuesdays, Thursdays, and a third flex day of their choosing (Monday, Wednesday, or Friday). Additionally, hybrid in-office roles will have the flexibility to work remotely up to 4 weeks per year. Specific Workplace and Information Technology positions may require onsite attendance 5 days per week as will be indicated in the job posting.

Why you’ll love working at Faire

  • Move fast: You'll own meaningful problems that serve customers around the globe with the agency to move fast and see your results clearly.
  • Equipped to scale: We invest in what matters, including the latest enterprise AI tools, to help you work smarter and get more out of every day.
  • Best in class: Our team is full of sharp, kind, and generous colleagues who care about their craft and about helping you grow in yours.
  • Real rewards. Competitive pay, equity, and comprehensive benefits designed to support your life inside and outside of work.
  • Belonging: We're intentional about building an environment where every Faire employee has equal access to opportunities, growth, and success.

Faire was founded in 2017 by a team of early product and engineering leads from Square. We’re backed by some of the top investors in retail and tech including: Y Combinator, Lightspeed Venture Partners, Forerunner Ventures, Khosla Ventures, Sequoia Capital, Founders Fund, and DST Global. We have headquarters in San Francisco and Kitchener-Waterloo, and a global employee presence across offices in Toronto, London, and New York. To learn more about Faire and our customers, you can read more on our blog .

Faire provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, genetics, sexual orientation, gender identity or gender expression.

Faire is committed to providing access, equal opportunity and reasonable accommodation for individuals with disabilities in employment, its services, programs, and activities. Accommodations are available throughout the recruitment process and applicants with a disability may request to be accommodated throughout the recruitment process. We will work with all applicants to accommodate their individual accessibility needs. To request reasonable accommodation, please fill out our Accommodation Request Form (https://bit.ly/faire-form)

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer, Application Security
Senior Security Engineer, Application Security

Faire • Toronto

Hybrid
CAD 160,000 - 220,000
Equity and benefits
Senior Security Engineer, Application Security
Senior Security Engineer, Application Security

faire • Kitchener

On-site
CAD 160,000 - 220,000
Equity
Benefits
Staff Software Engineer - Code Authoring
Staff Software Engineer - Code Authoring

Faire • Toronto

Hybrid
CAD 191,000 - 262,000
Equity
Hybrid work model
Remote work up to 4 weeks/year
Senior Frontend Engineer
Senior Frontend Engineer

Worky • Toronto

Hybrid
CAD 160,000 - 220,000
Equity
Benefits
Hybrid/Remote flexibility
Staff Software Engineer - Code Authoring
Staff Software Engineer - Code Authoring

Worky • Toronto

Hybrid
CAD 191,000 - 262,000
Senior Software Engineer - Brand Platform - Backend
Senior Software Engineer - Brand Platform - Backend

Faire • Kitchener, Toronto

Hybrid
CAD 156,000 - 215,000
Equity
Comprehensive benefits
Hybrid work model
+1
Staff Software Engineer - Code Authoring
Staff Software Engineer - Code Authoring

Socket.dev • Kitchener

Hybrid
CAD 191,000 - 262,000
Equity
Competitive pay
Comprehensive benefits
+2
Senior Software Engineer - Design Platform - Frontend
Senior Software Engineer - Design Platform - Frontend

Engg • Toronto

Hybrid
CAD 160,000 - 220,000
Staff Backend Engineer - Search FX (Discovery Experience)
Staff Backend Engineer - Search FX (Discovery Experience)

Faire • Kitchener

Hybrid
CAD 191,000 - 262,000
Competitive pay
Equity
Comprehensive benefits
+1
Software Engineer - Retailer Experience & Growth - Fullstack, Backend or Frontend
Software Engineer - Retailer Experience & Growth - Fullstack, Backend or Frontend

Faire • Kitchener, Toronto

Hybrid
CAD 107,000 - 178,000