Senior Security Engineer (Application Security)

Faire

Toronto

On-site

CAD 110,000 - 150,000

Full time

6 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Healthcare benefits
Parental leave
Learning grant
WFH stipend
Charitable matching
Wellness programs

Job summary

Faire is seeking an Application Security Engineer to join our Engineering organization. You will help secure our marketplace by finding and fixing vulnerabilities in first‑party and third‑party code, integrating AI‑powered detection and guardrails into the SDLC.

You will lead threat modeling, security reviews for new products, and collaborate with product teams to bake in secure design. Strong experience with SAST/DAST/SCA, cloud environments (AWS/GCP), and clear risk communication is essential.

Qualifications

  • 5+ years in application security or secure software development.
  • Strong knowledge of OWASP Top 10 and secure SDLC.
  • Experience with SAST/DAST/SCA and secret scanning tooling.
  • Ability to explain risk to engineers and influence design discussions.
  • Experience with cloud environments (AWS or GCP).

Responsibilities

  • Find and fix vulnerabilities in first‑party code and third‑party dependencies using AI detection, SAST, DAST, SCA and secret scanning tools.
  • Build shift‑left tooling and CI/CD guardrails to make secure paths the default.
  • Own offensive security engagements such as penetration tests with external vendors.
  • Lead threat modeling and secure design reviews for new products and high‑risk changes.
  • Conduct security reviews and consultations and develop secure coding standards and scaling frameworks.

Skills

Threat modeling
Secure coding practices
Vulnerability remediation
CI/CD integration
OWASP Top 10
Cloud security (AWS/GCP)
Kotlin/Java/Python/TypeScript
SAST/DAST/SCA
Communication with engineers

Tools

SAST
DAST
SCA
Secret scanning

Job description

  • Our Engineering organization owns the software that makes our marketplace work. Our Application Security function is focused on keeping vulnerabilities out of the code and software as it’s built and shipped, owning the SDLC from commit to production
  • We care about good engineering practice and love to write software that is secure, tested, easy to maintain, and can scale to millions of users. We build scalable, reusable frameworks; consult with product teams; listen to the data; and iterate
  • Find and fix vulnerabilities in first‑party code and third‑party dependencies using AI‑powered detection, SAST, DAST, SCA, and secret scanning tooling
  • Build shift‑left tooling and CI/CD guardrails that make the secure path the default in the build pipeline
  • Own offensive security engagements such as penetration tests with external vendors
  • Evaluate and harden the security of AI‑assisted code generation workflows
  • Own the bug bounty program and the vulnerability management lifecycle end to end, from intake through remediation and closure
  • Lead threat modeling and secure design reviews for new products and high‑risk platform changes, shaping the architecture before the code is written rather than reviewing it after
  • Conduct security reviews and consultations with product and platform teams and develop secure coding standards and scaling frameworks for recurring vulnerability classes
Benefits
  • Comprehensive healthcare: Including Health, Dental, Vision and Disability for all our locations.
  • Time off: Paid time off, holidays and company‑wide “Faire Fundays”.
  • Parental leave: Generous parental and family leave, as well as fertility support benefits.
  • Productivity support: Monthly stipends to help cover work from home connectivity needs.
  • Annual learning grant: For personal and professional development, as well as unlimited access to training courses through LinkedIn Learning.
  • Thoughtfully designed spaces: All of our offices have been designed with local in mind – from our architects to our coffee blends.
  • Fitness and well‑being benefits: Including monthly credit towards your wellness‑related programmes.
  • Mental health benefits: Including free access to Modern Health therapists and resources.
  • Charitable matching: Faire will match up to £250 of your charity donations, every year.
  • Career planning: Whether you want to grow as a leader, hone your craft or explore a new discipline, our career framework allows space for you to explore.

Curiosity about the security of AI-assisted development, and interest in figuring out what changes when a meaningful share of the code is machine-generatedExperience driving vulnerability remediation across teams you do not own, with a point of view on how to set severities, hold SLAs, and get things actually closedA passion for coding and solving security problems scalably with code and automation, rather than with process and policyComfort writing and reviewing code in OOP languages such as Kotlin, Java, Python, or TypeScript, enough to read an unfamiliar service, judge whether a finding is real, and open the pull request that fixes itExperience leading threat models on systems you did not build, and the judgement to know which designs need one and which do notExposure to offensive security, whether that is running a bug bounty program, scoping penetration tests with external vendors, or finding and reporting real vulnerabilities yourselfA thorough understanding of web application security principles and common vulnerabilities, including OWASP Top 10, with an instinct for the systemic fix behind the individual findingHands‑on experience integrating security into the software development lifecyclePractical experience with AppSec detection tooling (SAST, DAST, SCA, or secret scanning), including the unglamorous parts: deploying it, tuning the rules, and cutting the false positives so engineers trust the resultsThe ability to explain risk to product engineers in a way that makes them want to fix it, and the credibility to be invited into design discussions rather than added as a gateExperience working in modern cloud computing environments such as AWS or GCP

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer, Application Security
Senior Security Engineer, Application Security

faire • Kitchener

Hybrid
CAD 160,000 - 220,000
Equity
Benefits
Application Security Engineer
Application Security Engineer

Segment (Twilio) • Toronto

On-site
CAD 100,000 - 130,000
Developer
Developer

CoFoMo Inc. • Lévis

On-site
CAD 120,000 - 150,000
Developer
Developer

COFOMO • Lévis

On-site
CAD 90,000 - 130,000
Senior Security Engineer, Application Security
Senior Security Engineer, Application Security

Faire • Toronto

Hybrid
CAD 160,000 - 220,000
Equity and benefits
IT & Security Operations Lead
IT & Security Operations Lead

Software Secured • Ottawa

On-site
CAD 90,000 - 120,000
Profit sharing 8-15%
Monthly Ubereats budget
Work from home stipend
+5
Staff Application Security Specialist
Staff Application Security Specialist

Workleap Inc. • Canada

Hybrid
CAD 120,000 - 180,000
LTIP program
RRSP + health insurance
Flexible vacation
+3
Senior Security Research Engineer (Security Operations and Novel Adversary Research)
Senior Security Research Engineer (Security Operations and Novel Adversary Research)

Elastic • Ottawa

Hybrid
CAD 120,000 - 170,000
Fully paid health coverage for you and
Flexible location and schedule
Generous vacation days
+3
Chief Software Engineering Architect
Chief Software Engineering Architect

DataStealth Inc. • Mississauga

Hybrid
CAD 180,000 - 240,000
Hybrid schedule
Security Engineer, Application Security
Security Engineer, Application Security

Sentry • Toronto

On-site
CAD 162,000 - 420,000
Equity grants
Paid time off
Health insurance