Senior/Staff Engineer, Application & Product Security

Grow Therapy

Southwestern Ontario

Hybrid

CAD 252,000 - 399,000

Full time

13 days ago
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Benefits offered by this job

Health Benefits
Grow for Grow: therapy access for US
Financial Wellness & equity
Flexible time off & holidays
Parental Leave & child stipend
Mental Health time for self care
Wellness stipend & development
Commuter Benefits
Home Office & meals support
Global travel assistance

Job summary

Grow Therapy is seeking a seasoned Security Engineer to embed secure by default practices across our product stack. You will automate security tasks, dive into codebases, and shape the security roadmap with cross‑functional teams.

You will work with product, engineering, and DevOps to ship secure software without slowing teams, prioritizing real risk and building scalable defenses for a fast‑growing platform.

Qualifications

  • 6+ years of experience in application or product security.
  • Ability to automate tedious security work and build frameworks or services.
  • Hands-on with microservice architectures.
  • Collaborates well within a security team and across the wider engineering org.
  • Prioritizes based on real risk, not just vulnerability counts.
  • Deep understanding of a codebase beyond tooling outputs (SAST/DAST/SBOM).
  • Works with product managers and service teams, not just engineers.

Responsibilities

  • Champion a secure by default culture across frameworks and processes.
  • Develop security requirements and integrate them into new apps and services.
  • Manually analyze source code to gain real understanding of products.
  • Drive the product security roadmap with product, engineering, and security teams.
  • Partner across product, engineering, DevOps, and services to ship secure software efficiently.
  • Design solutions to mitigate vulnerabilities and research relevant threats.
  • Conduct security risk assessments, penetration testing, and threat modeling; translate findings into education.

Skills

Security experience
Automation
Microservices
Cross‑functional collaboration
Risk prioritization
Codebase comprehension
Product-minded

Tools

SAST tooling
DAST tooling
SBOM tooling

Job description

Grow was born to tackle a critical challenge: making mental health care more effective and accessible for everyone. Since launching in 2020, 15 million sessions have started on Grow, and we've barely scratched the surface. We do it through a three-sided marketplace that empowers providers, augments insurance payors, and serves patients. Every solution we build reveals ten more waiting to be delivered, and that's just what gets us going. We've backed that ambition with more than $328M in funding, including our Series D at a $3B valuation from Sequoia Capital, Transformation Capital, TCV, SignalFire, Menlo Ventures, Goldman Sachs Alternatives, and others.

At Grow, the work you do can literally change someone's life. Your work here doesn't stay on a screen; it impacts whether someone can find, afford, and access quality care. That ambition sets us apart, and offers you an endless runway to impact one of the world's most urgent issues. We don’t have passenger seats here. Everyone is driving something that matters.

This work deserves real commitment. So if you thrive on meeting problems head on, untangling serious complexity, and working at pace with the sharpest yet kindest people around, you've come to the right place.

The Opportunity

You'll make the secure path - the easy path for our engineering org of roughly 145 engineers, baking secure defaults, CI guardrails, and threat modeling into the SDLC so security ships with the product instead of blocking it, including for our fast growing AI and agent features.

What You'll Be Doing
  • Champion a secure by default culture, building defense in depth into our frameworks, architecture, and everyday processes
  • Develop security requirements and work directly with teams to build them into new applications and services
  • Manually dig into our source code to build a real, working understanding of our products, not just a surface level view from tooling output
  • Drive the product security roadmap in collaboration with product, engineering, and the wider security team
  • Partner across product, engineering, DevOps, and services to ship secure software without slowing teams down
  • Design solutions that resolve and mitigate vulnerabilities and risk, and research the threats and attack methods most relevant to Grow
  • Run security risk assessments, hands on penetration testing, and threat modeling, and turn those findings into secure coding education for engineers
You’ll Be a Good Fit If
  • You have 6+ years of experience in application or product security
  • You code well enough to automate tedious work and build frameworks or services that solve real security problems
  • You've been hands on with microservice architectures
  • You collaborate well, both within a security team and across the wider engineering org
  • You prioritize based on real risk, not just raw vulnerability counts
  • You've rolled up your sleeves and built a deep understanding of a codebase, rather than just talking about SAST, DAST, and SBOM tooling from the outside
  • You work well with product managers and service teams, not just engineers, and you genuinely care about the product and how it actually functions

Employment Type: Full Time, Exempt

Base Compensation: The base compensation range for this position is:

  • Hybrid Commitment: $217,000–$288,000 USD Annually
  • Fully Remote Commitment: $182,000- $240,000 USD Annually

This role can be hybrid (onsite from our NYC, San Francisco, or Seattle hub location three days per week: Tuesday, Wednesday, Thursday) or fully remote. Both arrangements include travel 2–3 times per year (e.g., company and department offsites).

The base compensation for this role will vary depending on several factors, including relevant experience, qualifications, and the candidate’s working location.

Full Time Employee Benefits
  • Health Benefits: Comprehensive medical, dental, vision, life, and disability coverage.
  • Grow for Grow: No cost access to therapy through the Grow platform (available to US employees)
  • Financial Wellness: Retirement savings programs and equity opportunities to help you invest in your future.
  • Flexible Time Off, Paid Holidays & Winter Break: Flexible time off, company paid holidays (which vary by country), and a full company wide Winter Break to rest and recharge
  • Parental Leave: Up to 18 weeks of paid parental leave to support you and your growing family and a new child stipend.
  • Mental Health Mornings/Afternoons: Dedicated weekly flexible time for self care, whether that's therapy, exercise, journaling, time with family, or simply taking a break.
  • Wellness & Development Stipend: Annual stipend to support your personal wellbeing and professional growth, from fitness and education to books and learning resources.
  • Commuter Benefits: Pre tax commuter benefits to support teammates working from one of our hub locations.
  • Home Office & Meals: Support for your home workspace plus meal benefits, with offerings tailored to both remote and hub based employees.
  • Additional Perks: A variety of wellbeing benefits, including wellness memberships, virtual care, pet insurance discounts (where available), and global travel assistance.

Research shows that some groups hesitate to apply unless they meet every qualification. If you’re excited about this role but don’t check every box, we encourage you to apply. At Grow, we value diverse experiences, transferable skills, and the unique strengths each person brings.

Grow Therapy is proud to be an equal opportunity workplace and is an affirmative action employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements.

Use of AI Tools: We use certain AI and automated tools to support recruitment. These tools help our team review applications, organize interviews, detect potential application integrity issues, and maintain interview records; they do not make final hiring decisions.

Application Review: Ashby's AI-Assisted Application Review helps review application materials against role-specific criteria and may flag potential fraud or integrity issues for recruiter review. All advancement decisions are made by our human recruiting team after independent review. See Ashby's AI Bias Audit Report.

Interview Recording: We use BrightHire to record interviews, supporting note-taking and consistency across candidates. Learn more. Interviews are confidential; you may ask your interviewer to stop recording anytime, or opt out in advance. Choosing not to be recorded will not, by itself, affect your candidacy.

AI-Assisted Recruiter Screen: For select roles, BrightHire's AI features may help structure initial recruiter screens and organize interview notes. All responses are reviewed by our recruiting team; no hiring decisions are made by AI alone.

State-specific notices: Depending on your location, you may have additional rights. Illinois: If AI analyzes a video interview, we'll provide notice, explain how it works and what it evaluates, and obtain consent beforehand. New York City: Where required, we’ll provide at least 10 business days’ notice before using an automated employment decision tool and explain how to request an alternative process. Maryland: We do not use facial recognition to create facial templates during interviews unless required notice and written consent are obtained.

Questions, accommodation requests, requests for an alternative selection process, objections to recording, or concerns about AI use? Contact talentops@growtherapy.com. We’re happy to help or offer an alternative way to participate.

Compensation Range: $182K - $288K

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Client Delivery Director
Client Delivery Director

BetterUp • Toronto

On-site
CAD 178,000 - 222,000
Access to BetterUp coaching
Medical, dental, and vision insurance
Flexible paid time off
+3
Senior Full Stack Developer
Senior Full Stack Developer

Practice Better • Toronto

Hybrid
CAD 150,000 - 160,000
Health benefits
RRSP matching
Learning stipend
+1
Software Engineer
Software Engineer

FutureFit • Canada

On-site
USD 150,000 - 185,000
Senior Manager, Product Security Engineering (Security Posture and Supply Chain)
Senior Manager, Product Security Engineering (Security Posture and Supply Chain)

Talanto • Canada

Hybrid
CAD 233,000 - 340,000
Equity Compensation & Employee Stock(P
Growth and Development Fund
Parental Leave
+2
Senior Application Security Engineer
Senior Application Security Engineer

JobCubby • Quebec

Hybrid
CAD 231,000 - 319,000
Competitive compensation
401(k) with company match
Employee stock purchase plan (ESPP)
+2
Senior Security Engineer
Senior Security Engineer

FORMA.AI • Toronto

On-site
CAD 160,000 - 190,000
Senior Security Engineer Toronto, Canada
Senior Security Engineer Toronto, Canada

Forma AI Inc. • Toronto

On-site
CAD 160,000 - 190,000
Stock options (employee equity)
Healthcare coverage
$750 yearly training stipend
+1
Growth Software Developer - GTM
Growth Software Developer - GTM

Botpress • Montreal (administrative region)

On-site
CAD 90,000 - 130,000
4 weeks vacation
Paid sick leave
Parental leave
+5
Growth Manager
Growth Manager

Awesome-Motive-Inc.-1 • Canada

On-site
USD 120,000 - 180,000
Competitive Salary
Health, Dental, Vision Insurance (US)
Work from home
+3
Growth Marketing Manager
Growth Marketing Manager

ExaCare Inc • Toronto

Hybrid
CAD 90,000 - 130,000
Flexible PTO
Medical, dental, and vision coverage
Competitive salary and equity