Staff/Lead Application Security Engineer

Beacon Software

Toronto

On-site

CAD 120,000 - 180,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Beacon Software seeks its first dedicated application security engineer to set product security strategy and build the program. You will embed with engineering teams across Beacon and portfolio companies, defining the technical roadmap for product security as the organization grows.

You will own threat modeling, secure design reviews, vulnerability management, and AI security across diverse stacks. This role requires shipping production fixes and mature security tooling to sustain multi‑team

Qualifications

  • Experience securing web and API functions across cloud environments.
  • Ability to set standards across multiple codebases and teams.
  • Track record of shipping production fixes and security tooling.

Responsibilities

  • Lead threat modeling and security architecture reviews for new work.
  • Own product security reviews for acquired codebases and cloud environments.
  • Perform secure code reviews and drive remediation with teams.
  • Assess AI features for security risks across products.
  • Own end‑to‑end vulnerability management and reporting.
  • Build CI/CD security tooling and automation for a multi‑team portfolio.
  • Write secure coding standards and developer training.
  • Serve as security expert during incidents and postmortems.
  • Partner with GRC to provide audit evidence and security reviews.

Skills

Web security
API security
Identity access design
Cryptography
Cloud security
Container security

Tools

SAST
DAST
SCA
Secrets scanning

Job description

The role

You will be Beacon's first dedicated application security engineer. You will set the strategy for product security and start to build the program.

Beacon's application security surface spans both Beacon's own engineering and our portfolio companies' products, each independently built with its own stack and engineering team. You will embed with the teams that own the code, whether at Beacon HQ or within a portfolio company, working inside their design reviews and planning, and own the technical roadmap for product security as Beacon grows.

What Application Security owns

This is the full remit of Application Security at Beacon. It is more than one person can cover at once. As the first member of the team, you will stand up the essentials, prioritize the highest-leverage work first, and build the rest into a roadmap.

  • Secure design and architecture: lead threat modeling and security architecture review for new product work and platform initiatives, and define standards for authentication, authorization, encryption, and tenant isolation.
  • Acquisition assessment: own the product security review of newly acquired codebases and cloud environments, establishing baseline posture, material risk, and the remediation path.
  • Code and security review: perform secure code review, targeting authorization and business logic flaws that automated tooling does not catch. Identify and manage the external partner who runs penetration testing against our products and infrastructure, and drive remediation of what they find.
  • AI security: assess AI features across our products, including agent architectures, model and tool access, delegated credentials, and the data reachable through them.
  • Vulnerability management: own the end-to-end program, including intake, severity, prioritization, remediation SLAs, and reporting, and drive fixes through engineering teams in a way they can sustain.
  • Tooling and automation: own the standard for SAST, DAST, SCA, and secrets scanning, and its integration into CI/CD across the portfolio. Build the automation that lets one person cover a multi-team portfolio, including routine fix PRs, dependency remediation, and findings routing. Own the security of any internal tools you build, including their access to credentials, source code, and production systems.
  • Enablement: write the secure coding standards and training that engineering teams consult before they build.
  • Incident response: serve as the product security expert during incidents, from investigation through remediation and postmortem.
  • Compliance partnership: work with GRC to produce the evidence audit and customer security review require, without letting compliance drive the security roadmap.
What we are looking for
  • Would rather build a system that finds every instance of a bug than fix one at a time.
  • Already uses AI as part of how you work, with real opinions on where it helps and where it doesn't, including judgment on when to build tooling versus buy it.
  • Can set architecture and standards across many codebases, not just review one at a time.
  • Ships production code yourself. You should be able to author a fix, not only specify it.
  • Expert knowledge of web and API security, identity and access design (authentication, authorization, RBAC/ABAC), and applied cryptography.
  • Experience securing applications in cloud environments and containerized workloads.
  • A track record of driving security work to completion in engineering organizations outside your reporting line.
Our Values at Beacon Software
  • Humility: We acknowledge that the path to getting to the right answer involves being wrong along the way. We have strong beliefs which are weakly held. We actively seek new ideas and believe we can learn from anyone at any time.
  • Honesty: We are truth seeking in our approach to business problems. Business is a repeat game and we believe that human relationships generate alpha. We understand that trust is earned over a lifetime and can be lost in an instant.
  • Hunger: We play to win. We hold ourselves to high standards and will not be outworked. We take pride in having a deep sense of responsibility to ourselves, each other, our partners, and our customers. We believe to whom much is given much is expected.
  • Horizon: We seek to build a generational software company. This will take decades. We manage our expectations and those of our partners to take advantage of the 8th wonder of the world - compounding growth.

How We Use AI in Our Hiring Process: To ensure transparency, we want candidates to know that Beacon Software uses Artificial Intelligence and AI-enabled tools to assist with screening, reviewing, organizing and highlighting profiles and applications that match the key requirements for each role.

AI does not make hiring decisions: Every application is reviewed by a member of our team, and all decisions throughout the process are made by humans. We use AI to support efficiency and consistency, not to replace human judgment. We are committed to a fair, thoughtful, and equitable experience for every candidate.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff/Lead Enterprise Security Engineer
Staff/Lead Enterprise Security Engineer

Beacon Software • Toronto

On-site
CAD 140,000 - 180,000
Tech Lead - ToolHound
Tech Lead - ToolHound

Beacon Software • Toronto

On-site
CAD 150,000 - 210,000
Technical Project Manager, Integrations
Technical Project Manager, Integrations

Beacon Software • Toronto

On-site
CAD 110,000 - 160,000
Strategic Finance Director
Strategic Finance Director

Beacon Software • Toronto

On-site
CAD 150,000 - 230,000
Investment Director
Investment Director

Beacon Software • Toronto

On-site
CAD 90,000 - 130,000
Learning directly from seasoned entrepreneurs
Unique work environment blending startup and private equity
Strong development opportunities in tech-driven value creation
Recruiting Operations Lead
Recruiting Operations Lead

Beacon Software • Toronto

On-site
CAD 90,000 - 130,000
Product Manager
Product Manager

Beacon Software • Toronto

On-site
CAD 90,000 - 120,000
Employment Counsel
Employment Counsel

Beacon Software • Toronto

On-site
CAD 120,000 - 190,000
Head of Application Security – Strategy & Secure Coding
Head of Application Security – Strategy & Secure Coding

Beacon Software • Toronto

On-site
CAD 120,000 - 180,000
Deal Origination Associate
Deal Origination Associate

Beacon Software • Toronto

On-site
CAD 70,000 - 90,000
Dedicated mentor
Learning from successful entrepreneurs
Unique work environment combining startup and investment
+1