Principal Application Security Specialist

Global Relay

Vancouver (WA)

On-site

USD 88,866 - 113,748

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
Vacation days
Sick days
Parental leave
Bonus
RRSP matching
Meal program

Job summary

Global Relay is hiring a Principal Application Security Specialist in Vancouver. You will set testing strategies, lead complex assessments, and drive secure SDLC practices across CI/CD pipelines and AI/LLM security.

Collaboration with engineering and product leadership is essential to align security with business goals. We seek a senior expert with 8+ years in security testing, strong scripting, and experience with SAST/DAST/SCA, plus solid communication and mentoring abilities.

Qualifications

  • 8+ years in application/security testing and DevSecOps.
  • Experience with security frameworks (OWASP, MITRE, NIST).
  • Proficient in SAST/DAST/SCA tooling and scripting.
  • Familiar with CI/CD tooling and secure SDLC practices.
  • Strong cross-functional collaboration and communication.

Responsibilities

  • Lead testing methodology across web, API, mobile and AI/LLM domains.
  • Own penetration testing and offensive security program directions.
  • Drive secure SDLC and CI/CD pipeline integration.
  • Define remediation standards and validate evidence quality.
  • Mentor security specialists and influence engineering teams.

Skills

Application security testing
DevSecOps leadership
SAST/DAST/SCA tooling
Scripting (Python, Java, Bash, Power)
CI/CD security integration
Threat modelling
Communication & mentoring

Tools

Git
Jenkins
Docker/Kubernetes

Job description

Overview

For over 25 years, Global Relay has set the standard in enterprise information archiving with industry-leading cloud archiving, surveillance, eDiscovery, and analytics solutions. We securely capture and preserve the communications data of the world’s most highly regulated firms, giving them greater visibility and control over their information and ensuring compliance with stringent regulations.

Global Relay is a career-building company. A place for big ideas, new challenges, groundbreaking innovation. It’s a place where you can genuinely make an impact – and be recognized for it.

Global Relay is an equal opportunity employer and values diversity, inclusion, and the contributions of all employees. We recruit candidates from different backgrounds and foster a work environment that encourages employees to collaborate and learn from each other, completely free of barriers.

Your role

The Principal Application Security Specialist is the most senior individual contributor across Global Relay's Software & Application Security function. Combining deep application security testing mastery with DevSecOps leadership, you set the technical direction for how Global Relay tests the security of its applications and for how security is engineered into the software development lifecycle. You lead the most complex and novel assessments, define testing methodology and standards, and drive the integration of automated security controls into CI/CD pipelines. You act as the organization’s authority on application, mobile and AI/LLM security, and partner with engineering, platform and product leadership so that security is built in and aligned with business objectives.

Responsibilities

Testing & methodology leadership

  • Collaborate with the Team Lead, Application & Software Security to develop and own the application security testing methodology and standards across web, API, mobile and AI/LLM domains.
  • Lead the most complex, novel and high-risk security assessments, including original research and the development of new testing techniques and tooling.
  • Own the organization-wide triage, escalation and evidence-quality framework across all security testing and scanning functions and define how L1–L3 teams are trained and measured against it.
  • Support the direction for the penetration testing and offensive security program.
  • Own the most advanced threat modelling for critical and cross-cutting architecture.
  • Serve as the organization's authority and final technical escalation point for application security.

DevSecOps & secure SDLC

  • Drive the integration of security into the SDLC and CI/CD pipelines, championing a proactive, risk-based, “shift-left” approach.
  • Develop the organization-wide standards for remediation verification, retest evidence and release closure, ensuring security gating is consistently and appropriately applied across all release pipelines.
  • Design and deploy an automated security framework for robust tooling and processes, using scripting and open-source solutions.
  • Collaborate with Engineering for the selection, deployment and management of security scanning tools (SAST, DAST, SCA, container) within CI/CD pipelines, integrating them via APIs and plugins using agile delivery methods.
  • Serve as the liaison for DevSecOps standards and provide input into new standards and policies.
  • Review and analyze vulnerability data to identify risk across applications, infrastructure and network, and manage false positives.
  • Set the organization's standards for root-cause analysis and remediation guidance on the most complex or systemic security defects and define how remediation quality is assessed across teams.

Influence, measurement & people

  • Define how testing coverage, quality and effectiveness are measured and drive continuous improvement.
  • Partner with engineering, product and architecture teams to influence secure design at scale and prioritize security investment.
  • Lead security sessions for engineering teams covering risks, report analysis, mitigations and process improvements.
  • Mentor and develop specialists, create documentation and training material, and raise the technical bar across the function.
  • Represent application security in cross-functional and, where appropriate, external forums.
Qualifications
  • 8+ yearsexperience across application/product security testing and DevSecOps, with expert knowledge of software security.
  • Experience with security frameworks (OWASP, MITRE, NIST), testing tools (SAST/DAST/SCA), scripting (Python, Java, Bash, PowerShell), and DevOps/CI-CD tooling (Git, Jenkins, Docker/Kubernetes)
  • Solid understanding of secure development and coding practices
  • Comfortable working cross-functionally with Security, Dev, and Engineering teams
  • Strong communicator, able to translate technical concepts for any audience
  • Self-directed, detail-oriented, and a sharp problem-solver
Compensation

Global Relay describes the pay range in compliance with pay transparency laws. Individual pay rates are determined by evaluating factors such as expertise, skills, education, and professional background.

The range below reflects the expected annual base salary, which is one element of our total rewards package designed to reflect our company pay philosophy, culture and values. We provide a comprehensive extended health benefits program, including virtual healthcare and a wellness allowance. Employees also receive annual vacation days, which increase based on tenure. Other benefits include paid sick days, maternity/parental enhancement program, bonus, and an RRSP contribution matching program. For Vancouver-based employees, a subsidized meal program is provided by our in-house culinary team.

British Columbia - Base salary range

$125,000 — $160,000 CAD

What you can expect

There’s no ceiling to what you can achieve at Global Relay. You’ll be part of a culture that breeds creativity and rewards perseverance and hard work. You’ll work alongside smart, talented individuals from diverse backgrounds, with complementary knowledge and skills.

Global Relay is an equal-opportunity employer committed to diversity, equity, and inclusion. We seek to ensure reasonable adjustments, accommodations, and personal time are tailored to meet the unique needs of every individual.

To learn more about our business, culture, and community involvement, visit www.globalrelay.com

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Director, Cyber Security Operations
Director, Cyber Security Operations

Global Relay • Vancouver (WA)

On-site
USD 127,967 - 156,404
Extended health benefits
Wellness allowance
Vacation days
+3
Senior Application Security Analyst - L3
Senior Application Security Analyst - L3

Global Relay • United States

On-site
USD 120,000 - 190,000
Manager, Client Services - Enterprise
Manager, Client Services - Enterprise

Global Relay • New York (NY)

On-site
USD 100,000 - 140,000
Health benefits program
401(k) plan with company matching
Paid vacation and sick days
Co-op Product Management - Fall 2026
Co-op Product Management - Fall 2026

Global Relay • Vancouver (WA)

On-site
USD 29,859 - 40,096
Senior Solutions Engineer
Senior Solutions Engineer

Global Relay • New York (NY)

On-site
USD 120,000 - 180,000
Subsidized meal program
In-house culinary team
401(k) retirement plan with company-mh
Support Specialist, Technical Support - L1
Support Specialist, Technical Support - L1

Global Relay • Vancouver (WA)

On-site
USD 35,760 - 46,488
Extended health benefits
Annual vacation days
Subsidized meal program
Enterprise Technical Implementation Specialist
Enterprise Technical Implementation Specialist

Global Relay • New York (NY)

On-site
USD 90,000 - 150,000
Health benefits
Disability insurance
401(k) retirement plan with company matching
Senior C# Developer
Senior C# Developer

Global Relay • Vancouver (WA)

On-site
USD 63,000 - 92,000
Comprehensive health benefits
Paid sick days
Maternity/parental enhancement program
+1
Project Manager, Unified Communications
Project Manager, Unified Communications

Global Relay • Vancouver (WA)

On-site
USD 66,000 - 85,000
Comprehensive health benefits
Annual vacation days
Subsidized meal program
Senior Reporter - Technology
Senior Reporter - Technology

Global Relay • San Francisco (CA)

On-site
USD 120,000 - 140,000
Extended health benefits
401k contributions
Commissions