Senior Application Security Engineer
- Salary
- $150K–$230KUSD per year
- Hiring from
- Canada
- Work type
- Remote
- Posted
- Sep 27, 2026
About the Role
This is a hands-on application security engineering role within a small, high-impact security team at a fast-growing B2B SaaS company serving the life sciences and scientific research space. You will bring an engineering-first mindset, shipping production security fixes yourself rather than filing tickets, and help scale the team's impact through AI-native automation and thoughtful security architecture.
What You'll Do
Contribute production-quality code directly to the application (Node.js/Python), shipping security fixes and hardening features yourself.
Build AI-powered automation to eliminate manual security work, such as PR analysis and vulnerability triage, so the team can focus on higher-leverage architecture work.
Manage a HackerOne bug bounty program end-to-end: evaluate submissions, reproduce issues, and close findings by shipping fixes.
Define secure-by-design patterns and drive security standards across the application architecture, including for AI-integrated product features.
Act as a security reviewer on RFCs and design documents, pairing with engineers to resolve issues at the source.
What We're Looking For
6 or more years of hands-on software development and/or application security experience, with a background in shipping production code.
Proficiency in Node.js and Python with a track record of shipping production-quality security fixes.
Experience owning application-level security implementation at a VC-backed startup with fewer than 1,000 employees.
Experience with Terraform and AWS for infrastructure as code and cloud security.
Experience building or implementing AI-powered security automation to reduce manual security work.
Experience defining secure-by-design patterns for AI-integrated product features.
Active use of AI coding assistants (such as Claude, Copilot, or Codex) in daily workflow.
End-to-end bug bounty program management experience, from submission through remediation.
Cloud security experience (AWS preferred) or GRC/compliance knowledge.
Authorization to work in the US or Canada without visa sponsorship.
Strong CS fundamentals; a degree in Computer Science or a related field is a plus.
Compensation & Benefits
The salary range for this role is $150,000 to $230,000 USD annually. Visa sponsorship is not available.
Location
This role is fully remote. Candidates must be located in Canada or the United States.