Senior Application Security Engineer
- Salary
- $150K–$230KUSD per year
- Hiring from
- Canada
- Work type
- Remote
- Posted
- Sep 30, 2026
About the Role
This is a senior individual contributor role on a small, high-impact security team at a growth-stage SaaS company serving the life sciences and research community. You will bring an engineering-first mindset to application security, shipping production fixes yourself and building AI-powered automation to help the team scale through leverage rather than headcount. The work directly shapes how security is embedded into a fast-moving, AI-integrated product used by scientists worldwide.
What You'll Do
Contribute production-quality code directly to the application (Node.js and Python), shipping security fixes and hardening features rather than filing tickets for others to action.
Build AI-powered automation to eliminate manual security work, such as pull request analysis and vulnerability triage, so the team can focus on higher-leverage architecture decisions.
Manage a bug bounty program end-to-end, from evaluating and reproducing submissions through to closing findings by shipping the fixes yourself.
Define secure-by-design patterns and drive security standards across the application architecture, including for AI-integrated product features.
Act as a security reviewer on RFCs and design documents, pairing with engineers to resolve issues at the source.
What We're Looking For
6 or more years of hands-on software development and/or application security experience.
Proficiency in Node.js and Python with a track record of shipping production-quality security fixes.
Prior application-level security ownership at a VC-backed startup or similar high-growth environment with under 1,000 employees.
Experience with Terraform and AWS for infrastructure as code and cloud security.
Experience building or implementing AI-powered security automation to reduce manual security work.
Experience defining secure-by-design patterns for AI-integrated product features.
Experience managing a bug bounty program from submission through remediation.
Strong CS fundamentals; a background as a traditional software engineer before specializing in security is a strong plus.
GRC or compliance knowledge is a plus.
Must be located in Canada or the United States and authorized to work without visa sponsorship.
Compensation & Benefits
Salary range: $150,000 to $230,000 USD annually. Visa sponsorship is not available for this role.
Location
Fully remote. Open to candidates based in Canada or the United States.