5 hours ago
Responsibilities
- Find and fix vulnerabilities in first-party code and third-party dependencies using AI-powered detection, SAST, DAST, SCA, and secret scanning.
- Build shift-left tooling and CI/CD guardrails that make secure development the default.
- Own offensive security engagements, including penetration tests with external vendors.
- Evaluate and harden AI-assisted code generation workflows.
- Own the bug bounty program and vulnerability management lifecycle from intake through remediation and closure.
- Lead threat modeling and secure design reviews for new products and high-risk platform changes.
- Conduct security reviews and consultations and develop secure coding standards and scalable frameworks for recurring vulnerabilities.
Requirements
- Hands-on experience integrating security into the software development lifecycle.
- Experience driving vulnerability remediation across teams, including setting severities, managing SLAs, and achieving closure.
- Exposure to offensive security through bug bounty programs, penetration tests, or vulnerability research.
- Strong coding and automation skills for solving security problems at scale.
- Ability to write and review code in OOP languages such as Kotlin, Java, Python, or TypeScript.
- Practical experience deploying, tuning, and reducing false positives in SAST, DAST, SCA, or secret scanning tools.
- Thorough understanding of web application security, OWASP Top 10, and common vulnerabilities.
- Experience leading threat models for systems the candidate did not build.
- Experience with modern cloud environments such as AWS or GCP.
- Ability to explain security risk to product engineers and contribute credibly to design discussions.
- Interest in the security implications of AI-assisted development.
Benefits
- Base pay range of $160,000 to $220,000 per year in Canada.
- Eligible for equity and comprehensive benefits.
- Hybrid schedule with office attendance three days per week on Tuesdays, Thursdays, and one flexible Monday, Wednesday, or Friday.
- Hybrid employees may work remotely for up to four weeks per year.
- Access to enterprise AI tools and opportunities for professional growth.
- Equal employment opportunities and reasonable accommodation throughout the hiring process.
Categories
About Faire
Faire is a wholesale technology platform empowering brands and retailers to strengthen the unique character of local communities.