about 3 hours ago
Toronto, Canada
Mid Level / Senior
H1B Sponsor
Responsibilities
- Partner with engineers to identify, triage, and remediate security issues in product features and services.
- Participate in security reviews and threat modeling for new features and systems.
- Perform security-focused code reviews and help identify common vulnerabilities.
- Contribute to secure-by-default patterns, libraries, and tooling in our TypeScript-based stack.
- Help implement and operate security tooling (SAST, DAST, dependency scanning, etc.).
- Support vulnerability management workflows, including internal findings and bug bounty reports.
- Assist in investigating security issues and assessing risk and impact.
- Collaborate with platform and infrastructure teams to improve application and cloud security posture.
- Contribute to improving security practices in AWS-based environments.
- Assist in identifying and mitigating risks in AI/LLM-powered features.
- Contribute to security guidance, documentation, and training for engineering teams.
- Help improve how security is integrated into the development lifecycle.
Requirements
- 1–3+ years of experience in product security, application security, or software engineering.
- Experience writing and maintaining code in JavaScript/TypeScript (or similar languages like Python or Ruby).
- Familiarity with common web and API vulnerabilities (e.g., OWASP Top 10).
- Exposure to security testing tools (SAST, DAST, dependency scanning, etc.).
- Experience working in or with cloud environments (AWS or similar).
- Ability to identify common security risks and suggest practical mitigations.
- Understanding of secure coding practices and basic security controls.
- Strong communication skills and ability to work closely with engineering teams.
- Willingness to ask questions, learn quickly, and take ownership of well-scoped problems.
Benefits
- Medical, dental, and vision insurance.
- Life, AD&D, and disability insurance.
- Emergency weather support and wellness apps.
- Paid parental leave and paid time off inclusive of holidays and sick time.
- Commuter and parking accounts.
- Lunches in the office and internet/phone stipend.
- One-time WFH office set-up stipend.
- 401(k) retirement plan and financial planning.
- Learning and development budget.
Tech Stack
AWSGraphQLJavaScriptKubernetesNestJSNext.jsPythonRubyTypeScript
Categories
AI & MLSecurity
