1 month ago
Remote, Canada +3 moreSenior
Responsibilities
- Write, review, debug, and implement tools that help developers prevent security flaws.
- Partner with development teams on security best practices, threat modeling, vulnerability remediation, and developer education.
- Develop frameworks, guidelines, and systematic fixes for recurring vulnerabilities.
- Identify and implement automated application scanning, static analysis, and related security tools.
- Conduct penetration testing, offensive campaigns, proactive security research, and application vulnerability exploitation.
- Support bug bounty researchers and perform reactive incident response and forensics.
- Analyze logs to identify malicious behavior and emerging threats.
Requirements
- Experience in application or product security with a focus on offensive security and penetration testing.
- Hands-on ability to identify and exploit complex vulnerabilities such as SSRF, deserialization, and logic bypasses.
- Proven ability to lead and conduct formal threat modeling sessions.
- Strong proficiency in at least one major programming language, such as Python, .NET, Ruby, or JavaScript.
- Experience securing applications in AWS, Azure, or GCP environments.
- Expertise with application security tools and platforms such as Burp Suite, SAST, and SCA.
- Experience with log aggregation and SIEM technologies and the ability to identify malicious behavior through log analysis.
- Security certifications such as OSCP or OSWE and active security-community participation are preferred.
- Experience with Ruby on Rails, Puppet, Kubernetes, Terraform, ELK, AWS EC2, managed AWS services, WAFs, ACLs, authentication, and device hardening is preferred.
Benefits
- Competitive salary with health, dental, and vision insurance.
- Hybrid work environment; local employees near specified hubs are expected in the office at least two days per week.
- Flexible time off policy with an encouraged 20 days off per year.
- $2000 annual counseling benefit.
- RRSP matching and RESP contributions.
- Clioversary recognition at 3, 5, 7, and 10 years.
- Role available across Canada excluding Quebec.
Tech Stack
AWSAzureGoogle Cloud PlatformJavaScriptKibanaKubernetesLogstash.NETPuppetPythonRubyRuby on RailsTerraform
