Avatar for Faire
Faire
Actively Hiring
The future is local
  • B2B
  • Scale Stage
    Rapidly increasing operations
  • Top Investors
    This company has received a significant amount of investment from top investors
  • +2

Senior Security Engineer, Application Security

  • $160k – $220k CAD
  • |
  • |Full Time
Posted: yesterday• Recruiter recently active
Job Location
Visa Sponsorship

Not Available

RelocationNot Allowed
Hiring contact
Jeff Durante
Employee
Waterloo
image

About the job

About this role

Our Engineering organization owns the software that makes our marketplace work. Our Application Security function is focused on keeping vulnerabilities out of the code and software as it's built and shipped, owning the SDLC from commit to production. We care about good engineering practice and love to write software that is secure, tested, easy to maintain, and can scale to millions of users. We build scalable, reusable frameworks; consult with product teams; listen to the data; and iterate.

As a Senior Security Engineer, Application Security, you'll collaborate with us to:

  • Find and fix vulnerabilities in first-party code and third-party dependencies using AI-powered detection, SAST, DAST, SCA, and secret scanning tooling.
  • Build shift-left tooling and CI/CD guardrails that make the secure path the default in the build pipeline.
  • Own offensive security engagements such as penetration tests with external vendors.
  • Evaluate and harden the security of AI-assisted code generation workflows.
  • Own the bug bounty program and the vulnerability management lifecycle end to end, from intake through remediation and closure.
  • Lead threat modeling and secure design reviews for new products and high-risk platform changes, shaping the architecture before the code is written rather than reviewing it after.
  • Conduct security reviews and consultations with product and platform teams and develop secure coding standards and scaling frameworks for recurring vulnerability classes.

We're excited about you because you have:

  • Hands-on experience integrating security into the software development lifecycle.
  • Experience driving vulnerability remediation across teams you do not own, with a point of view on how to set severities, hold SLAs, and get things actually closed.
  • Exposure to offensive security, whether that is running a bug bounty program, scoping penetration tests with external vendors, or finding and reporting real vulnerabilities yourself.
  • A passion for coding and solving security problems scalably with code and automation, rather than with process and policy.
  • Comfort writing and reviewing code in OOP languages such as Kotlin, Java, Python, or TypeScript, enough to read an unfamiliar service, judge whether a finding is real, and open the pull request that fixes it.
  • Practical experience with AppSec detection tooling (SAST, DAST, SCA, or secret scanning), including the unglamorous parts: deploying it, tuning the rules, and cutting the false positives so engineers trust the results.
  • A thorough understanding of web application security principles and common vulnerabilities, including OWASP Top 10, with an instinct for the systemic fix behind the individual finding.
  • Experience leading threat models on systems you did not build, and the judgement to know which designs need one and which do not.
  • Experience working in modern cloud computing environments such as AWS or GCP.
  • The ability to explain risk to product engineers in a way that makes them want to fix it, and the credibility to be invited into design discussions rather than added as a gate.
  • Curiosity about the security of AI-assisted development, and interest in figuring out what changes when a meaningful share of the code is machine-generated.

Technologies we use and teach:

  • Kotlin, Typescript, Python
  • AppSec tooling - SAST/DAST/SCA/secret scanning
  • AWS, OCI, Terraform, Kubernetes
  • AI tooling - Cursor, Claude

Salary Range

Canada: the pay range for this role is $160,000 to $220,000 per year.

This role will also be eligible for equity and benefits. Actual base pay will be determined based on permissible factors such as transferable skills, work experience, market demands, and primary work location. The base pay range provided is subject to change and may be modified in the future.

Faire uses Artificial Intelligence (AI) to screen and select applicants for this position.

This job posting is for an existing vacancy.

About the company

Faire company logo

Faire

Actively Hiring
The future is local501-1000 Employees
  • B2B
  • Scale Stage
    Rapidly increasing operations
  • Top Investors
    This company has received a significant amount of investment from top investors
  • YC Funded
    Startup funded by Y Combinator
  • Valuation $1B+
    This company has a valuation of $1B or more
Learn more about Faire image

Funding

AMOUNT RAISED
Undisclosed amount
FUNDED OVER
1 round
Round
G
Undisclosed amount
Series G - Nov 2021

Founders

Max Rhodes
Founder
image
Daniele Perito
Founder
image
Marcelo Cortes
CTO • 10 years
Waterloo
image
View the team image

Similar Jobs

Feathery company logo
Feathery
AI-powered data intake for financial services
Sponsor a Pet company logo
Sponsor a Pet
We are a fundraising company for animal non-profits
BrainStation company logo
BrainStation
Digital skills training for the future of work
Crema Social company logo
Crema Social
Fast Growting International Dating through a Social Meal Experiment
PathPilot company logo
PathPilot
Optimizing Career and Learning Journeys at Scale with AI