Application Security Engineer II
$140,000–$154,000 year
RemoteCanada
CanadaRemoteFull Time$140,000–$154,000 yearSmall
Full TimeSmall
Job Summary
Conduct white-box penetration tests and threat model technical design documents to identify vulnerabilities across Relay's TypeScript, Node.js, and AWS stack. Triage researcher reports, reproduce exploitable issues, and ship production patches directly to the codebase rather than filing tickets. Extend in-house security tooling for secrets scanning and logging while enforcing software supply chain controls like SBOMs and dependency pinning. Collaborate with product engineers during biweekly security sessions and weekly Hack The Box challenges to evolve guardrails as the platform scales.
Required Qualifications
- 2 to 4 years of professional security experience
- Application security, penetration testing, or product security engineering or similar roles
- Shipped production code
- Deep understanding of OWASP Top 10 and real-world exploitation/mitigation techniques
- You build with AI
- You use AI tooling in your daily work
- You've built something with AI
- You can talk about where it gets things wrong
- You are a collaborator who loves to partner with developers to bring value to customers in the most secure way possible
- You have a sense of responsibility towards problems and take ownership over them making sure nothing is forgotten and stakeholders stay informed
- You are comfortable mentoring team members and members of other teams on security best practices
- Valid background check
- Employment verification through Certn
Desired Qualifications
- Experience with TypeScript and Node.js
- Experience with Postgres
- Experience with AWS cloud infrastructure
- Experience with Threat modeling & offensive testing
- Experience with TDDs (Threat Design Documents)
- Experience with white-box penetration tests
- Experience with VDP & bug bounty
- Experience triaging researcher reports
- Experience reproducing and assessing impact
- Experience coordinating fixes with owners
- Experience with clear comms and durable controls
- Experience contributing directly to Relay's code base
- Experience writing patches
- Experience with Datadog security
- Experience with secrets scanning and logging
- Experience with Burp Suite
- Experience with in-house tools
- Experience modifying tools rather than just operating them
- Experience with Claude Code
- Experience with Cursor
- Experience with software supply chain
- Experience with SBOM on every build
- Experience with dependency pinning/owner verification
- Experience with private registries/proxies
- Experience with runtime SCA detections
- You push relentlessly for reinvention
- You crave autonomy
- You own your work
- You build with AI, not just use it
- You care about impact, not noise
- You're energized by complexity and ambiguity
- You seek out feedback
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.