Principal Application Security Specialist
$125,000–$160,000 year
On-siteVancouver, British Columbia, Canada
Job Summary
Develop and own the application security testing methodology and standards across web, API, mobile, and AI/LLM domains. Lead complex, novel security assessments and establish the organization-wide triage, escalation, and evidence-quality framework for L1–L3 teams. Drive the integration of automated security controls into CI/CD pipelines, championing a shift-left approach with proactive, risk-based remediation verification and release closure. Serve as the final technical escalation point for application security, manage false positives, and define root-cause analysis standards for systemic defects. Mentor specialists, create training materials, and lead sessions on risks and mitigations for engineering teams. Partner with product and architecture leadership to influence secure design at scale and prioritize security investments.
Required Qualifications
- 8+ years experience across application/product security testing and DevSecOps
- expert knowledge of software security
- Experience with security frameworks (OWASP, MITRE, NIST)
- Experience with testing tools (SAST/DAST/SCA)
- scripting (Python, Java, Bash, PowerShell)
- DevOps/CI-CD tooling (Git, Jenkins, Docker/Kubernetes)
- Solid understanding of secure development and coding practices
- Comfortable working cross-functionally with Security, Dev, and Engineering teams
- Strong communicator, able to translate technical concepts for any audience
- Self-directed, detail-oriented, and a sharp problem-solver
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.