Senior Application Security Engineer II
Job description
About the role
You own the security posture of critical Relay services end to end, driving measurable risk reduction across the platform. You partner closely with product and engineering teams to embed security into delivery workflows rather than treating it as a gatekeeping exercise. You leverage deep offensive and defensive skills to find exploitable issues and then write the code that fixes them directly in the Relay codebase. You bring clarity and rigor to ambiguous problems, translating complex security findings into actionable guidance for non-specialists. You act as a force multiplier by mentoring engineers across the organization on secure design and implementation practices. You continuously evaluate and evolve the security tooling chain to keep pace with the growth and complexity of our systems. You champion a shift-left mindset, ensuring that security is a contributor to velocity instead of a bottleneck.
Key facts
What you'll do
- Conduct threat modeling on technical design documents and run white-box penetration tests in our testing environment to uncover attacker-facing vulnerabilities.
- Triage researcher reports from our vulnerability disclosure channel, reproduce and assess impact, coordinate fixes with service owners, and communicate outcomes clearly.
- Write production-level fixes inside the Relay codebase when appropriate, moving beyond ticket creation to direct code contribution.
- Extend and operate security tooling including Datadog security, secrets scanning and logging, Burp Suite, and in-house instruments to improve coverage and signal quality.
- Use AI coding assistants such as Claude Code and Cursor as daily drivers, building with them, evaluating their output, and understanding their failure modes.
- Participate in team rituals including two weekly standups, a biweekly security champions session with product engineers, and a weekly Hack The Box practice session.
- Enforce software supply chain integrity through SBOM generation on every build, dependency pinning and owner verification, private registries and proxies, and runtime SCA detections.
- Close the loop on security work with durable controls, clear documentation, and timely stakeholder updates to maintain trust and alignment.
- Measure the effectiveness of security activities against coverage and risk metrics, iterating on approach based on observed outcomes.
- Collaborate with platform and infrastructure teams to ensure security controls are consistent, scalable, and aligned with reliability goals.
Requirements
- You have 5 to 6 years of professional security experience in roles such as application security, penetration testing, or product security engineering.
- You have production-level software experience where real users depended on your work, and you can read an unfamiliar codebase well enough to fix something in it.
- You possess a deep understanding of the OWASP Top 10 and real-world exploitation and mitigation techniques across web, API, and cloud environments.
- You build with AI tools in your daily work and have shipped something meaningful using them, while being able to explain their limitations and risks.
- You are a clear and collaborative communicator who enjoys partnering with developers to deliver secure experiences for customers.
- You take ownership of problems end to end, ensuring follow-through and keeping stakeholders informed throughout the lifecycle of security initiatives.
- You are comfortable mentoring engineers both within the AppSec team and across product teams on secure practices and threat modeling approaches.
- You are based in Toronto, Ontario, and able to work full time in this role during standard business hours.
Nice to have
Experience contributing to or maintaining security tooling used in production environments.
Background in fintech, payments, or regulated environments where security and compliance considerations are heightened.
Familiarity with modern DevSecOps pipelines, CI/CD systems, and infrastructure-as-code security checks.
Practical notes
This role is full time based in Toronto, Ontario, during standard business hours.
The annual salary range for this role is $180,000 CAD to $220,000 CAD, with typical starting compensation at $200,000 CAD for fully ready candidates.
Compensation may vary above this range based on demonstrated impact and expanded scope from day one.
The interview process includes a Hiring Manager conversation, a live team session, a secure code review and coaching session, and a leadership conversation.