
Application Security Engineer II
Job description
About the role
You will own a defined slice of Relay's platform coverage end to end, driving security testing from design through deployment. You will threat model technical design documents and run white-box penetration tests in our testing environment to uncover attacker paths. You will triage researcher reports through the VDP and bug bounty program, reproducing and assessing impact while coordinating fixes. You will ship fixes yourself when it makes sense, contributing directly to Relay's codebase instead of only filing tickets. You will extend and operate our security tooling, including Datadog security, secrets scanning and logging, Burp Suite, and in-house utilities. You will build with AI as a default, using Claude Code and Cursor daily and being able to explain where these tools get things wrong. You will mentor team members and product engineers on security best practices during dedicated sessions and hands-on workshops. You will collaborate closely with developers to bring clarity, confidence, and control to every dollar earned, turning financial visibility into resilient business outcomes.
Key facts
What you'll do
- Threat model technical design documents and run white-box penetration tests on our testing environment to identify vulnerabilities from an attacker's point of view.
- Triage researcher reports through our VDP and bug bounty program, reproduce and assess impact, and coordinate fixes with service owners.
- Close the loop on findings with clear communications and durable controls that reduce future risk.
- Contribute directly to Relay's codebase by writing patches for issues when it makes sense, shipping the fixes you can implement.
- Extend and operate our security tooling, including Datadog security, secrets scanning and logging, Burp Suite, and in-house tools you will modify rather than only operate.
- Build with AI as a default, using Claude Code and Cursor as daily drivers, and provide feedback on correctness and failure modes.
- Participate in two weekly standups, a biweekly security champions session with product engineers, and a weekly Hack The Box session.
- Enforce software supply chain provenance by ensuring SBOM on every build, dependency pinning and owner verification, private registries/proxies, and runtime SCA detections.
- Collaborate with product and engineering teams to embed security into design reviews, implementation checkpoints, and release gates.
- Drive measurable improvement in coverage and exploitability understanding for the platform, closing gaps that have existed for years.
- Mentor team members and members of other teams on secure coding practices, threat modeling techniques, and exploit mitigation.
- Maintain and evolve our DAST tooling from scratch alongside senior engineers who manage our auth system.
- Translate complex attacker behavior into clear guidance that non-security stakeholders can act on without losing critical nuance.
- Track and prioritize findings based on business risk, ensuring limited engineering capacity is directed at the highest-leverage problems.
Requirements
- You have 2 to 4 years of professional security experience in Application security, penetration testing, or product security engineering or similar roles.
- You have production-level software experience where real users depended on your work, and you can read an unfamiliar codebase well enough to fix something in it.
- You have a deep understanding of OWASP Top 10 and real-world exploitation and mitigation techniques.
- You build with AI and use AI tooling in your daily work, and you have built something with it while understanding its limitations.
- You are a clear communicator and collaborator who enjoys partnering with developers to deliver secure products.
- You take ownership of problems and ensure stakeholders stay informed throughout the lifecycle of an issue.
- You are comfortable mentoring others and sharing security best practices through pair work and sessions.
- You are legally authorized to work in Canada and require no sponsorship for employment at this time.
Nice to have
- Experience with TypeScript and Node.js in production services.
- Familiarity with Postgres and AWS cloud infrastructure.
- Hands-on work with Burp Suite, Datadog security, secrets scanning, and logging tools.
- Contributions to open source security projects or public disclosure experience.
- Participation in Hack The Box or similar security training environments.
Practical notes
- Hours: Full-time during standard business hours.
- Travel: Not applicable.
- Visa: Sponsorship is not available at this time; you must be authorized to work in Canada without employer support.
- Deadlines: Please submit your application through our portal by the specified closing date listed in the posting.