/roles — ROLE_272

Senior Application Security Engineer

Established science-communication software company whose tools help researchers make professional figures and visuals

The role

COMP
$150K - $230K
EQUITY
Competitive equity
LOCATION
Canada
WORKPLACE
Remote
EXPERIENCE
6 - 10 years
VISA
None
STACK
NodeJS, React, Python, Terraform, AWS, Cloudflare, CI/CD
INDUSTRY
Life Sciences, Security, AI

The company

Widely used, venture-backed software company that helps scientists turn their research into clear, professional visuals, built by a team of scientists, designers, and engineers.

STAGE
growth-stage
FUNDING
$60M+ raised
TEAM
250+ people
FOUNDED
2017
BACKING
backed by Y Combinator

JD — the work

About the role

You would join a small security team with an outsized footprint and bring an engineer's approach to application security. The ideal person has a software development background or has kept coding throughout their career, is fluent in reading code, and would rather write and merge the fix than hand a finding to someone else. Much of the job is replacing repetitive manual checks with AI-native tools, letting the team scale through leverage, inside an engineering organization that moves fast, builds with AI, and serves heavily regulated customers. The role is remote within Canada.

What you'll do

  • Write and merge security patches and hardening changes directly in the Node.js and Python code
  • Build AI-driven automation for PR review and vulnerability triage to remove repetitive security work
  • Run the public bug bounty program end to end: triage reports, reproduce issues, and ship fixes
  • Set secure-by-design patterns and application-wide security standards, including for features that use AI
  • Act as security reviewer on design docs and RFCs, working with engineers to solve problems where they start

What they're looking for

  • 6+ years of experience, grounded in software engineering or steady hands-on coding
  • Fluent code reading and production-quality Node.js or Python
  • Application security depth across secure design, vulnerability triage, and remediation
  • Experience with AWS, Terraform, Cloudflare, and CI/CD pipelines
  • Interest in using AI tooling to automate security work
APPLY FOR THIS ROLE →All open rolesOne application covers up to 3 roles.