Senior Application Security Engineer

HelloFresh
Toronto
Workplace: HybridFull timeFunction: CybersecurityExperience: 4-7 yearsSkills: ["Communication","Presentation","Teamwork","Stakeholder management","Problem-solving"]

Senior Application Security Engineer responsible for leading HelloFresh’s Vulnerability Management program. The role performs network/cloud penetration testing, web/mobile assessments, source code reviews, and threat analysis, while developing tools and scripts to improve security posture. You will communicate findings to technical and executive audiences, manage remediation tracking, and contribute to bug bounty and red team activities in a hybrid Canada-based team.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
HelloFresh
HelloFresh
2 months ago

Senior Application Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 7 hours agoStatus: Live

Job Summary

Senior Application Security Engineer responsible for leading HelloFresh’s Vulnerability Management program. The role performs network/cloud penetration testing, web/mobile assessments, source code reviews, and threat analysis, while developing tools and scripts to improve security posture. You will communicate findings to technical and executive audiences, manage remediation tracking, and contribute to bug bounty and red team activities in a hybrid Canada-based team.
Location: Toronto
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity

Key Responsibilities

  • •Perform network/cloud penetration testing, web/mobile application testing, source code reviews, threat analysis, wireless network assessments, and social-engineering assessments
  • •Develop comprehensive reports and presentations for technical and executive audiences
  • •Effectively communicate findings and strategy to client stakeholders including technical staff, executive leadership, and legal counsel
  • •Use formal project management skills to plan, track, and report to close remediation loop
  • •Recognize and safely utilize attacker tools, tactics, and procedures to identify vulnerabilities

Pay and Benefits

Perks:Health InsuranceParental LeavePaid Leave

Key Requirements

  • •4-7 years' experience in offensive security across multiple areas (Network, Wireless, Cloud, Web, Mobile, API, Source Code Review, Red Teaming, Social Engineering)
  • •Proficiency in one modern scripting language (Python or Go)
  • •Relevant application penetration testing certifications (OSWE, GWAPT, or equivalent)
  • •Participation in web hacking challenges, bug bounties, or security testing communities
  • •Development of tools/plugins or exploits to improve testing/analysis and ability to review source code for security flaws
Experience:4-7 yearsCybersecurityOffensive securityPentestWeb securityCloud security
Skills:CommunicationPresentationTeamworkStakeholder managementProblem-solving
Certifications:OSWEGWAPT
Languages:English
Tech Stack:PythonGoPenetration testingCloudNetworkSource code review

Company Brief

HelloFresh
HelloFresh is a meal-kit and food subscription company that delivers fresh ingredients and recipes to consumers, offering convenient home-cooked meals through weekly subscription boxes across multiple international markets.
Industry: FoodTech
Company Size: Enterprise (1,001+ employees)
Revenue: USD 1B+
Growth: Public Company
Valuation: Public Company (Market Cap in USD)
Funding: IPO / Publicly Listed
Headquarters: Berlin, Germany
Founded: 2011
Glassdoor
Glassdoor: 3.6
WebsiteLinkedIn