Senior Security Engineer, Application Security

Faire
Waterloo, Toronto
Workplace: HybridFull time160,000 - 220,000 annuallyFunction: CybersecuritySkills: ["Leadership","Cross-team collaboration","Risk communication","Coding","Problem-solving"]

Own application security across the SDLC, from commit to production. You’ll identify and remediate vulnerabilities in first- and third-party code using SAST/DAST/SCA and secret scanning, and build shift-left CI/CD guardrails. Lead offensive security work (including vendor penetration tests and bug bounty operations), harden AI-assisted code generation workflows, and drive threat modeling and secure design reviews with product and platform teams.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
Faire
Faire
1 day ago

Senior Security Engineer, Application Security

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 3 hours agoStatus: Live

Job Summary

Own application security across the SDLC, from commit to production. You’ll identify and remediate vulnerabilities in first- and third-party code using SAST/DAST/SCA and secret scanning, and build shift-left CI/CD guardrails. Lead offensive security work (including vendor penetration tests and bug bounty operations), harden AI-assisted code generation workflows, and drive threat modeling and secure design reviews with product and platform teams.
Location: Waterloo, Toronto
Workplace: Hybrid
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Find and fix vulnerabilities in first-party code and third-party dependencies using AI-powered detection and AppSec tooling.
  • •Build shift-left tooling and CI/CD guardrails to make secure builds the default.
  • •Own offensive security engagements, including penetration tests with external vendors.
  • •Evaluate and harden AI-assisted code generation workflows.
  • •Lead bug bounty and vulnerability management lifecycle end to end, and run threat modeling and secure design reviews for new products and high-risk platform changes.

Pay and Benefits

Salary: 160,000 - 220,000 annually
Perks:Equity

Key Requirements

  • •Hands-on experience integrating security into the software development lifecycle.
  • •Ability to drive vulnerability remediation across teams you don’t own, including setting severities, SLAs, and closing issues.
  • •Exposure to offensive security, such as running bug bounty programs, scoping penetration tests with external vendors, or finding and reporting real vulnerabilities.
  • •Comfort writing and reviewing code in OOP languages such as Kotlin, Java, Python, or TypeScript, including fixing findings via pull requests.
  • •Practical experience with AppSec detection tooling (SAST, DAST, SCA, or secret scanning), including deploying it, tuning rules, and reducing false positives.
Skills:LeadershipCross-team collaborationRisk communicationCodingProblem-solving
Languages:English
Tech Stack:KotlinTypescriptPythonSASTDASTSCASecret scanningAWSOCITerraformKubernetesCursorClaudeOOPOWASP Top 10

Company Brief

Faire
Operates a wholesale marketplace connecting independent retailers with emerging and established brands, providing ordering, logistics, and payment solutions to help small businesses discover and stock unique products.
Industry: Online Marketplaces
Company Size: Enterprise (1,001+ employees)
Growth: Scaleup
Valuation: Unicorn (USD 1B+)
Headquarters: San Francisco, United States
Founded: 2017
WebsiteLinkedIn