Senior Application Security Engineer

BioRender
Canada
Workplace: RemoteFull timeFunction: CybersecuritySkills: ["Collaboration","Problem-solving"]

Join BioRender’s Security team as an engineer-first Application Security Engineer. You’ll contribute production code across the application (Node.js/React/Python) and infrastructure (AWS, Terraform, Cloudflare), define secure-by-design patterns, and own CI/CD security integration (SAST/DAST/SCA/secrets). The role is AI-native—using coding assistants and agentic tooling—while you perform penetration testing, lead threat modeling, and run the end-to-end bug bounty program by shipping fixes.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
BioRender
BioRender
1 month ago

Senior Application Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 18 hours agoStatus: Live

Job Summary

Join BioRender’s Security team as an engineer-first Application Security Engineer. You’ll contribute production code across the application (Node.js/React/Python) and infrastructure (AWS, Terraform, Cloudflare), define secure-by-design patterns, and own CI/CD security integration (SAST/DAST/SCA/secrets). The role is AI-native—using coding assistants and agentic tooling—while you perform penetration testing, lead threat modeling, and run the end-to-end bug bounty program by shipping fixes.
Location: Canada
Workplace: Remote
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Contribute production-quality code to the application (Node.js/React) and infrastructure (Python/Terraform), including shipping fixes and hardening.
  • •Build and maintain security and CI/CD tooling so the secure path is the default.
  • •Define secure-by-design patterns and standards for authentication, authorization, and API security.
  • •Lead threat modeling and turn models into shipped controls; own Secure SDLC and CI/CD security integration (SAST/DAST/SCA/secrets).
  • •Perform penetration testing and code reviews (OWASP), remediate vulnerabilities (SAST/DAST/HackerOne), and run the bug bounty program end to end by shipping fixes.

Key Requirements

  • •Demonstrable software engineering ability with production-quality code contributions (Node.js/React; Python a plus).
  • •Expertise in web application security and secure-coding best practices, including code and findings review.
  • •Experience integrating and maintaining SAST/DAST within CI/CD and working with secure software development life cycles.
  • •Hands-on experience securing cloud workloads on AWS and comfort with infrastructure-as-code (Terraform or equivalent).
  • •Threat-modeling experience and practical knowledge of cryptography, PKI, and TLS.
Skills:CollaborationProblem-solving
Certifications:OSCPOSWEAWS Security Specialty
Tech Stack:Node.jsReactPythonTerraformAWSCloudflareCI/CDSASTDASTSCASecretsOWASPHackerOneTLSPKICryptographyThreat modelingPenetration testingSOC 2

Company Brief

BioRender
Provides an online scientific illustration platform that enables researchers and life science professionals to create publication-quality figures, diagrams, and presentations using a library of scientifically accurate icons and templates.
Industry: SaaS
Company Size: Medium (51 to 250 employees)
Growth: Scaleup
Headquarters: Toronto, Canada
WebsiteLinkedIn