← Back to results

Senior Application Security Engineer II

Join Relay as a Senior Application Security Engineer II to enhance security practices across our tech stack.

Location
Toronto, ON, Canada
Compensation
CA$180k–CA$220k/yr
Level
senior
Type
full time

Posted by employer 1 month ago

First seen on Joblaze 2 hours ago

Last verified on the company career page 2 hours ago

Apply at NorthOne → Save job Scanned from northone.com

What you'll build

  • Threat modeling technical design documents
  • Run white-box penetration tests
  • Triage researcher reports
  • Contribute directly to Relay's code base
  • Enforce software supply chain provenance

Must have

  • 5 to 6 years of professional security experience
  • Shipped production code
  • Deep understanding of OWASP Top 10

Nice to have

  • Mentoring team members
  • Experience with AI tooling

AI in the day-to-day

Claude Code and Cursor are daily drivers on this team.

Requirements

Experience
5–6 years

Not disclosed in this posting: work arrangement, visa sponsorship.

Joblaze summary

The Senior Application Security Engineer II at NorthOne is responsible for ensuring the security of applications throughout their lifecycle, from design to deployment. This role requires expertise in application security, penetration testing, and familiarity with technologies like TypeScript, Node.js, and AWS. Ideal candidates have 5 to 6 years of relevant experience and a strong grasp of security fundamentals, along with a collaborative mindset for mentoring and guiding developers. The position offers opportunities for growth within a team that values autonomy and innovation in security practices.

Joblaze insights

  • Listed today — first seen on Joblaze October 5, 2026. Last confirmed on NorthOne's careers page October 5, 2026.
  • Starts above 74% of 19 comparable senior security roles in Canada we track (median $107,391 across 10 companies).

Quick facts

What's the salary range?
NorthOne lists CAD 180,000–CAD 220,000 for this role.
How much experience is required?
5–6 years of relevant experience for this Senior Application Security Engineer II role.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, Burp Suite, Datadog, Node.js, PostgreSQL, TypeScript.
What seniority level is this role?
NorthOne targets senior candidates for this position.
Is this full-time or contract?
Full-time for this Senior Application Security Engineer II role at NorthOne.

From the original posting

We’re looking for an Senior Application Security Engineer II who thrives on autonomy, curiosity, and impact. You'll join an Application Security team that is deliberately moving away from the advisory model most AppSec functions are stuck in. You’ll work across our stack (from TypeScript and Node.js, to Postgres and AWS cloud infrastructure) ensuring our applications are secure from design to deployment. You’ll blend technical depth with systems thinking, working across teams to identify risks, build guardrails, and evolve our security practices as Relay scales.

Your mission is to own at least one AppSec process end to end, guide developers on how to solve challenging security problems and adapt traditional security solutions to the new AI landscape.

This is a role with room to grow. You'll be working next to senior engineers who are maintaining our auth system and building our DAST tooling from scratch. The Relay AppSec team genuinely enjoys Application Security and is looking to make an impact on the field.

What You'll Be Doing

  • Threat modeling & offensive testing: Threat model technical design documents (TDDs) and run white-box penetration tests on our testing environment to identify vulnerabilities from an attacker’s point of view.

  • VDP & bug bounty: Triage researcher reports, reproduce/assess impact, coordinate fixes with owners, and close the loop with clear comms and durable controls.

  • Shipping the fixes you can: Contributing directly to Relay’s code base when it makes sense — writing the patch, not filing the ticket.

  • Working in our security tooling and extending it: Datadog security, secrets scanning and logging, Burp Suite, and in-house tools you'll be expected to modify rather than just operate.

  • Building with AI as a default: Claude Code and Cursor are daily drivers on this team, not a pilot program.

  • Joining the team's rhythms: Two weekly standups, a biweekly security champions session with product engineers, and a weekly Hack The Box session.

  • Software supply chain: Enforce provenance: SBOM on every build, dependency pinning/owner verification, private registries/proxies, and runtime SCA detections.

Who You Are

  • You have 5 to 6 years of professional security experience. Application security, penetration testing, or product security engineering or similar roles.

  • You've shipped production code: Production-level software real users depended on. And you can read an unfamiliar codebase well enough to fix something in it, which is most of this job.

  • Security fundamentals: Deep understanding of OWASP Top 10 and real-world exploitation/mitigation techniques.

  • You build with AI. You use AI tooling in your daily work and you've built something with it. You can talk about where it gets things wrong, not just that it's fast.

  • Clear communicator & collaborator: You are a collaborator who loves to partner with developers to bring value to customers in the most secure way possible.

  • Ownership: You have a sense of responsibility towards problems and take ownership over them making sure nothing is forgotten and stakeholders stay informed.

  • Mentorship: You are comfortable mentoring team members and members of other teams on security best practices.

The Interview Process

  • Stage 1: A 45-minute Google Meet call with a member of the Talent team

  • Stage 2: A 60-minute Google Meet video call with the Hiring Manager

  • Stage 3: A 60-minute Secure Code Review Interview with two members of our appsec team

  • Stage 4: A take-home case study, followed by a 60-minute Google Meet video call review with two members of the Engineering team

  • Stage 5: A 45-minute in-person interview with a member of our leadership team

Our Compensation Approach

The annual salary range for this role is $180,000 CAD to $220,000 CAD.

For candidates who demonstrate full readiness for the defined scope of the role, the typical starting salary is $200,000 CAD. Offers below this point reflect candidates we believe can grow into the full scope of the role with support and development. Offers above this point reflect impact that meaningfully exceeds the role’s defined expectations or an expanded scope from day one.

  • You push relentlessly for reinvention: You're always asking "how can this be better?" -- in your work, in your craft, in yourself. Comfort is a signal to push harder, not coast. You'd rather build something better than defend something familiar.

Standard company text repeated across NorthOne's postings is omitted here.

Similar positions

NorthOne
Security Engineer
NorthOne · Toronto, ON, Canada
NorthOne
Senior Software Engineer II, Multiple Teams
NorthOne · Toronto, ON, Canada
NorthOne
Senior Software Quality Engineer
NorthOne · Toronto, ON, Canada
NorthOne
Senior Data Engineer
NorthOne · Toronto, ON
Apollo
Senior Application Security Engineer
Apollo · Remote, Canada; Remote, United States