Join Relay as a Senior Application Security Engineer II to enhance security practices across our tech stack.
Posted by employer 1 month ago
First seen on Joblaze 2 hours ago
Last verified on the company career page 2 hours ago
Skills & Technologies
What you'll build
Must have
Nice to have
AI in the day-to-day
Claude Code and Cursor are daily drivers on this team.
Requirements
Not disclosed in this posting: work arrangement, visa sponsorship.
Joblaze summary
The Senior Application Security Engineer II at NorthOne is responsible for ensuring the security of applications throughout their lifecycle, from design to deployment. This role requires expertise in application security, penetration testing, and familiarity with technologies like TypeScript, Node.js, and AWS. Ideal candidates have 5 to 6 years of relevant experience and a strong grasp of security fundamentals, along with a collaborative mindset for mentoring and guiding developers. The position offers opportunities for growth within a team that values autonomy and innovation in security practices.
Joblaze insights
Quick facts
From the original posting
We’re looking for an Senior Application Security Engineer II who thrives on autonomy, curiosity, and impact. You'll join an Application Security team that is deliberately moving away from the advisory model most AppSec functions are stuck in. You’ll work across our stack (from TypeScript and Node.js, to Postgres and AWS cloud infrastructure) ensuring our applications are secure from design to deployment. You’ll blend technical depth with systems thinking, working across teams to identify risks, build guardrails, and evolve our security practices as Relay scales.
Your mission is to own at least one AppSec process end to end, guide developers on how to solve challenging security problems and adapt traditional security solutions to the new AI landscape.
This is a role with room to grow. You'll be working next to senior engineers who are maintaining our auth system and building our DAST tooling from scratch. The Relay AppSec team genuinely enjoys Application Security and is looking to make an impact on the field.
What You'll Be Doing
Threat modeling & offensive testing: Threat model technical design documents (TDDs) and run white-box penetration tests on our testing environment to identify vulnerabilities from an attacker’s point of view.
VDP & bug bounty: Triage researcher reports, reproduce/assess impact, coordinate fixes with owners, and close the loop with clear comms and durable controls.
Shipping the fixes you can: Contributing directly to Relay’s code base when it makes sense — writing the patch, not filing the ticket.
Working in our security tooling and extending it: Datadog security, secrets scanning and logging, Burp Suite, and in-house tools you'll be expected to modify rather than just operate.
Building with AI as a default: Claude Code and Cursor are daily drivers on this team, not a pilot program.
Joining the team's rhythms: Two weekly standups, a biweekly security champions session with product engineers, and a weekly Hack The Box session.
Software supply chain: Enforce provenance: SBOM on every build, dependency pinning/owner verification, private registries/proxies, and runtime SCA detections.
Who You Are
You have 5 to 6 years of professional security experience. Application security, penetration testing, or product security engineering or similar roles.
You've shipped production code: Production-level software real users depended on. And you can read an unfamiliar codebase well enough to fix something in it, which is most of this job.
Security fundamentals: Deep understanding of OWASP Top 10 and real-world exploitation/mitigation techniques.
You build with AI. You use AI tooling in your daily work and you've built something with it. You can talk about where it gets things wrong, not just that it's fast.
Clear communicator & collaborator: You are a collaborator who loves to partner with developers to bring value to customers in the most secure way possible.
Ownership: You have a sense of responsibility towards problems and take ownership over them making sure nothing is forgotten and stakeholders stay informed.
Mentorship: You are comfortable mentoring team members and members of other teams on security best practices.
The Interview Process
Stage 1: A 45-minute Google Meet call with a member of the Talent team
Stage 2: A 60-minute Google Meet video call with the Hiring Manager
Stage 3: A 60-minute Secure Code Review Interview with two members of our appsec team
Stage 4: A take-home case study, followed by a 60-minute Google Meet video call review with two members of the Engineering team
Stage 5: A 45-minute in-person interview with a member of our leadership team
Our Compensation Approach
The annual salary range for this role is $180,000 CAD to $220,000 CAD.
For candidates who demonstrate full readiness for the defined scope of the role, the typical starting salary is $200,000 CAD. Offers below this point reflect candidates we believe can grow into the full scope of the role with support and development. Offers above this point reflect impact that meaningfully exceeds the role’s defined expectations or an expanded scope from day one.
You push relentlessly for reinvention: You're always asking "how can this be better?" -- in your work, in your craft, in yourself. Comfort is a signal to push harder, not coast. You'd rather build something better than defend something familiar.
Standard company text repeated across NorthOne's postings is omitted here.