Senior Application Security Researcher

🔥 9 minutes ago

🇨🇦 Canada – Remote

⏰ Full Time

đźź  Senior

👮‍♂️ Cybersecurity / Security Engineer

đź‘» Ghost score 22%

infoinfo
Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Commit

Commit

501 - 1000 employees

đź”’ Cybersecurity

Cybersecurity

Commit is a global tech services company founded in 2005, with a presence in Israel, the US, Canada, the UK, and Europe. It specializes in advanced technologies and applications, providing innovative, end-to-end technology solutions, including custom software and IoT platforms. Commit has over 700 multidisciplinary experts who cater to a wide array of companies, from startups to large enterprises, and focuses on areas like Cloud, GenAI, Software, IoT, Big Data, Cybersecurity, and data center migration. Its proprietary Flexible R&D methodology supports clients in transforming their technology visions into high-quality products while reducing costs and improving time-to-market.

đź“‹ Description

• Conduct hands-on application security research to advance modern AppSec • Work with engineers, researchers, and AI/data scientists on next-generation detection • Develop autonomous, agentic penetration-testing capabilities • Build and break security systems rather than perform a typical AppSec role • Take research ideas from prototype through production

🎯 Requirements

• 5+ years hands-on in offensive security, vulnerability research, or application security • Deep understanding of web application and API vulnerabilities, including business-logic flaws and multi-step attack chains • Strong coding in Python, Go, or similar, with production-quality code shipped • Experience building or tuning detection logic (SAST, DAST, SCA, secrets, or custom rule engines) and reducing false positives • Solid grasp of modern stacks: CI/CD pipelines, containers, Kubernetes, and at least one major cloud provider • Hands-on use of LLMs / AI models for security tasks, with the judgment to measure where they help and where they fail • Comfort with large datasets (SQL, BigQuery, or similar) to drive research and measure detection accuracy • Takes research ideas from prototype to production with minimal guidance • Clear written communication — can explain a complex attack path to engineers and product managers • M.Sc. in Computer Science, Cyber Security, or a related field • Published research, CVEs, conference talks, or a bug bounty track record • Experience building AI agents or evaluation frameworks for LLMs • Background in exploit development, red teaming, or penetration testing • Code analysis techniques (taint analysis, call graphs, reachability) • Contributions to open-source security tools

Apply Now

Similar Jobs

đź•’ 3 days ago

Sophos

1001 - 5000

đź’Ľ Consulting

🏥 Healthcare

🏭 Manufacturing

Security Engineer investigating cyber threats and engineering detections for Sophos’s AI-driven cybersecurity platform. Building automation and observable, safe agentic workflows for Internal Detection and Response.

🇨🇦 Canada – Remote

đź’µ $86k - $143k / year

đź’° Post-IPO Equity on 2021-08

⏰ Full Time

🟡 Mid-level

đźź  Senior

👮‍♂️ Cybersecurity / Security Engineer

đź•’ 6 days ago

BeyondTrust

1001 - 5000

đź”’ Cybersecurity

Senior Product Security Engineer building AI-driven SDLC security tooling for BeyondTrust’s identity security SaaS. Automating reviews, integrating CI/CD controls, and supporting product incident response.

đź•’ 6 days ago

Motive

1001 - 5000

📦 Logistics

🏗️ Construction

🍽️ Food & Beverage

Red Team Security Engineer conducting cloud adversary simulations for Motive’s fleet-management platform. Assessing attack paths, validating detection coverage, and driving remediation with engineering teams.

đź•’ September 25

Shakepay

51 - 200

đź’Ľ Consulting

🍽️ Food & Beverage

🛡️ Insurance

Ingénieur sécurité senior protégeant l'infrastructure, les produits et les données clients de Shakepay, plateforme canadienne de services financiers bitcoin. Conception de contrôles, automatisation IA, observabilité et réponse aux incidents.

🗣️🇫🇷 French Required

đź•’ September 25

Shakepay

51 - 200

đź’Ľ Consulting

🍽️ Food & Beverage

🛡️ Insurance

Senior Security Engineer securing Shakepay’s Bitcoin financial platform, infrastructure, and customer data. Applying AI, threat modeling, detection engineering, and incident response across regulated fintech systems.