Search Remote Jobs

Staff Application Security Specialist

🕒 April 22

đŸ—ŁïžđŸ‡«đŸ‡· French Required

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of Workleap

Workleap

201 - 500 employees

đŸ‘„ HR Tech

☁ SaaS

⚡ Productivity

💰 Private Equity Round on 2023-06

HR Tech ‱ SaaS ‱ Productivity

Workleap is a company that provides an integrated platform designed to improve the employee experience by focusing on engagement, performance, and development. Their suite of products includes Officevibe, Pingboard, and various Learning Management Systems (LMS) that help businesses tackle challenges like hybrid work, onboarding, professional development, and performance management. Workleap aims to create happier and more productive workplaces by making it easier for HR teams to manage and enhance their HR strategies. With a customer base exceeding 20,000 leaders globally, Workleap offers tools that are easy to implement and integrate with existing HR and productivity systems.

📋 Description

‱ Build the security layer that governs how Workleap writes code and automate it ‱ Implement SAST, DAST, SCA and secret detection in GitHub Actions ‱ Improve the quality of security signals so developers actually remediate findings ‱ Perform threat modeling on architectural changes and new features ‱ Design an agentic security review where agents analyze pull requests and escalate ambiguous cases ‱ Build security guardrails for AI-assisted and agentic development ‱ Automate first-pass security reviews and reserve human judgment for ambiguous cases ‱ Reduce real-world risk from application vulnerabilities ‱ Harden Azure environments and deployment patterns together with the Infrastructure SecOps team ‱ Collaborate with the AI SDLC team and product engineering teams ‱ Own end-to-end deliverables and set appropriate priorities

🎯 Requirements

‱ 5+ years in application security, DevSecOps, or security-focused software development ‱ Strong engineering background ‱ Deep knowledge of web application security, OWASP Top 10 and CWE Top 25 ‱ Proven experience integrating security automation into CI/CD pipelines, preferably GitHub Actions ‱ Experience building and delivering agentic tooling: MCP servers, Claude skills, subagents and custom tools ‱ Expertise in context engineering applied to agent reasoning over a codebase ‱ Understanding of prompt injection, permission scoping, credential management, and the risks of agents with write access to the repository ‱ Proficiency in Python for building tooling ‱ Hands-on experience with AI-assisted and agentic development workflows ‱ Solid knowledge of Azure services, infrastructure security and deployment patterns ‱ Ability to explain risk trade-offs to engineers and executives ‱ Experience in secure code review for C#/.NET (a plus) ‱ Large-scale integration of SAST, DAST, SCA and secret detection (a plus) ‱ Familiarity with OIDC, SAML and OAuth (a plus) ‱ Exposure to SOC 2 requirements (a plus) ‱ Experience in vulnerability discovery and triage with a developer community (a plus)

đŸ–ïž Benefits

‱ Annual bonus program ‱ Long-Term Incentive Plan (LTIP), participation in Workleap's long-term growth ‱ RRSP ‱ Group health insurance covering families ‱ Telemedicine ‱ Annual wellness budget ‱ Flexible vacation policy ‱ Remote work, with access to Montreal offices ‱ In-person company gatherings twice a year ‱ Claude available to everyone

Apply Now

Similar Jobs

🕒 March 31

Colliers

10,000+ employees

đŸ’Œ Consulting

🏹 Hospitality

📩 Logistics

Global Security Architect at Colliers responsible for defining security solutions across global processes and technology. Leading cloud migrations and security strategies for GCP and Azure environments.

🇹🇩 Canada – Remote

đŸ’” $149.8k - $165k / year

⏰ Full Time

🟠 Senior

🔮 Lead

đŸ‘źâ€â™‚ïž Cybersecurity / Security Engineer