Lead Application Security Engineer at Arctic Wolf scaling AI-first security practices across products and platforms. Involves threat modeling, security standard definition, and risk-reduction programs.
Responsibilities
Lead threat modeling exercises for applications, microservices, APIs, and AI/LLM-enabled systems
Define reusable security patterns and drive secure design reviews for product and platform architectures
Own AppSec initiatives end-to-end and drive risk-reduction programs across R&D
Influence engineering and product leaders to adopt secure practices through clear guidance and rationale
Conduct security assessments for new features, cloud architectures, and AI/GenAI capabilities
Implement and optimize AppSec tooling including SAST, DAST, IAST, SCA, IaC scanning, and container security
Establish metrics, dashboards, and scalable process improvements
Drive R&D wide security practices and help shape internal standards for secure development
Explore emerging technologies, and promote continuous learning within AppSec and the Security Champions community
Requirements
7+ years of experience in Application Security, Product Security, Secure Software Development, or a related security engineering discipline.
Deep expertise in secure design and development principles, including the OWASP Top 10, OWASP ASVS, and modern application security best practices.
Proven experience leading threat modeling exercises, security architecture reviews, and risk assessments for complex applications and services.
Hands-on experience with application security tooling, including SAST, DAST, SCA, IaC, container, and cloud-native security solutions.
Strong analytical and problem-solving skills, with the ability to identify security risks, evaluate tradeoffs, and develop practical, scalable solutions.
Demonstrated ability to influence engineering teams and technology leaders through collaboration, technical expertise, and sound risk-based decision making.
Experience driving the adoption of secure development practices and integrating security into engineering workflows and SDLC processes.
Excellent communication skills with the ability to translate complex technical concepts into actionable guidance for both technical and executive stakeholders.
Proven track record of leading security initiatives, establishing standards, and delivering measurable improvements to an organization's security posture.
Passion for mentoring engineers, fostering a security-first culture, and elevating the security capabilities of development teams.
Benefits
Equity for all employees
Flexible time off and paid volunteer days
RRSP and 401k match
Training and career development programs
Comprehensive private benefits plan including medical, mental health, dental, disability, life and AD&D, and value-added services
Robust Employee Assistance Program (EAP) with mental health services
Regional Health & Safety Manager leading health, safety, and regulatory compliance for GFL’s environmental services operations in Quebec. Conducting audits, incident management, training oversight, and regional site visits.
Information Security Student supporting vulnerability management and cloud security at Nasdaq Verafin. Assisting with remediation, security posture enforcement, and cloud environment protection.
Senior Principal Security Architect shaping enterprise security architecture for Invesco, a global investment - management firm. Leading cloud, identity, network, data - protection, and risk initiatives.
Principal Security Architect securing Menlo Security’s browser and AI - agent protection platform. Leading cryptography, cloud, vulnerability, and product security architecture.
BDC banking manager overseeing commercial loan security and disbursements across Western Canada. Coordinating due diligence, risk evaluation, lending partners and compliant loan funding.
Cybersecurity new graduate rotating through Intact’s 24 - month tech development program. Supporting threat detection, incident response, infrastructure security, and AI - enhanced security insights.