Resume Score

Check how well your resume matches this job before you apply.

Sign in to check score

About the role

  • Senior Application Security Engineer embedding Secure by Design, threat modeling, and AI-assisted vulnerability remediation. Strengthening security for Lightspeed’s global cloud commerce platform serving merchants worldwide.

Responsibilities

  • Serve as a foundational anchor on the AppSec team
  • Lead the strategic shift toward developer-embedded security and Secure by Design operationalization
  • Design, build, and scale AppSec practices
  • Collaborate with Vulnerability Operations to streamline vulnerability triage and remediation
  • Embed security controls into feature designs, pull requests, IaC checks, and daily engineering workflows
  • Architect feature and infrastructure threat models
  • Validate and enhance AI-generated threat modeling pipelines
  • Configure, fine-tune, and orchestrate SAST, DAST, SCA, Secrets, and LLM scanner rulesets
  • Build and stabilize new AppSec processes while maintaining legacy security controls
  • Pioneer AI-driven automation for vulnerability triage and remediation
  • Provide technical fix guidance for structural flaws and web application vulnerabilities
  • Drive developer security enablement and champion the Security Champions program
  • Deliver secure coding workshops
  • Partner with Platform and Infrastructure Security teams to build automated CI/CD guardrails

Requirements

  • Deep, hands-on experience in Application Security, Product Security, or Secure Software Engineering in high-growth cloud environments
  • Bachelor's degree in Computer Science, Cybersecurity, or Software Engineering, or equivalent practical experience
  • Deep understanding of web application vulnerabilities (OWASP Top 10), business logic flaws, and secure coding practices
  • Proven track record tuning SAST, DAST, SCA, Secrets, and LLM scanner pipelines in CI/CD environments
  • Demonstrated experience with threat modeling methodologies, Secure by Design principles, and guiding developers through code remediations
  • Proven experience leveraging AI/LLM tools to automate security analyses, accelerate triage, and optimize developer security workflows
  • Fluency in modern software development languages (e.g., Python, Go, JavaScript/TypeScript, Java)
  • Excellent cross-functional influence and communication skills to effectively lead the Security Champions program
  • Applicants must disclose any criminal convictions
  • Criminal record check required as part of the hiring process
  • Must be legally eligible to work in the country where the role is advertised

Benefits

  • Amazing benefits & perks, including equity for all Lightspeeders
  • Constant development of both your skill-set and business acumen with limitless growth opportunities
  • Lots of autonomy, flexible work culture
  • Innovation time to explore and learn at work
  • Shaping the company by joining cultural & technical committees
  • Tons of growth opportunities into technical or people management roles
  • Lightspeed equity scheme (we are all owners)
  • Flexible paid time off and remote work policies
  • Health insurance
  • Contributions to your pension plan - RRSP
  • Health and wellness benefit of $500 per year
  • Paid leave and assistance for new parents
  • Mental health online platform and counseling & coaching services
  • Training opportunities to grow your skills and career
  • Volunteer day
  • Fully stacked kitchen (hot and cold beverages, meals served)
  • Happy hours to build your relationships with colleagues after work
  • Continuous learning opportunities
  • Global mobility
  • Benefits designed to support you
  • Diverse and inclusive workplace
  • Accommodations available on request for candidates taking part in all aspects of the selection process

Job type

Full Time

Experience level

Senior

Salary

Not specified

Degree requirement

Bachelor's Degree

Tech skills

CloudCyber SecurityJavaJavaScriptPythonTypeScriptGo

Location requirements

RemoteCanada

Report this job

Found something wrong with the page? Please let us know by submitting a report below.