Application Security Researcher building autonomous application-security capabilities for OX Security. Researching attack paths, AI models, and detection engines from prototype through production.
Responsibilities
Research vulnerability chaining, business-logic flaws, and complex attack paths across applications and infrastructure
Design and build detection engines and decision-making logic for autonomous security systems
Evaluate AI models for application security use cases, measuring where they perform and where they fall short
Prototype, build, and ship security capabilities into production environments
Analyze large-scale security data to uncover exploitable attack paths and improve detection accuracy
Partner with Product, Engineering, and Data teams to shape the next generation of security features
Help set the team's research direction and own initiatives end to end, from idea to shipped capability
Requirements
M.Sc. in Computer Science, Cyber Security, or a related field
5+ years of hands-on experience in offensive security, vulnerability research, or application security
Deep understanding of web application and API vulnerabilities, including business-logic flaws and multi-step attack chains
Strong coding skills in Python, Go, or a similar language, with experience shipping production-quality code
Experience building or tuning detection logic (SAST, DAST, SCA, secrets, or custom rule engines) and reducing false positives
Solid grasp of modern application and infrastructure stacks: CI/CD pipelines, containers, Kubernetes, and at least one major cloud provider
Hands-on experience using LLMs or AI models for security tasks, and the judgment to measure where they help and where they fail
Comfort working with large datasets (SQL, BigQuery, or similar) to drive research and measure detection accuracy
Ability to take a research idea from prototype to production with minimal guidance
Clear written communication: you can explain a complex attack path to engineers and product managers
Benefits
Comprehensive Health Coverage: Medical, Dental, and Vision plans to keep you and your family healthy.
Managing Norfolk County’s cybersecurity, disaster recovery, incident response, and security projects. Supervising IT security staff and protecting municipal systems, services, and information.
IT Security Officer overseeing information security for Desjardins’ property and casualty insurance sector. Managing risks, vulnerabilities, suppliers, complex projects, and executive security reporting.
Azure SA&A Specialist supporting Government of Canada security assessments, controls, evidence, and testing. PLATO delivers Indigenous - owned software testing and technology services across Canada.
Senior Security Engineer owning identity, IT automation, and cloud security for Maze, a user research platform. Driving vulnerability management, compliance, and secure infrastructure at scale.
Product Security Engineer securing WorkOS developer tools and APIs for enterprise authentication and identity. Leading secure design, offensive testing, tooling, and vulnerability remediation.
Product Security Lead securing Miovision’s intelligent transportation products, cloud services, and connected devices. Leading secure - by - design engineering and product risk management for safer smart transportation networks.