Workleap

Workleap

Workleap provides a comprehensive employee engagement software platform designed to enhance the productivity and collaboration of hybrid teams through tools for talent management, performance management, recognition, and onboarding.

Internet Software & Services
251-1K
$93M raised

Description

  • Embed security into CI/CD pipelines by delivering automated tooling and integrated security checks such as SAST, DAST, SCA, and secret scanning.
  • Design and implement automated, policy-driven security review workflows to support secure-by-default development.
  • Build security guardrails for AI-assisted development and agent workflows while preserving developer velocity.
  • Identify, assess, and drive remediation of application security vulnerabilities.
  • Lead threat modeling and security assessments for new features and architectural changes.
  • Develop automation, tooling, and streamlined processes to improve detection, response, and vulnerability management.
  • Partner with Infrastructure SecOps to harden Azure environments and deployment practices.
  • Contribute to and scale the bug bounty program and vulnerability intake processes.
  • Write code for security tooling, CI/CD configurations, and automated review workflows.
  • Collaborate with engineering teams through architecture discussions, code reviews, pairing, and coaching.

Requirements

  • 8+ years of experience in application security, DevSecOps, or security-focused software development.
  • Strong software engineering background combined with deep security expertise.
  • Deep understanding of web application security principles, OWASP Top 10, and CWE Top 25.
  • Hands-on experience performing secure code reviews in C#.
  • Experience building and maintaining security automation in CI/CD pipelines, with GitHub Actions preferred.
  • Solid understanding of Azure cloud services, infrastructure security, and deployment patterns.
  • Experience integrating SAST, DAST, SCA, and secret scanning tools into development workflows.
  • Proficiency in scripting with Python and Bash for automation and tooling.
  • Extensive hands-on experience with AI-assisted and agentic development workflows, including their security implications.
  • Familiarity with authentication protocols such as OIDC, SAML, and OAuth.
  • Ability to clearly communicate security risks and trade-offs to technical and non-technical stakeholders.

Benefits

  • Salary range of $150–180k CAD.
  • Canada-wide compensation scale with potential regional adjustment based on local market conditions.
  • Remote-friendly role (#LI-Remote).
  • Supportive, collaborative work environment that values trust and mutual support.
  • Opportunity to express yourself, grow, and develop creativity in a flexible environment.
  • Healthy and inclusive work environment.
  • Structured hiring process with Phone Screen, Virtual Interview via Microsoft Teams, Work Sample, and Job Offer.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Manager, Product Research

Huntress 251-1K Professional Services

Huntress is hiring a remote US Product Research Manager to lead cybersecurity research efforts that improve threat detection and prevention for customers.

Cybersecurity
3 days ago

Lead Application Security Engineer

Zeta Global 1K-5K Media

Zeta Global is hiring a Lead Application Security Engineer to strengthen application and platform security across its AI-powered marketing platforms through automated, AI-native security practices and cross-functional security engineering.

AWS Azure Burp Suite CI/CD Cybersecurity DevSecOps Django Docker FastAPI GCP JWT Kubernetes Microservices Node.js OAuth OpenID Connect React SonarQube
3 days, 23 hours ago

Principal Security Architect (Product Security)

Anaplan 1K-5K Internet Software & Services

Anaplan is hiring a Senior Security Architecture IC to define and drive secure-by-design architecture across its enterprise planning platform and AI products.

Encryption Machine Learning OWASP
1 week ago

Principal Security Architect (Product Security)

Anaplan 1K-5K Internet Software & Services

Anaplan is hiring a Senior Security Architect to define and drive secure architecture across its enterprise planning platform, including legacy and AI-enabled products.

Encryption LLM Machine Learning OWASP
1 week ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers