Workleap

Workleap

Workleap provides a comprehensive employee engagement software platform designed to enhance the productivity and collaboration of hybrid teams through tools for talent management, performance management, recognition, and onboarding.

Internet Software & Services
251-1K
$93M raised

Description

  • Embed security into CI/CD pipelines by delivering automated tooling and integrated security checks such as SAST, DAST, SCA, and secret scanning.
  • Design and implement automated, policy-driven security review workflows to support secure-by-default development.
  • Build security guardrails for AI-assisted development and agent workflows while preserving developer velocity.
  • Identify, assess, and drive remediation of application security vulnerabilities.
  • Lead threat modeling and security assessments for new features and architectural changes.
  • Develop automation, tooling, and streamlined processes to improve detection, response, and vulnerability management.
  • Partner with Infrastructure SecOps to harden Azure environments and deployment practices.
  • Contribute to and scale the bug bounty program and vulnerability intake processes.
  • Write code for security tooling, CI/CD configurations, and automated review workflows.
  • Collaborate with engineering teams through architecture discussions, code reviews, pairing, and coaching.

Requirements

  • 8+ years of experience in application security, DevSecOps, or security-focused software development.
  • Strong software engineering background combined with deep security expertise.
  • Deep understanding of web application security principles, OWASP Top 10, and CWE Top 25.
  • Hands-on experience performing secure code reviews in C#.
  • Experience building and maintaining security automation in CI/CD pipelines, with GitHub Actions preferred.
  • Solid understanding of Azure cloud services, infrastructure security, and deployment patterns.
  • Experience integrating SAST, DAST, SCA, and secret scanning tools into development workflows.
  • Proficiency in scripting with Python and Bash for automation and tooling.
  • Extensive hands-on experience with AI-assisted and agentic development workflows, including their security implications.
  • Familiarity with authentication protocols such as OIDC, SAML, and OAuth.
  • Ability to clearly communicate security risks and trade-offs to technical and non-technical stakeholders.

Benefits

  • Salary range of $150–180k CAD.
  • Canada-wide compensation scale with potential regional adjustment based on local market conditions.
  • Remote-friendly role (#LI-Remote).
  • Supportive, collaborative work environment that values trust and mutual support.
  • Opportunity to express yourself, grow, and develop creativity in a flexible environment.
  • Healthy and inclusive work environment.
  • Structured hiring process with Phone Screen, Virtual Interview via Microsoft Teams, Work Sample, and Job Offer.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Staff Product Certification Manager

PQShield 11-50 Semiconductors & Semiconductor Equipment

PQShield is hiring an Experienced Security Certification Manager/Engineer to lead certification efforts for its RISC-V and post-quantum cryptography security IP platform.

CI/CD GitLab CI HubSpot
1 day, 14 hours ago

Staff Application Security Engineer

Beyond Finance 251-1K Banks

Beyond Finance is hiring a Staff Application Security Engineer to own and advance application security across its product and cloud engineering teams.

AWS CI/CD CloudFormation Go Python React Native Ruby on Rails Secrets Management Terraform
6 days, 14 hours ago

Senior Application Security Engineer

Canopy 51-250 Internet Software & Services

Canopy is hiring a Senior Application Security Engineer to help secure its remote Utah-based SaaS platform for accounting firms, with a focus on hardening infrastructure, applications, observability, and the software supply chain.

AWS CI/CD Kubernetes Network Security SIEM WAF
6 days, 14 hours ago

Senior Security Engineer - Product Security

Ondo Finance 11-50 Diversified Financial Services

Ondo Finance is hiring a Senior Security Engineer for Product Security to secure its tokenized real-world asset platform by partnering with product engineering on threat modeling, secure reviews, and security-by-default delivery.

CI/CD Encryption Go JavaScript OAuth OpenID Connect Penetration Testing Python Rust Terraform TypeScript
1 week, 1 day ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers