SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: CAD 126,000 - 154,000 / annual
Relay is a digital banking platform serving self-made business owners with financial clarity and cash flow visibility. The Application Security team is moving away from a traditional advisory model toward hands-on, impact-driven security engineering.
As an Application Security Engineer II, you'll own a defined slice of the platform's security testing end-to-end. Your primary mission is closing a critical gap: most of Relay's platform has never been properly tested for vulnerabilities. You'll conduct threat modeling, white-box penetration testing, and offensive security assessments across the full stack (TypeScript, Node.js, Postgres, AWS).
Key responsibilities include:
- Threat modeling technical design documents and running penetration tests in the testing environment
- Triaging vulnerability disclosure program and bug bounty reports, assessing impact, and coordinating fixes
- Contributing directly to the codebase to ship security fixes rather than just filing tickets
- Working with security tooling (Datadog, Burp Suite, secrets scanning, in-house tools) and extending them as needed
- Enforcing software supply chain security: SBOM, dependency pinning, private registries, and runtime SCA
- Participating in team rhythms: twice-weekly standups, biweekly security champions sessions, weekly Hack The Box
- Mentoring team members and product engineers on security best practices
You'll work alongside senior engineers maintaining the auth system and building DAST tooling from scratch. The team uses AI tooling (Claude Code, Cursor) as daily drivers, not pilots.
Required: 2–4 years of professional security experience (application security, penetration testing, or product security); proven ability to ship production code and read unfamiliar codebases; deep OWASP Top 10 knowledge; hands-on experience with AI tooling; strong communication and ownership mindset.