SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: CAD 162,000 - 420,000 / annual
Sentry is an application monitoring platform trusted by 200,000+ organizations, helping developers fix errors and performance issues before users notice. The Security Team is responsible for securing Sentry's customers, code, and infrastructure. As a Security Engineer focused on application security, you'll work across application and platform security domains within a small, high-trust team.
You will support and mature Sentry's security review program, including secure code review, architecture review, and threat modeling. You'll help build processes, tooling, and culture that make security a natural part of the development and operations workflow. You'll contribute to mature vulnerability management practices: intake, triage, prioritization, remediation tracking, and support of the bug bounty and responsible disclosure program.
You'll advocate for secure-by-design principles by partnering with engineering and product teams to embed security early in the development lifecycle and integrate security tooling into developer and CI/CD workflows. You'll validate and reproduce application and infrastructure security findings through scanning, manual testing, and supporting penetration testing across Sentry's application, SDKs, and cloud-based platform.
You'll help evaluate and respond to emerging threats relevant to application security, including novel attack surfaces introduced by Sentry's agentic product features and AI-assisted engineering practices. The role requires operating cross-functionally, building relationships, and influencing with technical expertise. You should enjoy automation-first thinking, prefer to drive work end-to-end, and thrive with ownership and autonomy.
Required qualifications: 2+ years of industry experience designing, building, or securing complex applications and cloud systems; degree in Computer Science or related field, or equivalent professional experience; hands-on experience with security reviews, SDLC practices, secure CI/CD, architecture reviews, threat modeling, vulnerability management, or bug bounty programs; comfortable programming in at least one language and able to read code in Python, TypeScript, Go, or Rust; familiarity with distributed cloud technology (AWS, GCP, Azure, Kubernetes, Docker, Terraform) and cloud security concepts; collaborative problem-solving with strong communication skills.