SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Application Security Engineer II

Relay - Toronto, ON, Canada - In-office - posted 2026-08-11

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: CAD 180,000 - 220,000 / annual

Relay is a digital banking platform designed to help self-made business owners manage their finances with clarity and control. The company is building tools that replace financial guesswork with real visibility, enabling entrepreneurs to run stronger, more resilient businesses. You'll join the Application Security team as a Senior Application Security Engineer II, working with autonomy and impact across Relay's full stack (TypeScript, Node.js, Postgres, AWS). The team is deliberately moving away from a purely advisory model toward hands-on security engineering that ships fixes and builds guardrails. Your core mission is to own a defined slice of the platform end-to-end: threat modeling technical design documents, running white-box penetration tests in the testing environment, identifying vulnerabilities from an attacker's perspective, and fixing what you can directly in the codebase. You'll triage vulnerability disclosure program and bug bounty reports, assess impact, coordinate fixes with owners, and maintain clear communication with researchers. Key responsibilities include: - Threat modeling and offensive testing on services in scope - Vulnerability triage, reproduction, and impact assessment - Contributing directly to Relay's codebase to ship security fixes - Working with security tooling (Datadog, Burp Suite, secrets scanning, in-house tools) - Building with AI as a default (Claude Code, Cursor) - Enforcing software supply chain security (SBOM, dependency pinning, SCA) - Participating in team rhythms: two weekly standups, biweekly security champions sessions, weekly Hack The Box - Mentoring team members and product engineers on security best practices You'll work alongside senior engineers maintaining the auth system and building DAST tooling from scratch. The AppSec team genuinely enjoys application security and is focused on making an impact on the field. Required qualifications: 5–6 years of professional security experience (application security, penetration testing, or product security engineering); proven ability to ship production code and read unfamiliar codebases; deep understanding of OWASP Top 10 and real-world exploitation/mitigation; daily use of AI tooling with hands-on experience building with it; strong communication and collaboration skills; ownership mindset; and comfort mentoring others on security best practices.

Similar roles