SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: CAD 160,000 - 220,000 / annual
Faire is a technology wholesale platform connecting independent retailers globally with suppliers and products. The Application Security team owns security throughout the software development lifecycle, from commit to production, ensuring vulnerabilities are prevented and remediated at scale.
As a Senior Security Engineer in Application Security, you will drive security initiatives across Faire's engineering organization. Your responsibilities include:
• Identify and remediate vulnerabilities in first-party code and third-party dependencies using AI-powered detection, SAST, DAST, SCA, and secret scanning tools.
• Design and implement shift-left security tooling and CI/CD guardrails that make secure development the default path in the build pipeline.
• Own offensive security engagements, including scoping and managing penetration tests with external vendors.
• Evaluate and harden security practices around AI-assisted code generation workflows.
• Manage the bug bounty program end-to-end, from vulnerability intake through remediation and closure.
• Lead threat modeling and secure design reviews for new products and high-risk platform changes, influencing architecture before code is written.
• Conduct security reviews and consultations with product and platform teams; develop secure coding standards and frameworks for recurring vulnerability classes.
You bring hands-on experience integrating security into the SDLC, with a track record of driving vulnerability remediation across teams you don't directly manage. You have offensive security exposure (bug bounty programs, penetration testing, or vulnerability research). You're passionate about solving security problems with code and automation rather than process alone.
You're comfortable reading and reviewing code in OOP languages (Kotlin, Java, Python, TypeScript) and can judge whether a security finding is real and contribute fixes. You have practical experience deploying and tuning AppSec detection tools, understand web application security principles and OWASP Top 10, and can lead threat models on unfamiliar systems. You work effectively in modern cloud environments (AWS, GCP) and can explain security risk to engineers in ways that drive action. You're curious about the security implications of AI-assisted development.
Faire uses AI to screen applicants for this role.