SlipstreamJobsFresh Startup & VC-Backed Jobs

Staff Security Engineer

Jane App - Remote - Remote - posted 2026-09-17

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: CAD 158,400 - 247,500 / annual

Jane App is a high-growth, founder-led SaaS company serving 70,000+ clinics with software for booking, charting, and billing. The Product Security team partners closely with developers to build secure software at scale, viewing security as a collaborative effort rather than a gatekeeping function. You will join as a Staff-level Security Engineer reporting to Megan Stewart, Head of Product Security. This is a hands-on technical role with significant scope and influence across the organization. Key responsibilities: - Identify recurring vulnerability patterns across the codebase and lead architectural fixes with product teams, moving beyond one-off patches to systemic solutions. - Own and lead product security initiatives end-to-end, including private package repositories, SCA tooling maturation, and development lifecycle/GitHub workflow improvements. - Build AI into the team's security practice, advancing from automated reporting to AI-assisted vulnerability analysis and draft fixes that integrate closer to the code. - Champion secure development practices across Jane by building trusted relationships with developers, translating risk into plain language, and helping teams adopt new practices without friction. - Mentor teammates as the team's most senior hands-on engineer and represent Product Security in cross-functional initiatives. You'll work in a remote-first environment with team members across Canada, the US, and the UK. The company is embracing AI broadly and expects all engineers to experiment with and build using AI tools. REQUIREMENTS: - Staff-level application security experience, including owning security initiatives end-to-end and working directly with development teams. - Strong development background. Ruby on Rails is ideal; Python, Java, or C# with willingness to work in a Rails codebase is acceptable. You must be able to read a draft PR and assess whether a fix is correct. - Demonstrated experience identifying systemic vulnerability patterns and driving architectural fixes with engineering teams, not just reporting individual findings. - Strong relationship and communication skills with developers and stakeholders. You make security digestible, can push back kindly, and earn trust. - Hands-on experimentation with AI in security work, ideally building automation rather than one-off use cases. Experience securing AI features in a product is a strong asset. - The company notes: "If you don't meet every single qualification but are excited about this role, we'd still love to hear from you."

Similar roles