yoinka

Application Security Engineer II

NorthOne

RemoteToronto, ONFull TimeMid$126k/yr
Sign in to applyVerified 1h ago
Location
Toronto, ON
Employment
Full Time
Work model
Remote
Level
Mid
Salary
$126k/yr
Posted
1h ago

Skills

AWSCybersecurityDatadogGoJavaScriptNode.jsPostgreSQLTypeScript

About this role

Relay is a digital banking platform that gives self-made business owners the tools and know-how to be great with money—bringing clarity, confidence, and control to every dollar earned, so they can turn hard work into lasting success. We do this by replacing financial guesswork with real visibility, transforming cash flow from a constant source of stress into a clear signal owners can use to run stronger, more resilient businesses. We’re looking for an Application Security Engineer II who thrives on autonomy, curiosity, and impact. You'll join an Application Security team that is deliberately moving away from the advisory model most AppSec functions are stuck in. You’ll work across our stack (from TypeScript and Node.js, to Postgres and AWS cloud infrastructure) ensuring our applications are secure from design to deployment. You’ll blend technical depth with systems thinking, working across teams to identify risks, build guardrails, and evolve our security practices as Relay scales. That coverage number is where you come in. Right now, most of Relay's platform has never been properly tested — and closing that gap is the single highest-leverage thing our team can do this year. Your mission is to own a defined slice of it end to end: testing the services in scope, working out what's actually exploitable, and fixing what you can yourself. This is a role with room to grow. You'll be working next to senior engineers who are maintaining our auth system and building our DAST tooling from scratch. The Relay AppSec team genuinely enjoys Application Security and is looking to make an impact on the field.

What You'll Be Doing

Threat modeling & offensive testing: Threat model technical design documents (TDDs) and run white-box penetration tests on our testing environment to identify vulnerabilities from an attacker’s point of view. VDP & bug bounty: Triage researcher reports, reproduce/assess impact, coordinate fixes with owners, and close the loop with clear comms and durable controls. Shipping the fixes you can: Contributing directly to Relay’s code base when it makes sense — writing the patch, not filing the ticket. Working in our security tooling and extending it : Datadog security, secrets scanning and logging, Burp Suite, and in-house tools you'll be expected to modify rather than just operate. Building with AI as a default : Claude Code and Cursor are daily drivers on this team, not a pilot program. Joining the team's rhythms : Two weekly standups, a biweekly security champions session with product engineers, and a weekly Hack The Box session. Software supply chain: Enforce provenance: SBOM on every build, dependency pinning/owner verification, private registries/proxies, and runtime SCA detections.

Who You Are

You have 2 to 4 years of professional security experience. Application security, penetration testing, or product security engineering or similar roles. You've shipped production code: Production-level software real users depended on. And you can read an unfamiliar codebase well enough to fix something in it, which is most of this job. Security fundamentals: Deep understanding of OWASP Top 10 and real-world exploitation/mitigation techniques. You build with AI. You use AI tooling in your daily work and you've built something with it. You can talk about where it gets things wrong, not just that it's fast. Clear communicator & collaborator: you are a collaborator who loves to partner with developers to bring value to customers in the most secure way possible. Ownership: You have a sense of responsibility towards problems and take ownership over them making sure nothing is forgotten and stakeholders stay informed. Mentorship: You are comfortable mentoring team members and members of other teams on security best practices. The Interview Process Stage 1: A 60-minute Google Meet video call with the Hiring Manager Stage 2: A 60-minute live session with the team Stage 3: A 60-minute Secure Code Review and Coaching

Listing verified 1h ago. Applications go through the company's official careers site.

← Back to Yoinka

Application Security Engineer II at NorthOne, Toronto, ON | Yoinka