InternFlow

Greenhouse ·

full-time

Senior Security Engineer - Application Security

Faire · Kitchener-Waterloo, ON; Toronto, ON

About Faire Faire is a technology wholesale platform built on the belief that the future is local. Independent retailers around the globe collectively represent a multi-hundred-billion-dollar wholesale market that has historically been fragmented and offline. At Faire, we're using the power of tech, data, and machine learning to connect this thriving community of entrepreneurs across the globe. Picture your favorite boutique in town — we help them discover the best products from around the world to sell in their stores. With the right tools and insights, we believe that we can level the playing field so businesses can grow and local communities can thrive. We’re looking for smart, resourceful and passionate people to join us as we power the shop local movement. If you believe in community, come join ours. About this role Our Engineering organization owns the software that makes our marketplace work. Our Application Security function is focused on keeping vulnerabilities out of the code and software as it's built and shipped, owning the SDLC from commit to production. We care about good engineering practice and love to write software that is secure, tested, easy to maintain, and can scale to millions of users. We build scalable, reusable frameworks; consult with product teams; listen to the data; and iterate. As a Senior Security Engineer, Application Security, you'll collaborate with us to: Find and fix vulnerabilities in first-party code and third-party dependencies using AI-powered detection, SAST, DAST, SCA, and secret scanning tooling. Build shift-left tooling and CI/CD guardrails that make the secure path the default in the build pipeline. Own offensive security engagements such as penetration tests with external vendors. Evaluate and harden the security of AI-assisted code generation workflows. Own the bug bounty program and the vulnerability management lifecycle end to end, from intake through remediation and closure. Lead threat modeling and secure design reviews for new products and high-risk platform changes, shaping the architecture before the code is written rather than reviewing it after. Conduct security reviews and consultations with product and platform teams and develop secure coding standards and scaling frameworks for recurring vulnerability classes. We're excited about you because you have: Hands-on experience integrating security into the software development lifecycle. Experience driving vulnerability remediation across teams you do not own, with a point of view on how to set severities, hold SLAs, and get things actually closed. Exposure to offensive security, whether that is running a bug bounty program, scoping penetration tests with external vendors, or finding and reporting real vulnerabilities yourself. A passion for coding and solving security problems scalably with code and automation, rather than with process and policy. Comfort writing and reviewing code in OOP languages such as Kotlin, Java, Python, or TypeScript, enough to read an unfamiliar service, judge whether a finding is real, and open the pull request that fixes it. Practical experience with AppSec detection tooling (SAST, DAST, SCA, or secret scanning), including the unglamorous parts: deploying it, tuning the rules, and cutting the false positives so engineers trust the results. A thorough understanding of web application security principles and common vulnerabilities, including OWASP Top 10, with an instinct for the systemic fix behind the individual finding. Experience leading threat models on systems you did not build, and the judgement to know which designs need one and which do not. Experience working in modern cloud computing environments such as AWS or GCP. The ability to explain risk to product engineers in a way that makes them want to fix it, and the credibility to be invited into design discussions rather than added as a gate. Curiosity about the security of AI-assisted development, and interest in figuring out what changes when a meaningful share of the code is machine-generated. Technologies we use and teach: Kotlin, Typescript, Python AppSec tooling - SAST/DAST/SCA/secret scanning AWS, OCI, Terraform, Kubernetes AI tooling - Cursor, Claude Salary Range Canada: the pay range for this role is $160,000 to $220,000 per year. This role will also be eligible for equity and benefits. Actual base pay will be determined based on permissible factors such as transferable skills, work experience, market demands, and primary work location. The base pay range provided is subject to change and may be modified in the future. Faire uses Artificial Intelligence (AI) to screen and select applicants for this position. This job posting is for an existing vacancy. Hybrid Faire employees currently go into the office 3 days per week on Tuesdays, Thursdays, and a third flex day of their choosing (Monday, Wednesday, or Friday). Additionally, hybrid in-office roles will have the flexibility to work remotely up to 4 weeks per ye

RoleSenior Security Engineer - Application Security
CompanyFaire
LocationKitchener-Waterloo, ON; Toronto, ON
Typefull-time
CompensationNot disclosed
Posted2026-09-29
DeadlineRolling

Typical process for this type of role

A general guide — the exact steps for this specific listing may vary; check the original posting for details.

  1. 1ApplicationSubmit your resume through the apply link.
  2. 2ScreeningRecruiter reviews your background against the role.
  3. 3AssessmentA technical test, assignment, or coding round, depending on the role.
  4. 4Interview(s)One or more rounds with the hiring team.
  5. 5OfferOffer letter with compensation and start date.

Before you apply

0/4

Senior Security Engineer - Application Security at Faire: frequently asked questions

What is the salary for this role?
Faire has not stated compensation in the listing. Check the original posting or ask during the application process.
Is the Senior Security Engineer - Application Security position remote, hybrid or onsite?
The listing gives Kitchener-Waterloo, ON; Toronto, ON as the location and does not state a work mode.
What is the application deadline?
Faire has not listed a fixed deadline, so apply early in case the opening is filled.
How do I apply for the Senior Security Engineer - Application Security role?
Use the Apply button on this page. It opens the original listing on boards.greenhouse.io, where you submit your application with the company.

More at Faire

Other jobs at Faire

See all 31 openings at Faire

Explore Related Placements


// similar opportunities

You might also like

Senior Systems Engineer - Application Security

Cloudflare

Hybridfull-time
HybridAny GraduateGreenhouseApplication Security Engineering# Go# Rust# Kubernetes# Salt+6 more

About Us At Cloudflare, we are on a mission to help build a better Internet. Today the company runs one of the world’s largest networks that powers millions of ...

['Hybrid role (2 days in office)', '5+ years professional experience required']

Apply now →

Senior Application Security Engineer

Datadog

Datadog logo
Parisfull-time
Arbeitnow

As a Senior Security Engineer within Application Security at Datadog, you will help secure emerging application architectures where established security pattern...

Apply now →

Senior Security Engineer

Mixpanel

London, UK (Hybrid)full-time
Greenhouse

About Mixpanel Mixpanel is the leading product intelligence and analytics platform, trusted by more than 29,000 companies to help understand how people use the ...

Apply now →

Application Security Engineer

Pokemoncareers

Pokemoncareers logo
Londonfull-time
Arbeitnow

Get to know The Pokémon Company International The Pokémon Company International manages the Pokémon property outside of Asia and is responsible for brand manage...

Apply now →

Application Security Engineer

Legal Counsel - 12 Month FTC At Rightmove Greenhouse

Legal Counsel - 12 Month FTC At Rightmove Greenhouse logo
Londonfull-time
Arbeitnow

Our vision is to give everyone the belief they can make their move. We aim to make moving simpler, by giving everyone the best place to turn to and return to fo...

Apply now →

Senior Security Engineer

Tokyodev

Tokyodev logo
Unspecifiedfull-time
Any GraduateTokyodev

Senior Security Engineer...

0-1 year experience eligible.

Apply now →