Senior Application Security Researcher

CommIT

Remote (Canada) Remote Full-time yesterday
Workplace
Remote
Location
Canada
Who can apply
Remote for people based in Canada

Check your CV against this job

Free · No signup · A 0–100 ATS match score and the keywords you're missing.

Check my CV free

$14.99/month, cancel anytime. Already have an account? Log in

About the role

Description

The company secures the AI-driven SDLC from prompt to production, unifying development and cloud context to stop vulnerabilities at the source. The Security Research group is hiring a senior, hands-on Application Security Researcher to push modern AppSec forward — working with engineers, researchers and AI/data scientists on next-generation detection, including autonomous, agentic pen-testing capabilities. This is a build-and-break role, not a typical AppSec position.

Requirements

Must-have skills:

* 5+ years hands-on in offensive security, vulnerability research, or application security * Deep understanding of web application and API vulnerabilities, including business-logic flaws and multi-step attack chains * Strong coding in Python, Go, or similar, with production-quality code shipped * Experience building or tuning detection logic (SAST, DAST, SCA, secrets, or custom rule engines) and reducing false positives * Solid grasp of modern stacks: CI/CD pipelines, containers, Kubernetes, and at least one major cloud provider * Hands-on use of LLMs / AI models for security tasks, with the judgment to measure where they help and where they fail * Comfort with large datasets (SQL, BigQuery, or similar) to drive research and measure detection accuracy * Takes research ideas from prototype to production with minimal guidance * Clear written communication — can explain a complex attack path to engineers and product managers * . in Computer Science, Cyber Security, or a related field

Nice to have:

* Published research, CVEs, conference talks, or a bug bounty track record * Experience building AI agents or evaluation frameworks for LLMs * Background in exploit development, red teaming, or penetration testing * Code analysis techniques (taint analysis, call graphs, reachability) * Contributions to open-source security tools

Originally posted on Himalayas

Get matched & apply with FindAJobAI

Upload your resume once. We score every job against your profile, tailor your resume and cover letter, and autofill the application.