
Application Security Engineer - Assistant Vice President
iCapital
🇨🇦 Canada | 🇺🇸 United States
On-site
Manager or above
2 weeks ago
$100,000 – $130,000
- AppSec
- Threat Modeling
- CI/CD
- SAST
- Python
- triage
- OWASP
- GraphQL
- AI
- Ruby
- Scala
- Equity
- Unlimited time off
- Pension
2 weeks ago
- Support threat modeling and design reviews across a broad and growing service portfolio.
- Support shift-left security initiatives, security in CI/CD, developer guidance, and SAST and SCA remediation workflows.
- Contribute to API security across the organization, assessing API exposure, validating authentication and authorization patterns.
- Write Python automation that scales AppSec capacity: triage tooling, finding pipelines, security context enrichment.
- Work directly with developers to remediate SAST and SCA findings, reduce false positive noise, and build security habits across engineering.
- Hands-on experience across some secure design and threat modeling, API security, offensive security, or SAST/SCA program work
- Real understanding of attack patterns and exploitation techniques
- Familiar with OWASP Top 10 in practice
- API security experience with REST and GraphQL assessment
- Able to build and maintain security automation in Python, tooling that scales AppSec capacity
- Understanding of web application and API security
- Able to operate with autonomy in an environment still building its processes
- Relevant certifications, cloud-native environment experience and exposure to AI/LLM security are a plus
- Experience as a developer or engineer and fluency in Ruby, Python, and Scala are a plus
Application Security Engineer - Assistant Vice President · iCapital