Logo

Senior Application Security Engineer

True Talent Solutions Partners • Remote


No Relocation

Posted: October 2, 2026

Job Description

About the Role

This is a senior individual contributor role on a small, high-impact security team at a fast-growing B2B SaaS company serving the life sciences and pharma space. You will bring an engineering-first mindset to application security, writing and shipping production-quality fixes yourself rather than handing findings off to others. The role carries real scope to shape how security is embedded across a product organization that moves quickly and builds AI-native features.

What You'll Do

  • Contribute production-quality code directly to the application (Node.js and Python), shipping security fixes and hardening features end-to-end.

  • Build AI-powered automation to eliminate manual security work, such as pull request analysis and vulnerability triage, so the team can scale through leverage.

  • Manage a bug bounty program end-to-end, evaluating and reproducing submissions and closing findings by shipping the fixes yourself.

  • Define secure-by-design patterns and drive security standards across the application architecture, including for AI-integrated product features.

  • Review RFCs and design documents as a security stakeholder, pairing with engineers to resolve issues at the source.

What We're Looking For

  • 6 or more years of hands-on software development and/or application security experience.

  • Proficiency in Node.js and Python, with a track record of shipping production-quality security fixes.

  • Experience with Terraform and AWS, covering infrastructure as code and cloud security.

  • Experience defining secure-by-design patterns and driving security standards for AI-integrated product features.

  • Experience building or implementing AI-powered security automation to reduce manual security work.

  • End-to-end bug bounty program management experience (such as HackerOne), from submission through remediation.

  • Authorization to work in the US or Canada without visa sponsorship.

Compensation & Benefits

The compensation range for this role is $150,000 to $230,000 USD annually. Visa sponsorship is not available.

Location

This role is fully remote, open to candidates based in Canada or the United States.

Additional Content

About the Role

This is a senior individual contributor role on a small, high-impact security team at a fast-growing B2B SaaS company serving the life sciences and pharma space. You will bring an engineering-first mindset to application security, writing and shipping production-quality fixes yourself rather than handing findings off to others. The role carries real scope to shape how security is embedded across a product organization that moves quickly and builds AI-native features.

What You'll Do

  • Contribute production-quality code directly to the application (Node.js and Python), shipping security fixes and hardening features end-to-end.

  • Build AI-powered automation to eliminate manual security work, such as pull request analysis and vulnerability triage, so the team can scale through leverage.

  • Manage a bug bounty program end-to-end, evaluating and reproducing submissions and closing findings by shipping the fixes yourself.

  • Define secure-by-design patterns and drive security standards across the application architecture, including for AI-integrated product features.

  • Review RFCs and design documents as a security stakeholder, pairing with engineers to resolve issues at the source.

What We're Looking For

  • 6 or more years of hands-on software development and/or application security experience.

  • Proficiency in Node.js and Python, with a track record of shipping production-quality security fixes.

  • Experience with Terraform and AWS, covering infrastructure as code and cloud security.

  • Experience defining secure-by-design patterns and driving security standards for AI-integrated product features.

  • Experience building or implementing AI-powered security automation to reduce manual security work.

  • End-to-end bug bounty program management experience (such as HackerOne), from submission through remediation.

  • Authorization to work in the US or Canada without visa sponsorship.

Compensation & Benefits

The compensation range for this role is $150,000 to $230,000 USD annually. Visa sponsorship is not available.

Location

This role is fully remote, open to candidates based in Canada or the United States.