1

Application Security Engineer Jobs in Ontario (NOW HIRING)

Application Security Engineer (REMOTE)

Ottawa, ON ยท Remote

CA$117K - CA$146K/yr

Job Purpose The Application Security Engineer is responsible for strengthening the security of our applications, platforms, and development processes. This position partners with software engineers ...

Application Security Developer

Toronto, ON ยท Hybrid

CA$119K - CA$161K/yr

We are currently seeking an Application Security Engineer to join our rapidly growing Security team. The Application Security team is responsible for emulating real-world adversaries to proactively ...

Drive application security, product security, and vulnerability management initiatives from concept ... Mentor engineers and security practitioners, raising the bar for secure software development and ...

Drive application security, product security, and vulnerability management initiatives from concept ... Mentor engineers and security practitioners, raising the bar for secure software development and ...

... application security * Direct, hands-on experience securing AI-integrated systems including LLM ... Track record of influencing engineering decisions and behaviour without formal authority over the ...

The Cloud Security Engineer, Cloud Security Engineering will be responsible for providing technical ... Develop tools and scripts required by teams and end users using various cloud and application ...

The Opportunity As a Senior Security Engineer, you will be a hands-on technical leader ... Application, data, and AI security * Run threat modelling and security architecture reviews for new ...

The Cloud Security Engineer, Cloud Security Engineering will be responsible for providing technical ... Develop tools and scripts required by teams and end users using various cloud and application ...

... Application Security Engineer at Indeed, you will play a pivotal role in safeguarding our applications and services from potential threats and vulnerabilities. You will provide technical leadership ...

next page

Showing results 1-20

Application Security Engineer information

See Ontario salary details

$69K

$136.7K

$206.5K

How much do application security engineer jobs pay per year?

As of Aug 25, 2026, the average yearly pay for application security engineer in Ontario is $136,737.00, according to ZipRecruiter salary data. Most workers in this role earn between $113,500.00 and $154,000.00 per year, depending on experience, location, and employer.

What does an application security engineer do?

An application security engineer is responsible for ensuring the secure function of software application programs. For this career, you must have advanced training in cybersecurity and familiarity with multiple computer programming languages. Your main job duty is to evaluate lines of programming code to make sure a given application is safe from cyber-attack. You perform penetration testing to see if outside sources can "hack" into the application. You also do threat modeling and security code reviews of programming done by other application programmers.

What does an application security engineer do?

An Application Security Engineer is responsible for identifying and mitigating security vulnerabilities in software applications throughout their development lifecycle. They work closely with developers to ensure secure coding practices, conduct security assessments and code reviews, and implement tools for threat detection and prevention. Their primary goal is to protect applications from threats such as data breaches, unauthorized access, and other forms of cyber attacks. They also stay updated on the latest security trends and compliance requirements to keep applications safe.

What are the key skills and qualifications needed to thrive as an application security engineer, and why are they important?

To thrive as an Application Security Engineer, you need a solid background in software development, cybersecurity fundamentals, and vulnerability assessment, often supported by a degree in computer science or a related field. Familiarity with tools such as static and dynamic application security testing (SAST/DAST), penetration testing frameworks, and relevant certifications like CISSP or CEH is common. Attention to detail, problem-solving abilities, and strong communication skills help you effectively identify risks and collaborate with development teams. These skills are crucial for safeguarding applications against evolving threats and ensuring secure software delivery.

What are some common challenges faced by application security engineers when integrating security into the software development lifecycle?

Application Security Engineers often encounter challenges such as balancing security requirements with development speed, ensuring all team members understand secure coding practices, and keeping up with evolving threats. They frequently work closely with developers, DevOps, and QA teams to embed security controls without disrupting workflows. Overcoming these challenges requires strong communication skills, a deep understanding of both security and software development, and the ability to advocate for security as a shared responsibility across the organization.

What is the difference between Application Security Engineer vs Security Analyst?

AspectApplication Security EngineerSecurity Analyst
CertificationsCEH, CISSP, OSCPCISSP, Security+
Work EnvironmentDevelops security measures, reviews code, tests applicationsMonitors security systems, investigates incidents, analyzes threats
Industry UsageTech companies, software firms, organizations with strong app focusBroad sectors including finance, healthcare, government

Application Security Engineers focus on securing software applications through code review, vulnerability testing, and implementing security measures. Security Analysts monitor and analyze security threats, respond to incidents, and maintain security systems. While both roles require security certifications and work in security-focused environments, Application Security Engineers are more involved in the development and testing of secure applications, whereas Security Analysts focus on threat detection and incident response.

What are the most commonly searched types of Application Security Engineer jobs in Ontario?

The most popular types of Application Security Engineer jobs in Ontario are:

What are popular job titles related to Application Security Engineer jobs in Ontario?

For Application Security Engineer jobs in Ontario, the most frequently searched job titles are:

What job categories do people searching Application Security Engineer jobs in Ontario look for?

The top searched job categories for Application Security Engineer jobs in Ontario are:

What are popular job titles related to Application Security Engineer jobs in ON?

For Application Security Engineer jobs in ON, the most frequently searched job titles are:

Infographic showing various Application Security Engineer job openings in Ontario as of August 2026, with employment types broken down into 57% Full Time, and 43% Contract. Highlights an 60% In-person, and 40% Hybrid job distribution, with an average salary of $136,737 per year, or $65.7 per hour.

Senior Application Security Engineer

TripleLift

Toronto, ON โ€ข On-site

Full-time

Posted 12 days ago


Job description

Overview

The Senior Application Security Engineer plays a critical role in driving secure software development and application security maturity within TripleLift's Engineering and Security organization, directly influencing how we protect our advertising platforms and the trust our publishers and advertisers place in us. In this position, you will partner closely with Engineering, Platform, Cloud Infrastructure, and Security teams to shape secure coding practices, application security tooling, vulnerability remediation, and CI/CD security, ensuring security is embedded into how we design, build, deploy, and operate our products.This is an exciting opportunity for someone who wants to build and scale an application security program at a company operating at the center of a rapidly evolving, high-stakes ad-tech landscape, while contributing meaningfully to the long-term security posture and resilience of the organization.

Responsibilities
  • Play a critical role in building and maintaining a global security compliance program based on NIST CSF.
  • Scale application security by developing automated security testing utilizing enterprise SAST, DAST, and code-review tools.
  • Champion SDLC to promote secure application development and infrastructure deployment and facilitate secure coding remediation activities.
  • Automate security testing in CI/CD pipelines to detect vulnerabilities early, including building and maintaining the pipeline integrations themselves.
  • Administer and drive adoption of GitHub Advanced Security (GHAS) : code scanning, secret scanning, and dependency review across engineering repositories.
  • Participate in threat modeling and design/architecture spec reviews to identify and mitigate security risks early in the SDLC.
  • Coordinate with stakeholders to develop and implement a vulnerability management program and to perform threat-hunting activities.
  • Own and conduct internal penetration testing and vulnerability assessments of applications and infrastructure, and validate findings from third-party pentest engagements.
  • Monitor and respond to application-layer security threats like API abuses, business logic flaws, and common web vulnerabilities.
  • Collaborate with product and engineering teams to ensure security is a key consideration in software design and architecture.
  • Enhance application security posture by working with cross-functional teams to implement proper authentication, authorization, and data protection mechanisms.
  • Enhance and facilitate security incident handling activities.
  • Evangelize security best practices and provide education and awareness to company employees. Develop and implement secure coding guidelines and conduct secure development training for engineers.
  • Evaluate and continuously improve the maturity of the security program through the deployment and management of various security tools and processes.
Education & Requirements
  • 5 years minimum of experience in application security, secure software development, security engineering, or a similar role.ย 
  • Strong understanding of secure coding practices and ability to guide developers on remediation strategies.
  • Experience with GitHub Advanced Security (GHAS), including Code Scanning (SAST), Secret Scanning, and Dependency Review.
  • Proficiency in SAST, DAST, and SCA tools (e.g., CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode).
  • Hands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning, including designing and building pipeline workflows.
  • Hands-on penetration testing / offensive security experience across web applications, APIs, or cloud infrastructure.
  • Knowledge of common application security vulnerabilities and mitigations (OWASP Top 10, CWE, business logic flaws, API security).
  • Ability to perform threat modeling and participate in design/architecture spec reviews to assess security risks in applications and services.
  • Experience conducting security code reviews across various programming languages (e.g., Python, Java, TypeScript, Go).
  • Understanding of security fundamentals with relation to various cybersecurity and compliance frameworks, particularly NIST CSF, but any of PCI, SOC2, HITRUST, ISO 27001/2, or similar.
  • Strong understanding of AWS security services and controls (IAM, VPC, KMS, GuardDuty, CloudTrail) and experience securing cloud-native environments and workloads, with the ability to deploy security tools within them.
  • Takes ownership of projects, works independently with minimal oversight, and delivers results in a fast-paced environment while balancing multiple priorities.
  • Continuously learns, adapts, and values correctness, efficiency, and constructive feedback.

Preferred:

  • Experience in the ad-tech / programmatic advertising industry, or another high-scale, real-time environment.
  • Preferred: Familiarity with using AI/LLM-based tools (e.g., Claude or similar) for threat intelligence, alert triage, or security automation.
  • Holds a cybersecurity certification, e.g., OSCP, GWAPT, CISSP, CISA, etc.