1

Application Security Jobs in Toronto, ON (NOW HIRING)

Application Security Developer

Toronto, ON ยท Hybrid

CA$119K - CA$161K/yr

The Application Security team is responsible for emulating real-world adversaries to proactively discover, exploit, and help remediate critical security vulnerabilities across our applications. We ...

Improve the application security function at HelloFresh to harden the apps & services against abuse and nefarious activity * Secure containers, CI/CD pipelines and implement guardrails for the ...

Application Security Analyst

Woodbridge, ON ยท Hybrid

CA$95K - CA$115K/yr

Application Security Analyst Department: Information Technology Location: 6300 Steeles Ave West, Woodbridge Total Potential Compensation: $95,000-$115,000 Position Summary: As an Application Security ...

Develop and deliver security and compliance strategic roadmaps that mature security operations ... Lead application vulnerability assessments and remediation efforts to reduce risk and support ...

Drive application security, product security, and vulnerability management initiatives from concept through implementation. * Own complex security challenges that span multiple teams, balancing ...

next page

Showing results 1-20

Application Security information

See Toronto, ON salary details

$20.5K

$102.6K

$151.7K

How much do application security jobs pay per year?

As of Aug 12, 2026, the average yearly pay for application security in Toronto, ON is $102,614.00, according to ZipRecruiter salary data. Most workers in this role earn between $74,438.00 and $139,810.00 per year, depending on experience, location, and employer.

What is the difference between Application Security vs Security Analyst?

AspectApplication SecuritySecurity Analyst
Primary FocusSecuring software applications and codeMonitoring and analyzing overall security threats
CertificationsCSSLP, CEH, CISSPCISSP, Security+, CEH
Work EnvironmentDevelopment teams, software projectsSecurity operations centers, incident response
Industry UsageTech, finance, healthcareAll industries, including government and corporate

Application Security specialists focus on protecting software applications through secure coding practices, vulnerability assessments, and security testing. Security Analysts monitor security systems, analyze threats, and respond to incidents. While both roles require security certifications and work within the cybersecurity field, Application Security is more development-oriented, whereas Security Analysts focus on threat detection and response.

What are some common challenges faced by professionals working in application security roles?

Application Security professionals often encounter challenges such as keeping up with evolving threats and vulnerabilities, integrating security practices into fast-paced development cycles, and balancing security requirements with user experience and business needs. They also need to foster collaboration between development, operations, and security teams to ensure secure software delivery. Staying current with industry standards and communicating technical risks effectively to non-technical stakeholders are key aspects of the role.

How to become an application security?

To become an application security professional, you should gain a strong understanding of software development, cybersecurity principles, and common vulnerabilities. Earning certifications such as Certified Secure Software Lifecycle Professional (CSSLP) or Offensive Security Certified Professional (OSCP) can enhance your credentials. Practical experience with security tools, secure coding practices, and familiarity with application testing are also important for this role.

What is application security?

Application security refers to the measures and practices taken to protect software applications from security threats and vulnerabilities throughout their lifecycle. This includes identifying, fixing, and preventing security flaws in code, configuration, and design, as well as protecting sensitive data handled by applications. Application security professionals use tools such as code analysis, penetration testing, and security best practices to help ensure applications are safe from attacks like SQL injection, cross-site scripting, and data breaches. The goal is to reduce risks and maintain the integrity, confidentiality, and availability of applications.

What are the key skills and qualifications needed to thrive as an application security professional?

To thrive as an Application Security professional, you need a deep understanding of secure software development, threat modeling, vulnerability assessment, and a background in computer science or cybersecurity. Familiarity with tools such as static and dynamic analysis scanners, penetration testing frameworks, and certifications like CISSP or OSCP is highly valuable. Strong analytical thinking, attention to detail, and effective communication are essential soft skills to collaborate with development teams and articulate risks. These competencies are crucial for proactively identifying and mitigating security vulnerabilities, ensuring robust protection of applications and sensitive data.

What are examples of application security?

Application security involves implementing measures to protect software applications from vulnerabilities and attacks, such as input validation, authentication, authorization, encryption, and secure coding practices. Security professionals often use tools like static and dynamic analysis, penetration testing, and code reviews to identify and fix security issues throughout the development lifecycle.
Infographic showing various Application Security job openings in Toronto, ON as of August 2026, with employment types broken down into 72% Full Time, 24% Part Time, and 4% Contract. Highlights an 92% Physical, 2% Hybrid, and 6% Remote job distribution, with an average salary of $102,614 per year, or $49.3 per hour.

Application Security Developer

Clio

Toronto, ON โ€ข Hybrid

CA$119K - CA$161K/yr

Full-time

Medical, Dental, Vision

Re-posted 5 days ago


Job description

Clio is the global leader in legal AI technology, empowering legal professionals and law firms of every size to work smarter, faster, and more securely.

We are transforming the legal experience for all by bettering the lives of legal professionals while increasing access to justice.

Summary:


What your team does:

We are currently seeking an Application Security Engineer to join our rapidly growing Security team. The Application Security team is responsible for emulating real-world adversaries to proactively discover, exploit, and help remediate critical security vulnerabilities across our applications. We provide a vital adversarial perspective, challenging our defences and partnering with development teams to eliminate flaws before they can be exploited.
This role is for someone who is passionate about building innovative solutions and being exposed to new challenges and technologies while making an impact. This role is available to candidates across Canada (excluding Quebec). If you are local to one of our hubs (Burnaby, Calgary, or Toronto), you will be expected to be in office a minimum of two days per week for our Anchor Days.

A day in the life might look like:
  • Write, review, debug, and implement tools to help developers avoid security flaws;

  • Build partnerships with development teams and advise on security best practices;

  • Contribute to collective developer education by driving security awareness and knowledge amongst the product organization;

  • Provide detailed guidance and support to teams in vulnerability remediation, and develop frameworks, guidelines, and systematic fixes for recurring vulnerabilities;

  • Resolve issues, navigate ambiguity, and maintain positive working relationships with researchers in our Bug Bounty program;

  • Identify and implement tools for automated application scanning, static analysis and related tools;

  • Perform penetration testing, and offensive campaigns against internal assets;

  • Perform reactive incident response and forensics when a security event occurs;

  • Perform proactive research to detect new attack vectors;

  • Elevate and educate our security culture within Clio, contributing to our cultural values;

What you may have:
  • Experience in Application or Product Security, with a focus on offensive security and penetration testing

  • Hands-on expertise identifying and exploiting complex vulnerabilities (e.g., SSRF, Deserialization, logic bypasses)

  • Proven ability to lead and conduct formal threat modeling sessions

  • Strong proficiency in at least one major programming language (e.g., Python, .NET, Ruby, JavaScript)

  • Experience securing applications in modern cloud environments (AWS, Azure, or GCP)

  • Expertise with common application security tools and platforms (e.g., Burp Suite, SAST, SCA)

  • Experience with log aggregation and SIEM technologies

  • Ability to identify malicious behaviour and emerging threats via log analysis

  • Demonstrate a keen interest in improving your craft by using AI

Serious bonus points if you have:
  • Security certifications such as OSCP or OSWE

  • Active participation in the security community (e.g., presenting at conferences, contributing to open-source tools).

  • Experience with Ruby on Rails, Puppet, Kubernetes, Terraform, ELK (Elastic, Logtash and Kibana)

  • Strong AWS security experience on EC2 and managed services

  • Infrastructure security (WAF, ACLs, authentication, device hardening)

What you will find here:

Compensation is one of the main components of Clio's Total Rewards Program. We have developed a series of programs and processes to ensure we are creating fair and competitive pay practices that form the foundation of our human and high-performing culture.

Some highlights of our Total Rewards program include:

  • Competitive, equitable salary with top-tier health benefits, dental, and vision insurance

  • Hybrid work environment, with expectation for local Clions (Vancouver, Calgary, Toronto, Dublin, London, New York City and Sydney) to be in office min. twice per week.

  • Flexible time off policy, with an encouraged 20 days off per year.

  • $2000 annual counseling benefit

  • RRSP matching and RESP contribution

  • Clioversary recognition program with special acknowledgement at 3, 5, 7, and 10 years

The expected salary range for this role is $119,000 to $161,000 CAD. Initial placement within the range is informed by geographic region, experience, and skillset, with room to progress as impact and tenure grow. Final offer amounts will vary based on candidate profile.

Diversity, Inclusion, Belonging and Equity (DIBE) & Accessibility

Our team shows up as their authentic selves, and are united by our mission. We are dedicated todiversity, equity and inclusion. We pride ourselves in building and fostering an environment where our teams feel included, valued, and enabled to do the best work of their careers, wherever they choose to log in from. We believe that different perspectives, skills, backgrounds, and experiences result in higher-performing teams and better innovation. We are committed to equal employment and we encourage candidates from all backgrounds to apply.

Clio provides accessibility accommodations during the recruitment process. Should you require any accommodation, please let us know and we will work with you to meet your needs.

Learn more about our culture atclio.com/careers

We're a Human and High Performing AI company, meaning we use artificial intelligence to improve all of our operations. In recruitment, AI helps us streamline the process for greater efficiency. However, we've built our systems to ensure that a human always reviews AI-generated output, and we never make automated hiring decisions.

Disclaimer: We only communicate with candidates through official @clio.com email addresses.