1

Internship Application Security Engineer Jobs in Toronto, ON

Application Security Developer

Toronto, ON · Hybrid

CA$119K - CA$161K/yr

  • Medical

  • Dental

  • Vision

We are currently seeking an Application Security Engineer to join our rapidly growing Security team. The Application Security team is responsible for emulating real-world adversaries to proactively ...

Staff, Security Engineer

Toronto, ON · Remote

  • Medical

  • Retirement

  • PTO

Drive application security, product security, and vulnerability management initiatives from concept ... Mentor engineers and security practitioners, raising the bar for secure software development and ...

... application security * Direct, hands-on experience securing AI-integrated systems including LLM ... Track record of influencing engineering decisions and behaviour without formal authority over the ...

Position: Security Engineer (Coding Agent Experience) Type: Contract Compensation: $85/hour ... Experience with application security , cloud security , infrastructure security , or vulnerability ...

The Cloud Security Engineer, Cloud Security Engineering will be responsible for providing technical ... Develop tools and scripts required by teams and end users using various cloud and application ...

Cyber Security Engineer I

Toronto, ON · On-site

CA$81K - CA$115K/yr

Mobile application security and Pen testing tools The successful candidate must have demonstrated advanced ability to engineer, design, build, support and document solutions in these areas of ...

Cyber Security Engineer I

Mississauga, ON · On-site

CA$81K - CA$115K/yr

Mobile application security and Pen testing tools The successful candidate must have demonstrated advanced ability to engineer, design, build, support and document solutions in these areas of ...

Senior/Staff Security Engineer

Toronto, ON · Remote

CA$150K - CA$245K/yr

  • Medical

  • Dental

  • Vision

  • Life

  • Retirement

  • PTO

From application security and cloud infrastructure to AI security and automation, you'll have broad ownership and real impact. * Partner directly with engineers. Security is deeply embedded with ...

The Opportunity As a Senior Security Engineer, you will be a hands-on technical leader ... Application, data, and AI security * Run threat modelling and security architecture reviews for new ...

The Cloud Security Engineer, Cloud Security Engineering will be responsible for providing technical ... Develop tools and scripts required by teams and end users using various cloud and application ...

Palpatine Test Job

Toronto, ON · Remote

  • Medical

  • Life

  • PTO

... Application Security Engineer at Indeed, you will play a pivotal role in safeguarding our applications and services from potential threats and vulnerabilities. You will provide technical leadership ...

next page

Showing results 1-20

Internship Application Security Engineer information

What does an internship application security engineer do?

An Internship Application Security Engineer assists in identifying, analyzing, and mitigating security vulnerabilities in software applications. They work alongside experienced security engineers to conduct code reviews, run security tests, and implement best practices for secure software development. Interns may also help with documenting findings, researching new security threats, and educating development teams on security protocols. This role provides hands-on experience in safeguarding applications against common cyber threats while developing technical and analytical skills.

What types of projects and tasks can I expect to work on as an internship application security engineer?

As an Internship Application Security Engineer, you can expect to be involved in a variety of hands-on projects such as conducting vulnerability assessments, assisting with penetration testing, and reviewing source code for security flaws. You may also help develop and implement security best practices within the software development lifecycle, collaborate with software engineers to remediate identified issues, and contribute to security awareness initiatives. This role typically offers exposure to real-world security challenges and provides mentorship from experienced security professionals, helping you build foundational skills for a future career in cybersecurity.

What are the key skills and qualifications needed to thrive as an internship application security engineer, and why are they important?

To thrive as an Internship Application Security Engineer, you need a foundational understanding of application development, cybersecurity principles, and familiarity with programming languages like Python or Java, often supported by coursework or certifications in information security. Experience using tools such as Burp Suite, OWASP ZAP, and static code analyzers is typically required. Strong analytical thinking, attention to detail, and effective communication skills distinguish top candidates in this role. These skills are vital to identify, communicate, and help remediate security vulnerabilities, ensuring robust protection for software applications.
Infographic showing various Internship Application Security Engineer job openings in Toronto, ON as of August 2026, with employment types broken down into 30% Full Time, and 70% Contract. Highlights an 80% In-person, and 20% Remote job distribution.

Senior Application Security Engineer

TripleLift

Toronto, ON • On-site

Full-time

Posted 7 days ago


Job description

Overview

The Senior Application Security Engineer plays a critical role in driving secure software development and application security maturity within TripleLift's Engineering and Security organization, directly influencing how we protect our advertising platforms and the trust our publishers and advertisers place in us. In this position, you will partner closely with Engineering, Platform, Cloud Infrastructure, and Security teams to shape secure coding practices, application security tooling, vulnerability remediation, and CI/CD security, ensuring security is embedded into how we design, build, deploy, and operate our products.This is an exciting opportunity for someone who wants to build and scale an application security program at a company operating at the center of a rapidly evolving, high-stakes ad-tech landscape, while contributing meaningfully to the long-term security posture and resilience of the organization.

Responsibilities
  • Play a critical role in building and maintaining a global security compliance program based on NIST CSF.
  • Scale application security by developing automated security testing utilizing enterprise SAST, DAST, and code-review tools.
  • Champion SDLC to promote secure application development and infrastructure deployment and facilitate secure coding remediation activities.
  • Automate security testing in CI/CD pipelines to detect vulnerabilities early, including building and maintaining the pipeline integrations themselves.
  • Administer and drive adoption of GitHub Advanced Security (GHAS) : code scanning, secret scanning, and dependency review across engineering repositories.
  • Participate in threat modeling and design/architecture spec reviews to identify and mitigate security risks early in the SDLC.
  • Coordinate with stakeholders to develop and implement a vulnerability management program and to perform threat-hunting activities.
  • Own and conduct internal penetration testing and vulnerability assessments of applications and infrastructure, and validate findings from third-party pentest engagements.
  • Monitor and respond to application-layer security threats like API abuses, business logic flaws, and common web vulnerabilities.
  • Collaborate with product and engineering teams to ensure security is a key consideration in software design and architecture.
  • Enhance application security posture by working with cross-functional teams to implement proper authentication, authorization, and data protection mechanisms.
  • Enhance and facilitate security incident handling activities.
  • Evangelize security best practices and provide education and awareness to company employees. Develop and implement secure coding guidelines and conduct secure development training for engineers.
  • Evaluate and continuously improve the maturity of the security program through the deployment and management of various security tools and processes.
Education & Requirements
  • 5 years minimum of experience in application security, secure software development, security engineering, or a similar role. 
  • Strong understanding of secure coding practices and ability to guide developers on remediation strategies.
  • Experience with GitHub Advanced Security (GHAS), including Code Scanning (SAST), Secret Scanning, and Dependency Review.
  • Proficiency in SAST, DAST, and SCA tools (e.g., CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode).
  • Hands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning, including designing and building pipeline workflows.
  • Hands-on penetration testing / offensive security experience across web applications, APIs, or cloud infrastructure.
  • Knowledge of common application security vulnerabilities and mitigations (OWASP Top 10, CWE, business logic flaws, API security).
  • Ability to perform threat modeling and participate in design/architecture spec reviews to assess security risks in applications and services.
  • Experience conducting security code reviews across various programming languages (e.g., Python, Java, TypeScript, Go).
  • Understanding of security fundamentals with relation to various cybersecurity and compliance frameworks, particularly NIST CSF, but any of PCI, SOC2, HITRUST, ISO 27001/2, or similar.
  • Strong understanding of AWS security services and controls (IAM, VPC, KMS, GuardDuty, CloudTrail) and experience securing cloud-native environments and workloads, with the ability to deploy security tools within them.
  • Takes ownership of projects, works independently with minimal oversight, and delivers results in a fast-paced environment while balancing multiple priorities.
  • Continuously learns, adapts, and values correctness, efficiency, and constructive feedback.

Preferred:

  • Experience in the ad-tech / programmatic advertising industry, or another high-scale, real-time environment.
  • Preferred: Familiarity with using AI/LLM-based tools (e.g., Claude or similar) for threat intelligence, alert triage, or security automation.
  • Holds a cybersecurity certification, e.g., OSCP, GWAPT, CISSP, CISA, etc.