1

Senior Application Security Engineer Jobs in Toronto, ON

Position Summary: League is looking for a Principal Security Engineer to serve as the senior ... application security * Direct, hands-on experience securing AI-integrated systems including LLM ...

... senior technical leader and hands-on builder. This role is ideal for someone who started their career in software engineering and developed deep expertise in security engineering, application ...

Application Security Developer

Toronto, ON · Hybrid

CA$119K - CA$161K/yr

We are currently seeking an Application Security Engineer to join our rapidly growing Security team. The Application Security team is responsible for emulating real-world adversaries to proactively ...

The Opportunity As a Senior Security Engineer, you will be a hands-on technical leader ... Application, data, and AI security * Run threat modelling and security architecture reviews for new ...

We're looking for a Senior Cloud Security Engineer II to join our Security Engineering function as a senior individual contributor and technical leader for cloud security. This is a step up from our ...

The Cloud Security Engineer, Cloud Security Engineering will be responsible for providing technical ... Develop tools and scripts required by teams and end users using various cloud and application ...

Sr. Application Developer Information Technology, F&O Department Canada Shape the data architecture behind one of the world's fastest-growing healthcare companies - and see your solutions drive real ...

New

next page

Showing results 1-20

Senior Application Security Engineer information

See Toronto, ON salary details

$95.4K

$143.7K

$205.7K

How much do senior application security engineer jobs pay per year?

As of Aug 30, 2026, the average yearly pay for senior application security engineer in Toronto, ON is $143,705.00, according to ZipRecruiter salary data. Most workers in this role earn between $123,587.00 and $158,897.00 per year, depending on experience, location, and employer.

What is a senior application security engineer?

A Senior Application Security Engineer is responsible for ensuring the security of software applications by identifying vulnerabilities, implementing security best practices, and working with development teams to integrate secure coding principles. They conduct security assessments, perform threat modeling, and use security tools to detect and remediate risks. Additionally, they help establish security policies, oversee compliance with industry standards, and provide guidance to developers and stakeholders on security-related matters. Their goal is to protect applications from cyber threats while enabling business continuity and innovation.

What are the key skills and qualifications needed to thrive as a senior application security engineer?

To thrive as a Senior Application Security Engineer, you need a solid understanding of secure software development, threat modeling, vulnerability assessment, and a degree in computer science or a related field. Familiarity with tools like static and dynamic application security testing (SAST/DAST), code review platforms, and certifications such as CISSP or OSCP are often required. Strong analytical thinking, attention to detail, effective communication, and the ability to collaborate are standout soft skills for this role. These capabilities help ensure robust protection of applications, support safe software delivery, and enable effective teamwork across engineering and security teams.

What are the typical responsibilities of a senior application security engineer on a day-to-day basis?

A Senior Application Security Engineer typically spends their days reviewing application code for security vulnerabilities, performing threat modeling, and collaborating closely with development teams to ensure secure coding practices are followed. They may also lead security assessments, coordinate penetration tests, and work on developing or enforcing security policies within the organization. Regular interaction with cross-functional teams, such as DevOps and IT, is common to address security issues throughout the software development lifecycle. This role also often involves mentoring junior engineers and staying up to date with the latest security threats and technologies.

What are popular job titles related to Senior Application Security Engineer jobs in Toronto, ON?

For Senior Application Security Engineer jobs in Toronto, ON, the most frequently searched job titles are:

What job categories do people searching Senior Application Security Engineer jobs in Toronto, ON look for?

The top searched job categories for Senior Application Security Engineer jobs in Toronto, ON are:

What cities near Toronto, ON are hiring for Senior Application Security Engineer jobs?

Cities near Toronto, ON with the most Senior Application Security Engineer job openings:

Infographic showing various Senior Application Security Engineer job openings in Toronto, ON as of August 2026, with employment types broken down into 78% Full Time, 17% Part Time, and 5% Contract. Highlights an 90% Physical, 4% Hybrid, and 6% Remote job distribution, with an average salary of $143,705 per year, or $69.1 per hour.

Senior Application Security Engineer

Toronto, ON

TripleLift
Marketing • 51 - 200 employees

Full-time

Posted 17 days ago


Job description

Overview

The Senior Application Security Engineer plays a critical role in driving secure software development and application security maturity within TripleLift's Engineering and Security organization, directly influencing how we protect our advertising platforms and the trust our publishers and advertisers place in us. In this position, you will partner closely with Engineering, Platform, Cloud Infrastructure, and Security teams to shape secure coding practices, application security tooling, vulnerability remediation, and CI/CD security, ensuring security is embedded into how we design, build, deploy, and operate our products.This is an exciting opportunity for someone who wants to build and scale an application security program at a company operating at the center of a rapidly evolving, high-stakes ad-tech landscape, while contributing meaningfully to the long-term security posture and resilience of the organization.

Responsibilities
  • Play a critical role in building and maintaining a global security compliance program based on NIST CSF.
  • Scale application security by developing automated security testing utilizing enterprise SAST, DAST, and code-review tools.
  • Champion SDLC to promote secure application development and infrastructure deployment and facilitate secure coding remediation activities.
  • Automate security testing in CI/CD pipelines to detect vulnerabilities early, including building and maintaining the pipeline integrations themselves.
  • Administer and drive adoption of GitHub Advanced Security (GHAS) : code scanning, secret scanning, and dependency review across engineering repositories.
  • Participate in threat modeling and design/architecture spec reviews to identify and mitigate security risks early in the SDLC.
  • Coordinate with stakeholders to develop and implement a vulnerability management program and to perform threat-hunting activities.
  • Own and conduct internal penetration testing and vulnerability assessments of applications and infrastructure, and validate findings from third-party pentest engagements.
  • Monitor and respond to application-layer security threats like API abuses, business logic flaws, and common web vulnerabilities.
  • Collaborate with product and engineering teams to ensure security is a key consideration in software design and architecture.
  • Enhance application security posture by working with cross-functional teams to implement proper authentication, authorization, and data protection mechanisms.
  • Enhance and facilitate security incident handling activities.
  • Evangelize security best practices and provide education and awareness to company employees. Develop and implement secure coding guidelines and conduct secure development training for engineers.
  • Evaluate and continuously improve the maturity of the security program through the deployment and management of various security tools and processes.
Education & Requirements
  • 5 years minimum of experience in application security, secure software development, security engineering, or a similar role. 
  • Strong understanding of secure coding practices and ability to guide developers on remediation strategies.
  • Experience with GitHub Advanced Security (GHAS), including Code Scanning (SAST), Secret Scanning, and Dependency Review.
  • Proficiency in SAST, DAST, and SCA tools (e.g., CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode).
  • Hands-on experience integrating security testing tools into CI/CD pipelines for automated security scanning, including designing and building pipeline workflows.
  • Hands-on penetration testing / offensive security experience across web applications, APIs, or cloud infrastructure.
  • Knowledge of common application security vulnerabilities and mitigations (OWASP Top 10, CWE, business logic flaws, API security).
  • Ability to perform threat modeling and participate in design/architecture spec reviews to assess security risks in applications and services.
  • Experience conducting security code reviews across various programming languages (e.g., Python, Java, TypeScript, Go).
  • Understanding of security fundamentals with relation to various cybersecurity and compliance frameworks, particularly NIST CSF, but any of PCI, SOC2, HITRUST, ISO 27001/2, or similar.
  • Strong understanding of AWS security services and controls (IAM, VPC, KMS, GuardDuty, CloudTrail) and experience securing cloud-native environments and workloads, with the ability to deploy security tools within them.
  • Takes ownership of projects, works independently with minimal oversight, and delivers results in a fast-paced environment while balancing multiple priorities.
  • Continuously learns, adapts, and values correctness, efficiency, and constructive feedback.

Preferred:

  • Experience in the ad-tech / programmatic advertising industry, or another high-scale, real-time environment.
  • Preferred: Familiarity with using AI/LLM-based tools (e.g., Claude or similar) for threat intelligence, alert triage, or security automation.
  • Holds a cybersecurity certification, e.g., OSCP, GWAPT, CISSP, CISA, etc.