Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Application Security Engineer

Full-time

Apollo.Io

Apollo.io is the leading go-to-market solution for revenue teams, trusted by over 500,000 companies and millions of users globally, from rapidly growing startups to some of the world's largest enterprises. Founded in 2015, the company is one of the fastest growing companies in SaaS, raising approximately $250 million to date and valued at $1.6 billion. Apollo.io provides sales and marketing teams with easy access to verified contact data for over 210 million B2B contacts and 35 million companies worldwide, along with tools to engage and convert these contacts in one unified platform. By helping revenue professionals find the most accurate contact information and automating the outreach process, Apollo.io turns prospects into customers. Apollo raised a series D in 2023 and is backed by top-tier investors, including Sequoia Capital, Bain Capital Ventures, and more, and counts the former President and COO of Hubspot, JD Sherman, among its board members.

Role Overview


The Senior Application Security Engineer II is a senior individual contributor responsible for strengthening Apollo’s secure software development lifecycle and reducing application risk across product, platform, and AI-powered features.

This role blends deep code-level application security work with strong cross-functional partnership. It includes application security reviews, threat modeling, AppSec tooling, findings triage and remediation follow-through, external testing intake, and developer enablement.

This role is calibrated at the L6 senior-IC level: owning semi-annual or annual goals, solving ambiguous problems with sound judgment, improving operational processes, and driving meaningful cross-team collaboration and influence.

Key Responsibilities


Secure SDLC, design review, and threat modeling



  • Own and continuously improve the secure software development lifecycle for Apollo applications so security is embedded into design, implementation, and deployment.

  • Perform application security reviews, threat modeling, and deep code-level analysis for high-impact product, platform, and AI features before launch.

  • Provide practical security architecture guidance to Engineering, Product, and IT teams.

  • Help define and maintain application-security guardrails, secure design expectations, code review standards, and risk models for new and existing systems.

Vulnerability management and hands-on remediation



  • Drive execution-heavy vulnerability management across internal reviews, bug bounty, pentests, SCA/runtime findings, and other research signals, ensuring findings are validated, prioritized, routed clearly, and tracked through remediation and verification within SLAs.

  • Go beyond identifying issues: read the code, explain root cause, propose the safest fix, and directly implement or support remediation when needed for complex vulnerabilities.

  • Perform hands-on validation and offensive security testing of applications and fixes, including exploit development, bypass testing, adversarial thinking, and focused red-team-style exercises, to confirm remediations address the underlying issue rather than only the initial symptom.

  • Work across the kinds of application security issues common in modern SaaS environments, including authentication and authorization weaknesses, access control risks, OAuth and CSRF design flaws, SSRF, cryptographic and verification issues, information disclosure and data exposure risks, unsafe execution and deserialization patterns, and dependency or runtime vulnerabilities.

  • Apply clear, risk-based severity decisions using exploitability, data sensitivity, customer impact, and blast radius.

Tooling, automation, and AI



  • Configure and improve AppSec tooling and integrations, including SAST configuration, ignore lists, dashboards, and other controls that maintain useful coverage without excessive noise.

  • Select, build, or refine security tooling, small automations, and workflow enrichments that reduce manual effort and scale AppSec operations responsibly.

  • Use AI to automate, transform, and scale security and engineering-adjacent processes where it materially improves speed, consistency, or signal quality, while still validating outputs with strong engineering judgment.

  • Embed AI-specific security checks into SSDLC reviews and code analysis, including input and output handling, AI-exposed APIs, prompt and response guardrails, and abuse or data-exfiltration paths.

  • Partner cross-functionally on AI security requirements and controls so AI systems and AI-powered features are designed, deployed, and operated securely.

Engineering enablement and partnership



  • Support and scale security enablement for engineers and security champions, including secure coding, AppSec, and AI-safety content.

  • Provide actionable remediation guidance, secure patterns, and examples that help engineering teams fix issues quickly and correctly.

  • Partner closely with Engineering, Product, Platform, Data, Legal, and other security teams to keep AppSec priorities aligned with business risk and product velocity.

  • Produce clear documentation, metrics, and written narratives that improve AppSec visibility, observability, and decision-making.

What Good Looks Like at L6



  • Owns meaningful AppSec goals over a semi-annual or annual horizon and independently identifies the right solutions to ambiguous, open-ended problems.

  • Drives cross-team collaboration and operational improvements beyond isolated tickets or one-off reviews.

  • Makes informed decisions by balancing technical detail, business context, customer trust, and long-term risk.

  • Sets a high bar for ownership, communication, mentoring, and technical judgment, and helps raise the effectiveness of peers and partner teams.

Required Skills & Experience



  • 5+ years of software engineering or application security experience, with meaningful hands-on AppSec depth in modern SaaS environments.

  • Strong software development skills and the ability to read, write, and ship production code; Ruby experience is highly valuable, and Python or similar scripting ability is a plus.

  • Strong Linux and cloud fundamentals, ideally with experience in GCP-backed environments.

  • Deep familiarity with common AppSec issues, secure design, secure authentication and authorization patterns, vulnerability management, and developer security tooling.

  • Demonstrated ability to perform deep code review, penetration testing, and exploit-oriented validation, and to either fix vulnerabilities directly or work closely with engineers to land durable remediations that hold up against bypass attempts and variant analysis.

  • Experience handling findings from bug bounty, pentests, internal reviews, or automated security tooling through closure and verification.

  • Experience using AI-assisted tools, automations, APIs, or structured workflows to improve engineering or security processes at scale.

  • Experience securing AI-powered systems or features, including AI API exposure, prompt and response handling, data protection, misuse scenarios, and monitoring expectations.

  • Strong written and verbal communication, stakeholder management, and influencing skills across technical and non-technical partners.

Preferred Qualifications



  • Experience supporting or leading security reviews for AI-native products, internal agents, or AI-assisted engineering workflows.

  • Experience improving secure-by-design practices and AppSec observability in a fast-moving engineering organization.

  • Experience with security training, developer enablement, or security champions programs.

  • Relevant security certifications are a plus.

Example Success Outcomes





    • Improve the health and flow of AppSec findings by keeping prioritization, remediation, and verification moving within defined SLAs.

    • Complete recurring application reviews or threat models for important systems and features.

    • Increase engineering adoption of secure patterns, AppSec tooling, and security training.

    • Reduce manual toil and improve AppSec signal quality through targeted automation and responsible use of AI-assisted workflows.


 

The listed Pay Range reflects the total cash compensation inclusive of annual base salary and annual bonus as applicable. For sales roles, the range provided is the role’s On Target Earnings ("OTE") range, meaning that the range includes both the sales commissions/sales bonus target and annual base salary for the role. This salary range may be inclusive of several career levels at Apollo and will be narrowed during the interview process based on a number of factors, including the candidate’s experience, qualifications, and location. Applicants interested in this role who are not located in the US may request the annual salary range for their location during the interview process.

Additional benefits for this role may include: equity; company bonus or sales commissions/bonuses; 401(k) plan; at least 10 paid holidays per year, flex PTO, and parental leave; employee assistance program and wellbeing benefits; global travel coverage; life/AD&D/STD/LTD insurance; FSA/HSA and medical, dental, and vision benefits.

Tier 1 Pay Range (San Francisco, New York City, Seattle)

$218,000 - $273,000 USD

Tier 2 Pay Range (All other US Locations)

$190,000 - $237,000 USD

We are AI Native


Apollo.io is an AI-native company built on a culture of continuous improvement. We’re on the front lines of driving productivity for our customers—and we expect the same mindset from our team. If you're energized by finding smarter, faster ways to get things done using AI and automation, you'll thrive here.

Why You’ll Love Working at Apollo


At Apollo, we’re driven by a shared mission: to help our customers unlock their full revenue potential. That’s why we take extreme ownership of our work, move with focus and urgency , and learn voraciously to stay ahead.

We invest deeply in your growth, ensuring you have the resources, support, and autonomy to  own your role and make a real impact . Collaboration is at our core—we’re all for one , meaning you’ll have a team across departments ready to help you succeed. We encourage bold ideas and courageous action , giving you the freedom to experiment, take smart risks, and drive big wins.

If you’re looking for a place where your work matters, where you can push boundaries, and where your career can thrive—Apollo is the place for you. 

Learn more  here!

Vacancy posted 9 hours ago
Similar jobs that could be interesting for youBased on the Senior Application Security Engineer in Canada vacancy
  • $120k - $130k per year

     ...connection.   Reports to: Information Security Manager Location: Canada - Remote...  ...About the Role Backcountry needs a senior security engineer to protect and harden the multi-cloud...  ...with disabilities in our job application procedures. If you need assistance or... 
    Senior
    Remote job
    Full time
    Internship
    Work at office

    Csc Generation

    Canada
    9 hours ago
  •  ...Menlo Security's mission is enabling the world to connect, communicate and collaborate...  ...Ventures. We are seeking a Senior AI Security Engineer to focus on the emerging security challenges...  ...building a legacy. All qualified applicants will receive consideration for... 
    Senior
    Full time

    Menlo Security

    Canada
    9 hours ago
  • $158k - $237k per year

     ...Menlo Security's mission is enabling the world to connect, communicate...  ...a forward-thinking Security Engineer to join our security team,...  ...The role reaches beyond the application layer into the Control Plane,...  ...cookies, Subresource Integrity), secure authentication/authorization... 
    Senior
    Full time
    Local area
    Immediate start

    Menlo Security

    Canada
    9 hours ago
  • $150k - $180k per year

     ...on the spot, so everything stays clean, secure, and optimized. It lays the groundwork for...  ...will your new role look like? As an Application Security Manager, you will be a hands-on...  ...architecture and design discussions with engineering teams; Collaborating with... 
    Suggested
    Full time
    Local area

    Sharegate- En

    Canada
    9 hours ago
  • $104k - $139k per year

     ...diverse areas including AI, social media, security and more. And we’re doing this while...  ...automated moderation systems.  As a Senior Software Engineer - Operations, you’ll bring a passion...  ...bring:  Experience building modern web applications. Strong experience with Python/... 
    Senior
    Remote job
    Full time
    Immediate start
    Home office

    Mozilla

    Canada
    9 hours ago
  •  ...source. By delivering hardened, secure, and production-ready builds...  ...all the open source software engineers and AI agents rely on,...  ...Capital, and Spark Capital. Senior Product Security Engineer...  ...using AI for your resume or application, include the phrase “bonfires... 
    Senior
    Full time
    Local area
    Remote work
    Flexible hours

    Chainguard

    Canada
    9 hours ago
  •  ...support to make an impact as we build for the long term. About the role: As a member of our Security Operations Team, you will collaborate with a global team of engineers to monitor and respond to security events, lead security incidents as Incident Commander, and lead... 
    Senior
    Long term contract
    Full time
    Remote work

    Samsara

    Canada
    9 hours ago
  • $104k - $139k per year

     ...including AI, social media, security and more. And we’re doing this...  ...Contribute to standards-based, secure, and interoperable...  ...security initiatives: Partner with engineers across teams to identify, prioritize...  ..., cross-platform native applications, including performance and memory... 
    Senior
    Remote job
    Long term contract
    Full time
    Immediate start
    Home office

    Mozilla

    Canada
    9 hours ago
  •  ...on Docker to build, share, and run their applications across our suite of products including...  ...sandboxed environments, verified images, and secure infrastructure that make autonomous...  ...This is not a traditional software engineering role. You'll spend most of your time working... 
    Senior
    Full time
    Remote work
    Home office
    Shift work

    Docker

    Canada
    9 hours ago
  •  ...Role Overview We are seeking a forward-thinking Senior Security Engineer, AI & DevSecOps to help shape the future of secure AI adoption...  ...artificial intelligence. You'll work at the intersection of AI, application security, cloud security, and DevSecOps. This role is... 
    Senior
    Full time
    Internship
    Local area
    Flexible hours

    Atlas Hxm

    Canada
    9 hours ago
  • $175k - $195k per year

     ...We are seeking a Senior Staff Information Security Engineer to help shape and advance security across our hybrid technology estate. Our environment spans...  ..., veteran status, or any other basis protected by applicable law. Please be aware that all offers of employment are... 
    Senior
    Remote job
    Full time
    Work at office

    Nmi Llc

    Canada
    9 hours ago
  •  ...Docker to build, share, and run their applications across our suite of products including...  ...sandboxed environments, verified images, and secure infrastructure that make autonomous...  ...trustworthy by default. As a Senior Security Engineer embedded in the Desktop engineering team... 
    Senior
    Remote job
    Full time
    Home office
    Shift work

    Docker

    Canada
    9 hours ago
  • $222.2k - $412.7k per year

     ...their data and AI are fully understood, secured, and resilient to enable the...  ...posture management (DSPM) - is seeking a Senior Sales Engineer to drive technical leadership in our sales...  ...Privacy Notice . By submitting your application, you acknowledge that the information... 
    Senior
    Full time
    Local area
    Remote work
    Worldwide
    Shift work

    Veeam Software

    Canada
    9 hours ago
  •  ...improve operational efficiency, reduce security and compliance risk, and accelerate...  ...An overview of this role As a Senior Corporate Security Engineer, you'll help secure the systems...  ...including endpoints, identity systems, SaaS applications, and platforms that store sensitive... 
    Senior
    Full time
    Remote work

    Gitlab

    Canada
    9 hours ago
  •  ...taking advantage of all structured and unstructured data — securing and protecting private information more effectively — Elastic...  ...experience in onboarding and managing our security product. As a Senior Software Engineer on the Security EDR Workflows team, you will help design and... 
    Senior
    Full time

    Elastic Nv

    Canada
    9 hours ago
  • $80k - $150k per year

     ...Nasdaq: INOD) is a global data engineering company. We believe that data...  ...are looking for a hands-on Application Support Engineer to support,...  ...built and running on Google App Engine (GAE) and microservices....  ...client-specific engineering, security, review, change-management, and... 
    Full time
    Contract work
    Fixed term contract
    Internship
    Flexible hours

    Innodata Inc.

    Canada
    9 hours ago
  • $120k - $155k per year

     ...Looking For Breezeway is hiring a Senior Software Application Developer to join one of our customer-...  ..., and vendors. This role is for an engineer with a product-centric mindset, clear...  ...assisted tools. Assessment platforms and our applicant tracking systems may host data on... 
    Senior
    Full time
    Temporary work
    Remote work

    Breezeway

    Canada
    9 hours ago
  •  ...improve operational efficiency, reduce security and compliance risk, and accelerate...  ...An overview of this role As a Senior Software Engineer on GitLab's Authorization team, you will...  ...and operating production Ruby on Rails applications. Experience designing or implementing... 
    Senior
    Remote job
    Full time

    Gitlab

    Canada
    9 hours ago
  • $75k - $105k per year

     ...Reports to: Director of Engineering Location: Toronto, Canada...  ...Backcountry is looking for a senior engineer to own the architecture...  ..., and reliability of the web applications powering our ecommerce business...  ..., npm), and templating engines (Blade, Twig). Experience... 
    Senior
    Long term contract
    Full time
    Internship
    Remote work

    Csc Generation

    Canada
    9 hours ago
  •  ...comprehensive digital science platform – best-of-breed software applications already used by more than 2 million scientists, together in a...  ...Centric. We are Better Together.    What do we need  As the Senior Application Scientist your primary role is to configure &... 
    Senior
    Long term contract
    Full time
    Remote work
    Flexible hours

    Dotmatics

    Canada
    9 hours ago
  •  ...limited to, User Management: Provide technical support to Sales, Business Users, Institutional and Retail customer base with focus on application support, API support and network connectivity. Incident Management: Identification and resolution of production incidents. The... 
    Senior
    Full time
    Shift work
    Weekend work

    Crypto.com

    Canada
    9 hours ago
  •  ...to build, share, and run their applications across our suite of products including...  ..., verified images, and secure infrastructure that make autonomous...  .... We're looking for an Engineering Manager to lead this team. It's a small, very senior group that recently came... 
    Senior
    Full time
    Remote work
    Home office
    Visa sponsorship
    Shift work
    Afternoon shift

    Docker

    Canada
    9 hours ago
  •  ...committed to industry-leading security , crypto education , and...  ...controls program, we are seeking a senior professional with a strong...  ...Finance, Technology, Engineering, and Security to inform sound...  ...general controls (ITGCs) and IT application controls (ITACs), balancing regulatory... 
    Senior
    Full time
    Local area
    Remote work

    Kraken

    Canada
    9 hours ago
  • $218.42k - $302.84k per year

     ...building the new Internet by delivering software that makes it easy to securely interconnect people and their devices, no matter where they are....  .... Job Description We’re seeking a talented software engineer, specializing in security and infrastructure, to help grow our... 
    Full time
    Internship
    Work at office
    Remote work
    Home office
    Flexible hours

    Tailscale

    Canada
    9 hours ago
  • $120k - $140k per year

     ...of position: Staff Software Systems Engineer Position type:  Full time Location...  ..., Canada Position reports to: Senior Manager of Applications Engineering Application deadline:...  ...until filled. Work authorization: Applicants must have legal authorization to work... 
    Senior
    Full time
    Local area
    Work from home
    Flexible hours

    Extreme Networks

    Canada
    9 hours ago
  • $181k - $241k per year

     ...authentication. This role is a hands-on engineering position inside Information Security, focused on designing and shipping...  ...to web, mobile, and partner applications. Integrate CIAM platforms with...  ...downstream customer platforms. Own secure authentication and account flows... 
    Remote job
    Full time
    Work at office
    Flexible hours

    Affirm

    Canada
    9 hours ago
  •  ...milestone. Lime is hiring a Staff Security Software Engineer to join our Security team! In this role...  ...security practices for cloud-native application development. ~ Design and implement...  ..., identities and experiences. Applicants who require a reasonable accommodation... 
    Long term contract
    Full time
    Temporary work
    Remote work
    Flexible hours

    Lime

    Canada
    9 hours ago
  • $133k - $183k per year

     ...About the InfoSec & IT Team The Application Security team helps Affirm build and launch products...  ...risk. We partner closely with product, engineering, infrastructure, risk, compliance, and...  ..., partner with engineering teams on secure design decisions, and contribute lightweight... 
    Remote job
    Full time
    Internship
    Work at office
    Flexible hours

    Affirm

    Canada
    9 hours ago
  •  ...successfully hosted over 100 engineering internships, and always have...  ...Software Engineer Intern on our Security team, you'll get hands-on...  ...keeping Super.com 's products secure across the software lifecycle...  ...enforcement. Security and application logs/metrics/events are... 
    Remote job
    Full time
    Internship
    Work at office
    Home office
    Night shift

    Supercom

    Canada
    9 hours ago
  • $118k - $168k per year

     .... You'll join a small, sharp security team and take primary ownership...  ...the organization to bake secure-by-default patterns into their...  ...communication skills - you work with engineers as a partner.   Bonus:...  ...all our employees. We seek applicants of all backgrounds and... 
    Full time
    Work at office
    Work from home
    Flexible hours

    Waabi

    Canada
    9 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Application Security Engineer. Be the first to apply!