远程工作雷达

资深应用安全专员

Staff Application Security Specialist

开发工程限定地区(需当地身份)
公司workleap
薪资未公开
工作地点Canada - Remote
地域资格限定地区(需当地身份)
时区要求无特别要求
用工类型未标注
发布时间2026-04-22
数据来源Greenhouse
前往企业招聘页投递 →
注意地域限制:该职位明确限定在 Canada - Remote 招聘。如果你是位于中国大陆的求职者,通常需要当地工作身份才能投递,或需与雇主确认是否接受独立合同(Contractor)形式合作。

公司简介

Workleap 是一家成立于 2006 年的蒙特利尔科技公司。我们本质上是建造者,我们打造对使用者真正有意义的简单产品。我们有两个产品线:Workleap Agent,我们最新推出的解决方案,旨在让每位经理更高效;ShareGate,全球领先的 Microsoft 365 迁移和治理解决方案。全球超过 15,000 家公司信任我们完成这项工作。我们对加入我们的人员有明确的标准。如果你是那种对难题感到兴奋,并希望参与塑造未来的人,这里就有你的位置。

你的角色

你将构建 Workleap 编写软件的安全层,然后教会它自行运行。

目前这意味着正确地使用传统技术栈。将 SAST、DAST、SCA 和密钥扫描集成到 GitHub Actions 中,使发现的问题出现在开发者已经工作的位置,并减少噪音而不是容忍噪音。对架构变更进行威胁建模。漏洞接收和优先级排序要闭环处理,而不是堆积成待办事项。

接下来的方向才是这个职位存在的真正原因。我们正在向代理安全审查方向发展,其中代理会对每个 pull request 进行初步检查,根据上下文分析变更,并将重要的问题升级给人类。没有人完全解决过这个问题。规则引擎会忽略意图,模型会产生错误结论,而两者之间的差距正是有趣的工作所在。你将缩小这个差距,并决定系统在每一步能获得多少信任。

你将是一个亲自参与的个体贡献者。你将编写代码。

你的影响:

  • 为 AI 辅助和代理开发建立安全护栏,使速度和安全不再成为权衡
  • 将安全审查从人力瓶颈转变为自动化第一轮,将人类判断保留给真正模糊的问题
  • 通过将 SAST/DAST/SCA 集成到 CI/CD 中,并将噪音调低到发现问题真的能得到修复的程度,实现几乎零开发人员摩擦
  • 主导新功能和架构变更的威胁建模
  • 推动应用安全漏洞的实际修复,以淘汰的风险而非关闭的工单来衡量
  • 与 Infrastructure SecOps 一起强化 Azure 环境和部署模式

你的团队

你将加入 LeapSec,并向基础设施和安全总监汇报。我们是一个小团队,但影响范围广泛,涵盖产品安全、云安全和治理。

查看英文原文

Company Description

Workleap is a Montreal-based tech company, founded in 2006. We're builders at heart, we make simple products that actually matter to the people who use them. We have two product lines: Workleap Agent, our newest solution built to make every manager more effective, and ShareGate, the world's leading solution for Microsoft 365 migration and governance. More than 15,000 companies worldwide trust us to do exactly that. We're intentional about who joins us. If you're the kind of person who gets excited by a hard problem and wants to help shape what comes next, there's a place for you here.

Your role

You will build the security layer for how Workleap writes software, and then you will teach it to run itself.

Today that means the traditional stack done properly. SAST, DAST, SCA, and secret scanning wired into GitHub Actions so findings land where developers already work, with the noise tuned out rather than tolerated. Threat modeling on architectural changes. Vulnerability intake and triage that closes the loop instead of filling a backlog.

Where it goes next is the actual reason this role exists. We are moving toward agentic security review, where agents perform the first pass on every pull request, reason about the change in context, and escalate what matters to a human. Nobody has fully solved this. Rules engines miss intent, models hallucinate findings, and the gap between the two is where the interesting work is. You will close that gap, and you will decide how much trust the system earns at each step.

You will be a hands on individual contributor. You will write the code.

Your impact:

  • Build the security guardrails for AI assisted and agentic development so speed and safety stop being a tradeoff
  • Move security review from human bottleneck to automated first pass with human judgment reserved for what is genuinely ambiguous
  • Achieve near-zero developer friction on security signals by wiring SAST/DAST/SCA into CI/CD with noise tuned low enough that findings actually get fixed.
  • Lead threat modeling on new features and architectural changes
  • Drive real remediation of application security vulnerabilities, measured by risk retired and not tickets closed
  • Harden Azure environments and deployment patterns alongside Infrastructure SecOps

Your team

You will join LeapSec and report to the Director of Infrastructure and Security. We're a small team with broad reach covering product security, cloud security, and governance across Workleap and ShareGate. That means your work ships, you own it end to end, and you set the priorities that matter. The scope is real, and so is the autonomy that comes with it.

You will partner closely with the AI SDLC team, which builds the internal platform that lets AI agents operate across the development lifecycle, and with product engineering across the organization.

What you'll bring

  • Five or more years in application security, DevSecOps, or security focused software development, with a real engineering background behind it
  • Deep working knowledge of web application security, OWASP Top 10, and CWE Top 25
  • Proven experience building security automation into CI/CD pipelines, GitHub Actions preferred
  • Built and shipped real agent tooling, not just used it. MCP servers, Claude skills, subagents, and custom tools that other people depend on
  • Context engineering as a discipline. Knowing what an agent needs in front of it to reason correctly about a codebase, and what to leave out
  • Understanding of the security model of agentic systems themselves. Prompt injection, tool permission scoping, credential handling in agent workflows, and what an agent with repo write access can do when it is wrong
  • Proficiency in Python for building tooling, not just scripting around it
  • Hands on experience with AI assisted and agentic development workflows and a clear view of where they break
  • Solid grasp of Azure services, infrastructure security, and deployment patterns
  • The ability to explain a risk tradeoff to an engineer and to an executive in the same week and be understood by both

Strong assets

  • Secure code review experience in C#/.NET
  • Experience integrating SAST, DAST, SCA, and secret scanning at scale
  • Familiarity with OIDC, SAML, and OAuth
  • Exposure to SOC2 requirements
  • Experience running vulnerability discovery and triage with a developer community

What the job comes with

  • Annual bonus program.
  • LTIP program, share in Workleap's long-term growth.
  • RRSP + Family health insurance + telemedicine + annual wellness budget.
  • Flexible vacation policy.
  • Remote work, with access to our Montreal office.
  • In-person gathering twice a year.
  • Claude access, for everyone.

What drives us

At Workleap, we build software that sits at the center of how people experience work, every day, at every level.

We move fast. Priorities shift, decisions get made with the information we have, and we iterate. If you thrive on intensity and ambiguity doesn't slow you down, you'll feel right at home.
We're builders. We do what it takes to move forward. AI is part of our toolkit. We use it to go faster and decide smarter, not to replace judgment.

If you want real impact and a place where your decisions matter, this is it.

How we hire

Transparency is how we hire — for you as much as for us.

Here's how it works: a first call with a recruiter, then a virtual interview with the hiring manager. You'll then complete a take-home case study, followed by a meet with future colleagues to discuss it together. Depending on the role, the process may vary slightly — your recruiter will walk you through it on your first call.

We use AI to support certain steps of the process, but every hiring decision remains human.

We can't wait to meet you.

By applying, you confirm that you have read and agree to our privacy policy.

#LI-Remote

本页面信息整理自 Greenhouse,版权归原发布方所有。职位可能随时关闭,投递请以原始页面为准。 本站只做信息聚合展示,不参与招聘流程,也不向求职者收取任何费用。

该公司其他在招职位

← 返回全部职位