BioRender

Senior Application Security Engineer

BioRender$120K — $150K *
US-AnywhereRemote in United States
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years of software engineering experience with a focus on secure coding practices.
  • Proficient in programming languages like Node.js, React, and Python.
  • Experience with CI/CD security integrations (SAST/DAST/SCA).
  • Background in web application security and vulnerability management processes.
  • Hands-on experience with AWS and Terraform for cloud security.

Responsibilities

  • Contribute production-quality code for application and infrastructure directly.
  • Build and maintain security tooling for CI/CD that prioritizes security.
  • Review RFCs and design documents for security considerations with engineering teams.
  • Define secure design patterns and set security standards for the organization.
  • Lead threat modeling initiatives for both new and existing systems.
  • Oversee the integration of security practices into the Secure SDLC and automate where possible.
  • Conduct penetration testing and lead the bug bounty program processes.

Benefits

  • Flexible working arrangements to promote work-life balance.
  • Opportunity to work with cutting-edge AI technologies in security.
  • Collaborative work environment focused on innovation and improvement.
  • Professional development and growth opportunities within the company.
Full Job Description
BioRender is seeking a Senior Application Security Engineer to join our Security team - an engineer first, who contributes directly to the codebase rather than managing security from the sidelines. You'll help define how security is built into our engineering organization, contributing production code across our application (Node.js/React/Python) and infrastructure (Python, Terraform, AWS, Cloudflare) while shaping secure-by-design patterns, CI/CD automation, and engineering workflows that let the company move quickly and safely.

You'll work AI-natively, using AI coding assistants and agentic tooling to accelerate your own work while helping secure the AI-powered capabilities we're building. If you're excited by building developer-friendly security systems, solving meaningful engineering problems, and focusing on the threats that actually matter, we'd love to hear from you.

What you'll do

Hands-on engineering & codebase contribution

  • Contribute production-quality code directly to the application (Node.js/React) and infrastructure (Python, Terraform) - you ship fixes and hardening yourself, not just findings for others to action.
  • Build and maintain security and CI/CD tooling for automation, keeping the secure path the default path.
  • Act as a security reviewer on RFCs and design documents, and pair with engineers to resolve issues at the source.


Architecture, design & secure SSDLC

  • Define secure-by-design patterns and drive standards for authentication, authorization, and API security.
  • Lead threat modeling on new and existing systems and turn those models into shipped controls.
  • Own and evolve the Secure SDLC and CI/CD security integration (SAST/DAST/SCA/secrets) - tuned for high signal and low noise.


AI-native security & automation

  • Work AI-natively: use AI coding assistants and agentic tooling to accelerate code review, triage, and tooling development.
  • Secure AI-integrated product features - reasoning about prompt injection, data leakage, and over-scoped tool, token, and data access.
  • Automate recurring security work so the team scales through leverage, not headcount.


Web & product security (active defense)

  • Perform penetration testing and code reviews (Node.js/React) using OWASP methodology.
  • Drive identification and remediation of application security vulnerabilities (SAST/DAST/HackerOne).
  • Own the bug bounty program end to end - issue evaluation, reproduction, and closing findings by shipping fixes.


What you bring

  • Demonstrable software engineering ability - you read code fluently, write production-quality code that engineers respect, and have contributed to real codebases (Node.js/React; Python a plus).
  • Fluency using AI development tools (AI coding assistants, agentic workflows) to get the job done, and a clear-eyed view of the security risks they introduce.
  • Expertise in web application security and secure-coding best practices, and the ability to review code and application findings.
  • Experience integrating and maintaining SAST/DAST systems within CI/CD, and with Secure Software Development Life Cycles.
  • Hands-on experience securing cloud workloads on AWS and comfort with infrastructure-as-code (Terraform or equivalent); familiarity with Cloudflare a plus.
  • Threat-modeling experience and command of common code and network vulnerability types, their impact, and remediation.
  • Applied knowledge of cryptography, PKI, and TLS and their practical implementation.


Nice to have:

  • Experience hardening LLM-integrated or AI-powered features in production.
  • Experience operating a bug bounty program (e.g. HackerOne).
  • Contributions to SOC 2 control design and audit readiness from the engineering side.
  • Relevant certifications (e.g. OSCP, OSWE, AWS Security Specialty) - valued, but not a substitute for engineering ability.

About BioRender

BioRender is a biotech company that provides a platform for creating scientific illustrations. The company's platform enables scientists to create professional-grade illustrations for their research papers, presentations, and grant proposals. BioRender's clients include some of the world's leading research institutions, such as Harvard University, Stanford University, and the National Institutes of Health. The company was founded in 2016 and is headquartered in Toronto, Canada.
Learn more about BioRender
Size
50 employees
Industry
Net Income
-$2 million
Founded
2016
5 Year Trend
+50%
Revenue
$5 million

Similar Jobs

More Jobs at BioRender

More Information Technology Jobs

Find similar Senior Application Security Engineer jobs: