Senior Application Security Researcher

CommIT

• $135K — $160K *
US-AnywhereRemote in Toronto, ON
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in offensive security, vulnerability research, or application security
  • Deep understanding of web application and API vulnerabilities
  • Strong coding skills in Python, Go, or similar languages
  • Experience with detection logic (SAST, DAST, SCA) and reducing false positives
  • Familiarity with CI/CD pipelines, containers, Kubernetes, and cloud providers
  • Hands-on experience with LLMs/AI models for security tasks
  • Ability to work with large datasets (SQL, BigQuery) for research and detection accuracy
  • M.Sc. in Computer Science, Cyber Security, or related field

Responsibilities

  • Drive innovation in application security by developing next-generation detection methods
  • Collaborate with engineers and data scientists to enhance security capabilities
  • Build and refine autonomous pen-testing tools and techniques
  • Prototype and implement research ideas into production environments
  • Communicate complex security concepts clearly to technical and non-technical stakeholders

Benefits

  • Opportunity to work on cutting-edge security technologies
  • Collaborative environment with engineers and AI/data scientists
  • Focus on innovative, hands-on application security research
  • Potential for professional growth in a rapidly evolving field
  • Engagement in a build-and-break role that emphasizes creativity and problem-solving
Full Job Description
Description

The Security Research group is hiring a senior, hands-on Application Security Researcher to push modern AppSec forward - working with engineers, researchers and AI/data scientists on next-generation detection, including autonomous, agentic pen-testing capabilities. This is a build-and-break role, not a typical AppSec position.

Requirements

Must-have skills:

  • 5+ years hands-on in offensive security, vulnerability research, or application security
  • Deep understanding of web application and API vulnerabilities, including business-logic flaws and multi-step attack chains
  • Strong coding in Python, Go, or similar, with production-quality code shipped
  • Experience building or tuning detection logic (SAST, DAST, SCA, secrets, or custom rule engines) and reducing false positives
  • Solid grasp of modern stacks: CI/CD pipelines, containers, Kubernetes, and at least one major cloud provider
  • Hands-on use of LLMs / AI models for security tasks, with the judgment to measure where they help and where they fail
  • Comfort with large datasets (SQL, BigQuery, or similar) to drive research and measure detection accuracy
  • Takes research ideas from prototype to production with minimal guidance
  • Clear written communication - can explain a complex attack path to engineers and product managers
  • M.Sc. in Computer Science, Cyber Security, or a related field

Nice to have:

  • Published research, CVEs, conference talks, or a bug bounty track record
  • Experience building AI agents or evaluation frameworks for LLMs
  • Background in exploit development, red teaming, or penetration testing
  • Code analysis techniques (taint analysis, call graphs, reachability)
  • Contributions to open-source security tools

Similar Jobs

More Jobs at CommIT

More Information Technology Jobs

Find similar Senior Application Security Researcher jobs: