Staff Application Security Specialist

Workleap - en

$110K — $130K *
US-AnywhereRemote in Canada
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years in application security, DevSecOps, or security-focused software development
  • Strong software engineering foundation with advanced security knowledge
  • In-depth knowledge of web application security and OWASP Top 10
  • Hands-on secure code review experience in C#
  • Experience automating security in CI/CD pipelines (GitHub Actions preferred)
  • Understanding of Azure cloud services and infrastructure security
  • Familiarity with authentication protocols like OIDC, SAML, and OAuth

Responsibilities

  • Embed security into CI/CD pipelines with automated tooling and checks
  • Design and implement automated security review workflows
  • Establish security guardrails in AI-assisted development workflows
  • Identify and remediate application security vulnerabilities proactively
  • Lead threat modeling and security assessments for features and changes
  • Enhance vulnerability management through automation and tooling
  • Collaborate on hardening Azure environments for security

Benefits

  • Supportive and inclusive work environment
  • Encouragement for creativity and personal growth
  • Adaptable workplace aligning with employee needs
  • Flexible work-life balance
  • Opportunities for collaboration across teams
Full Job Description
Your role

You will build the security layer for how Workleap writes software, and then you will teach it to run itself.

Today that means the traditional stack done properly. SAST, DAST, SCA, and secret scanning wired into GitHub Actions so findings land where developers already work, with the noise tuned out rather than tolerated. Threat modeling on architectural changes. Vulnerability intake and triage that closes the loop instead of filling a backlog.

Where it goes next is the actual reason this role exists. We are moving toward agentic security review, where agents perform the first pass on every pull request, reason about the change in context, and escalate what matters to a human. Nobody has fully solved this. Rules engines miss intent, models hallucinate findings, and the gap between the two is where the interesting work is. You will close that gap, and you will decide how much trust the system earns at each step.

You will be a hands on individual contributor. You will write the code.

Your impact:
  • Build the security guardrails for AI assisted and agentic development so speed and safety stop being a tradeoff
  • Move security review from human bottleneck to automated first pass with human judgment reserved for what is genuinely ambiguous
  • Achieve near-zero developer friction on security signals by wiring SAST/DAST/SCA into CI/CD with noise tuned low enough that findings actually get fixed.
  • Lead threat modeling on new features and architectural changes
  • Drive real remediation of application security vulnerabilities, measured by risk retired and not tickets closed
  • Harden Azure environments and deployment patterns alongside Infrastructure SecOps

Your team

You will join LeapSec and report to the Director of Infrastructure and Security. We're a small team with broad reach covering product security, cloud security, and governance across Workleap and ShareGate. That means your work ships, you own it end to end, and you set the priorities that matter. The scope is real, and so is the autonomy that comes with it.

You will partner closely with the AI SDLC team, which builds the internal platform that lets AI agents operate across the development lifecycle, and with product engineering across the organization.

What you'll bring

  • Five or more years in application security, DevSecOps, or security focused software development, with a real engineering background behind it
  • Deep working knowledge of web application security, OWASP Top 10, and CWE Top 25
  • Proven experience building security automation into CI/CD pipelines, GitHub Actions preferred
  • Built and shipped real agent tooling, not just used it. MCP servers, Claude skills, subagents, and custom tools that other people depend on
  • Context engineering as a discipline. Knowing what an agent needs in front of it to reason correctly about a codebase, and what to leave out
  • Understanding of the security model of agentic systems themselves. Prompt injection, tool permission scoping, credential handling in agent workflows, and what an agent with repo write access can do when it is wrong
  • Proficiency in Python for building tooling, not just scripting around it
  • Hands on experience with AI assisted and agentic development workflows and a clear view of where they break
  • Solid grasp of Azure services, infrastructure security, and deployment patterns
  • The ability to explain a risk tradeoff to an engineer and to an executive in the same week and be understood by both


Strong assets

  • Secure code review experience in C#/.NET
  • Experience integrating SAST, DAST, SCA, and secret scanning at scale
  • Familiarity with OIDC, SAML, and OAuth
  • Exposure to SOC2 requirements
  • Experience running vulnerability discovery and triage with a developer community
What the job comes with
  • Annual bonus program.
  • LTIP program, share in Workleap's long-term growth.
  • RRSP + Family health insurance + telemedicine + annual wellness budget.
  • Flexible vacation policy.
  • Remote work, with access to our Montreal office.
  • In-person gathering twice a year.
  • Claude access, for everyone.

Similar Jobs

More Jobs at Workleap - en

More Information Technology Jobs

Find similar Staff Application Security Specialist jobs: