← Back to job listings
CL
Application Security Developer
Clio · Toronto, Canada
About The Role
Join Clio, a rapidly growing company in the legal tech industry, as an Application Security Engineer. In this role, you will be responsible for proactively discovering and remediating critical security vulnerabilities across our applications. You will work closely with development teams, provide guidance on security best practices, and contribute to collective developer education. Additionally, you will perform penetration testing, incident response, and proactive research to detect new attack vectors. This position offers a hybrid work model, flexible paid time off, and various health and wellness benefits.
- Emulating real-world adversaries to proactively discover, exploit, and help remediate critical security vulnerabilities across applications.
- Writing, reviewing, debugging, and implementing tools to help developers avoid security flaws, and building partnerships with development teams.
- Performing penetration testing, offensive campaigns against internal assets, and proactive research to detect new attack vectors.
- This role is for someone who is passionate about building innovative solutions and being exposed to new challenges and technologies while making an impact
- Experience in Application or Product Security, with a focus on offensive security and penetration testing
- Proven ability to lead and conduct formal threat modeling sessions
- Strong proficiency in at least one major programming language (e.g., Python, .NET, Ruby, JavaScript)
- Expertise with common application security tools and platforms (e.g., Burp Suite, SAST, SCA)
- Ability to identify malicious behaviour and emerging threats via log analysis
- Experience with log aggregation and SIEM technologies
- Experience securing applications in modern cloud environments (AWS, Azure, or GCP)
- Demonstrate a keen interest in improving your craft by using AI
- Hands-on expertise identifying and exploiting complex vulnerabilities (e.g., SSRF, Deserialization, logic bypasses)
- Active participation in the security community (e.g., presenting at conferences, contributing to open-source tools)
- Security certifications such as OSCP or OSWE
- Experience with Ruby on Rails, Puppet, Kubernetes, Terraform, ELK (Elastic, Logtash and Kibana)
- Strong AWS security experience on EC2 and managed services
- Infrastructure security (WAF, ACLs, authentication, device hardening)
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring