Senior Application Security Engineer II at Relay in Toronto, ON

  • Company: Relay
  • Location: Toronto, ON
  • Job type: full time
  • Workplace: remote
  • Posted: 2026-08-11

Apply for this role

All open roles at Relay

Job description

Relay is a digital banking platform that gives self-made business owners the tools and know-how to be great with money—bringing clarity, confidence, and control to every dollar earned, so they can turn hard work into lasting success. We do this by replacing financial guesswork with real visibility, transforming cash flow from a constant source of stress into a clear signal owners can use to run stronger, more resilient businesses. We’re looking for an Senior Application Security Engineer II who thrives on autonomy, curiosity, and impact. You'll join an Application Security team that is deliberately moving away from the advisory model most AppSec functions are stuck in. You’ll work across our stack (from TypeScript and Node.js, to Postgres and AWS cloud infrastructure) ensuring our applications are secure from design to deployment. You’ll blend technical depth with systems thinking, working across teams to identify risks, build guardrails, and evolve our security practices as Relay scales. Your mission is to own at least one AppSec process end to end, guide developers on how to solve challenging security problems and adapt traditional security solutions to the new AI landscape. This is a role with room to grow. You'll be working next to senior engineers who are maintaining our auth system and building our DAST tooling from scratch. The Relay AppSec team genuinely enjoys Application Security and is looking to make an impact on the field. What You'll Be Doing • Threat modeling & offensive testing: Threat model technical design documents (TDDs) and run white-box penetration tests on our testing environment to identify vulnerabilities from an attacker’s point of view. • VDP & bug bounty: Triage researcher reports, reproduce/assess impact, coordinate fixes with owners, and close the loop with clear comms and durable controls. • Shipping the fixes you can: Contributing directly to Relay’s code base when it makes sense — writing the patch, not filing the ticket. • Working in our security tooling and extending it : Datadog security, secrets scanning and logging, Burp Suite, and in-house tools you'll be expected to modify rather than just operate. • Building with AI as a default : Claude Code and Cursor are daily drivers on this team, not a pilot program. • Joining the team's rhythms : Two weekly standups, a biweekly security champions session with product engineers, and a weekly Hack The Box session. • Software supply chain: Enforce provenance: SBOM on every build, dependency pinning/owner verification, private registries/proxies, and runtime SCA detections. Who You Are • You have 5 to 6 years of professional security experience. Application security, penetration testing, or product security engineering or similar roles. • You've shipped production code: Production-level software real users depended on. And you can read an unfamiliar codebase well enough to fix something in it, which is most of this job. • Security fundamentals: Deep understanding of OWASP Top 10 and real-world exploitation/mitigation techniques. • You build with AI. You use AI tooling in your daily work and you've built something with it. You can talk about where it gets things wrong, not just that it's fast. • Clear communicator & collaborator: you are a collaborator who loves to partner with developers to bring value to customers in the most secure way possible. • Ownership: You have a sense of responsibility towards problems and take ownership over them making sure nothing is forgotten and stakeholders stay informed. • Mentorship: You are comfortable mentoring team members and members of other teams on security best practices. The Interview Process • Stage 1: A 60-minute Google Meet video call with the Hiring Manager • Stage 2: A 60-minute live session with the team • Stage 3: A 60-minute Secure Code Review and Coaching session with two members of our Customer Experience team • Stage 4: A 45-minute Google Meet video call with a member of our leadership team Our Com

Senior Application Security Engineer II on JobPost.