Hands-on experience integrating security into the software development lifecycle
Experience driving vulnerability remediation across teams you do not own, with a point of view on how to set severities, hold SLAs, and get things actually closed
Exposure to offensive security, whether that is running a bug bounty program, scoping penetration tests with external vendors, or finding and reporting real vulnerabilities yourself
A passion for coding and solving security problems scalably with code and automation, rather than with process and policy
Comfort writing and reviewing code in OOP languages such as Kotlin, Java, Python, or TypeScript, enough to read an unfamiliar service, judge whether a finding is real, and open the pull request that fixes it
Practical experience with AppSec detection tooling (SAST, DAST, SCA, or secret scanning), including the unglamorous parts: deploying it, tuning the rules, and cutting the false positives so engineers trust the results
A thorough understanding of web application security principles and common vulnerabilities, including OWASP Top 10, with an instinct for the systemic fix behind the individual finding
Experience leading threat models on systems you did not build, and the judgement to know which designs need one and which do not
Experience working in modern cloud computing environments such as AWS or GCP
The ability to explain risk to product engineers in a way that makes them want to fix it, and the credibility to be invited into design discussions rather than added as a gate
Curiosity about the security of AI-assisted development, and interest in figuring out what changes when a meaningful share of the code is machine-generated
AppSec tooling - SAST/DAST/SCA/secret scanning
Canada: the pay range for this role is $160,000 to $220,000 per year
Faire uses Artificial Intelligence (AI) to screen and select applicants for this position
This job posting is for an existing vacancy
Hybrid Faire employees currently go into the office 3 days per week on Tuesdays, Thursdays, and a third flex day of their choosing (Monday, Wednesday, or Friday). Additionally, hybrid in-office roles will have the flexibility to work remotely up to 4 weeks per year. Specific Workplace and Information Technology positions may require onsite attendance 5 days per week as will be indicated in the job posting