×
Register Here to Apply for Jobs or Post Jobs. X

Staff Application Security Specialist

Remote / Online - Candidates ideally in
Moncton, New Brunswick, Canada
Listing for: Workleap Inc.
Remote/Work from Home position
Listed on 2026-09-11
Job specializations:
  • Software Development
    AI Engineer (Applied/Software)
Job Description & How to Apply Below
Workleap is a Montreal-based tech company, founded in 2006. We're builders at heart, we make simple products that actually matter to the people who use them. We have two product lines:

Workleap Agent , our newest solution built to make every manager more effective, andShare

Gate , the world's leading solution for Microsoft 365 migration and governance. More than 15,000 companies worldwide trust us to do exactly that. We're intentional about who joins us. If you're the kind of person who gets excited by a hard problem and wants to help shape what comes next, there's a place for you here.

Your role
You will build the security layer for how Workleap writes software, and then you will teach it to run itself.

Today that means the traditional stack done properly. SAST, DAST, SCA, and secret scanning wired into Git Hub Actions so findings land where developers already work, with the noise tuned out rather than tolerated. Threat modeling on architectural changes. Vulnerability intake and triage that closes the loop instead of filling a backlog.

Where it goes next is the actual reason this role exists. We are moving toward agentic security review, where agents perform the first pass on every pull request, reason about the change in context, and upscale what matters to a human. Nobody has fully solved this. Rules engines miss intent, models hallucinate findings, and the gap between the two is where the interesting work is.

You will close that gap, and you will decide how much trust the system earns at each step.

You will be a hands on individual contributor. You will write the code.

Your impact:

Build the security guardrails for AI assisted and agentic development so speed and safety stop being a tradeoff

Move security review from human bottleneck to automated first pass with human judgment reserved for what is genuinely ambiguous

Achieve near-zero developer friction on security signals by wiring SAST/DAST/SCA into CI/CD with noise tuned low enough that findings actually get fixed.

Lead threat modeling on new features and architectural changes

Drive real remediation of application security vulnerabilities, measured by risk retired and not tickets closed

Harden Azure environments and deployment patterns alongside Infrastructure Sec Ops

Your team
You will join Leap Sec and report to the Director of Infrastructure and Security. We're a small team with broad reach covering product security, cloud security, and governance across Workleap and Share Gate. That means your work ships, you own it end to end, and you set the priorities that matter. The scope is real, and so is the autonomy that comes with it.

You will partner closely with the AI SDLC team, which builds the internal platform that lets AI agents operate across the development lifecycle, and with product engineering across the organization.

What you'll bring

Five or more years in application security, Dev Sec Ops , or security focused software development, with a real engineering background behind it

Deep working knowledge of web application security, OWASP Top 10, and CWE Top 25

Proven experience building security automation into CI/CD pipelines, Git Hub Actions preferred

Built and shipped real agent tooling, not just used it. MCP servers, Claude skills, subagents, and custom tools that other people depend on

Context engineering as a discipline. Knowing what an agent needs in front of it to reason correctly about a codebase, and what to leave out

Understanding of the security model of agentic systems themselves. Prompt injection, tool permission scoping, credential handling in agent workflows, and what an agent with repo write access can do when it is wrong

Proficiency in Python for building tooling, not just scripting around it

Hands on experience with AI assisted and agentic development workflows and a clear view of where they break

Solid grasp of Azure services, infrastructure security, and deployment patterns

The ability to explain a risk tradeoff to an engineer and to an executive in the same week and be understood by both

Strong assets

Secure code review experience in C#/.NET

Experience integrating SAST, DAST, SCA, and secret scanning at scale

Familiarity with OIDC, SAML, and OAuth

Exposure to SOC2 requirements

Experience running vulnerability discovery and triage with a developer community

What the job comes with

LTIP program, share in Workleap's long-term growth.

RRSP + Family health insurance + telemedicine + annual wellness budget.

Flexible vacation policy.

Remote work, with access to our Montreal…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary