×
Register Here to Apply for Jobs or Post Jobs. X

Application Security Engineer

Job in Toronto, Ontario, C6A, Canada
Listing for: HelloFresh
Full Time position
Listed on 2026-08-07
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, IT Consultant, Systems Engineer
Salary/Wage Range or Industry Benchmark: 90000 - 140000 CAD Yearly CAD 90000.00 140000.00 YEAR
Job Description & How to Apply Below

Application Security Engineer at Hello Fresh

As an Application Security Engineer at Hello Fresh, you will play a critical role in safeguarding our applications and ensuring the security of our systems. You will collaborate closely with various teams to identify vulnerabilities, implement security measures, and promote best practices across the organization. This position is ideal for someone passionate about application security and eager to contribute to a dynamic and innovative environment.

You will be based in Toronto, Ontario, and have the opportunity to work with a diverse group of professionals dedicated to delivering high-quality services.

Key facts
  • Location:

    Toronto, Ontario, Canada
  • Engagement:
    Full-time
  • Salary:
    Competitive salary based on experience
  • Visa:
    Open to candidates requiring work authorization
What you'll do
  • Conduct comprehensive security assessments on applications throughout the development lifecycle, identifying vulnerabilities and recommending remediation strategies.
  • Collaborate with development teams to integrate security best practices into the software development process, ensuring secure coding standards are followed.
  • Develop and maintain security testing frameworks and tools to automate security checks and streamline the assessment process.
  • Monitor and analyze security incidents, providing timely responses and implementing lessons learned to prevent future occurrences.
  • Create and deliver training sessions for developers and other stakeholders to raise awareness of application security risks and best practices.
  • Participate in threat modeling exercises to identify potential security risks in new and existing applications.
  • Review and analyze third-party software and services for security compliance, ensuring they meet Hello Fresh's security standards.
  • Stay updated on the latest security trends, vulnerabilities, and technologies, sharing insights with the team to enhance our security posture.
  • Collaborate with cross-functional teams to ensure security considerations are integrated into project planning and execution.
  • Assist in the development and enforcement of security policies, standards, and guidelines related to application security.
  • Conduct post-incident reviews to assess the effectiveness of security measures and recommend improvements.
  • Contribute to the continuous improvement of the application security program by providing feedback and suggestions based on industry best practices.
Requirements
  • Bachelor's degree in Computer Science, Information Security, or a related field.
  • A minimum of 3 years of experience in application security, software development, or a related field.
  • Strong understanding of secure coding practices and experience with common web application vulnerabilities (e.g., OWASP Top Ten).
  • Proficiency in programming languages such as Java, Python, or JavaScript, with the ability to review and analyze code for security flaws.
  • Experience with security testing tools (e.g., SAST, DAST, IAST) and familiarity with CI/CD pipelines.
  • Knowledge of security frameworks and standards, such as NIST, ISO 27001, or CIS.
  • Excellent problem-solving skills and the ability to work independently as well as collaboratively in a team environment.
  • Strong communication skills, with the ability to convey complex security concepts to non-technical stakeholders.
  • Familiarity with cloud security principles and experience with cloud platforms (e.g., AWS, Azure, GCP) is a plus.
Nice to have
  • Relevant security certifications, such as Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or Offensive Security Certified Professional (OSCP).
  • Experience with Dev Sec Ops  practices and tools.
  • Knowledge of container security and orchestration technologies (e.g., Docker, Kubernetes).
Skills & tools
  • Proficient in security assessment tools and methodologies.
  • Familiarity with application security testing tools and frameworks.
  • Strong analytical and troubleshooting skills.
  • Ability to work with version control systems (e.g., Git).
  • Experience with security incident response and management.
Practical notes
  • This position is based in Toronto, Ontario, and may require occasional travel for team meetings or conferences.
  • The role may involve working flexible hours to accommodate collaboration with teams in different time zones.
  • Candidates must be eligible to work in Canada and may require a work visa depending on their situation.
#J-18808-Ljbffr
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary