Magnet Forensics

Senior Application Security Engineer

Job Description

Role Overview:
Magnet Forensics is seeking a highly skilled and motivated Senior Application Security Engineer to join our dynamic team and play a key role in ensuring the security and integrity of our organization's products and customers’ data.
 
The Senior Security Engineer will be part of the engineering organization and responsible for implementing, managing, and enhancing security measures across our applications, products, and services to protect against potential cyber threats and attacks.
 
The ideal candidate will possess a strong technical background, a deep understanding of security best practices, and love to collaborate with developers and engineering teams to identify and mitigate security risks effectively. You’ll be a part of a talented team responsible for a wide range of product and engineering security programs.
 
Join us as a Senior Application Security Engineer and make a significant impact by fortifying our organization's security posture and ensuring the confidentiality, integrity, and availability of our critical assets.
 
NOTE: Candidate must reside in Canada.


Key Responsibilities:
  • Design, implement, and maintain application security processes and tooling such as SAST, SCA, containers, etc;
  • Collaborate with software developers and system administrators to review and improve the security architecture of new and existing applications, systems, and code. Familiarity with threat modelling, design reviews are helpful;
  • Conduct regular security assessments, vulnerability scans, and web application scanning. Work with engineering teams on notification, remediation, and patching strategies;
  • Monitor security events, analyze logs, and generate reports to identify suspicious activities, potential threats, and security breaches;
  • Establish and enforce security policies, standards, and guidelines in alignment with industry best practices, legal requirements, and internal security policies;
  • Design, implement, and maintain security infrastructure components in AWS and Azure such as Security Hub, Inspector, Config, Defender for Cloud.

  • Qualifications:
  • 5+ years as a Security Engineer or in a similar role, demonstrating hands-on experience in implementing, and improving a security program;
  • Strong knowledge of security protocols, cryptography, and common security technologies;
  • Ability to automate security tasks and integrate with various CI/CD tooling and processes;
  • Experienced with one or more scripting languages and reading basic scripts (Python, C#, PowerShell, Bash, or etc.);
  • Comfortable with writing pipelines for automation tasks (Jenkins, AzDO, GitLab, GitHub);
  • Strong familiarity writing IaC (CDK, CloudFormation, Terraform) with experience in deploying cloud workloads securely in either AWS or Azure and monitoring them for threats;
  • Excellent problem-solving and analytical skills to identify and address security vulnerabilities effectively;
  • Strong communication and interpersonal skills to collaborate with cross-functional teams and articulate complex security concepts to non-technical stakeholders;
  • Degree or diploma in relevant field or equivalent work experience.

  • Nice To Have Skills:
  • Experience in designing and building controls around AI usage in an engineering environment (models/technologies such as Claude Code/Bedrock/OpenAI/RAG/Txt&Img Classifiers/Agents/etc.);
  • Relevant certifications (e.g., CISSP, CISM, CompTIA Security+);
  • Experience with compliance frameworks (SOC2, ISO 27001, NIST 800-53, Fedramp, etc.).