Application Security Developer

Highspring โ€” Canada ยท Posted ~1 hour ago

๐Ÿ”“ Log in to save this job, tailor your resume & track your apply process โ€” 7 days free, no card needed.

Log in to add to target list

Description

Senior Application Security Developer - Python Position Overview We are seeking a Senior Application Security Developer to join a strategic enterprise Application Security transformation initiative. This is a highly technical, developer-first role requiring strong software development expertise in Python, combined with practical knowledge of application security, secure development practices, and vulnerability management. The successful candidate will help build, integrate, customize, and automate security solutions across the software development lifecycle. This is not simply a security-tool administration role-we are looking for a strong developer who can solve security challenges through engineering. Key Responsibilities Application Security Development Design, develop, and maintain Python-based security solutions, automation, and integrations.Build automation scripts and internal tooling to support secure software delivery.Develop custom APIs, connectors, and integrations between AppSec platforms and enterprise environments.Customize and extend existing security tooling based on business and technical requirements.Develop solutions when out-of-the-box security tooling does not fully address enterprise needs.Security Tooling & Platform Integration Support the implementation, configuration, integration, and optimization of AppSec platforms such as Snyk, Aqua Security, JFrog Xray, or similar technologies.Contribute to the evaluation and selection of the appropriate AppSec tooling strategy.Integrate security capabilities into CI/CD pipelines and software delivery workflows.Build proof-of-concepts and validate security tooling against technical and business requirements.Secure Development Practices Collaborate with development teams to implement secure-by-design principles.Analyze application vulnerabilities and provide actionable remediation recommendations.Improve application security across modern cloud-native and enterprise applications.Contribute to secure code reviews, threat modeling, vulnerability triage, and remediation.Collaboration & Enablement Work closely with the AppSec Architect, DevSecOps Engineers, and Software Developers.Support knowledge transfer and capability building within the AppSec squad.Help bridge the gap between application security and software engineering.Collaborate with technical stakeholders to ensure security solutions are practical, scalable, and aligned with development workflows.Required Qualifications 5+ years of enterprise software development experience.Strong hands-on development expertise in Python.Strong experience building APIs, backend services, automation, and system integrations.Solid understanding of application security and secure software development practices.Experience integrating tools and automation into CI/CD pipelines such as GitHub Actions, Jenkins, GitLab CI, or Azure DevOps.Experience working with cloud environments such as AWS, Azure, or GCP.Strong problem-solving skills with the ability to design and build custom technical solutions.Ability to work effectively in a complex enterprise environment.Nice-to-Have Hands-on experience with Snyk, Aqua Security, JFrog Xray, or comparable AppSec platforms.Experience with Software Composition Analysis (SCA).Experience with container security.Knowledge of SBOM management.Familiarity with secrets detection, dependency scanning, and vulnerability management.Knowledge of modern DevSecOps practices.Experience working within large, regulated enterprise environments. Profile We're Looking For We are looking for a strong developer first, with a security mindset. The ideal candidate: Is highly proficient in Python development.Can build and adapt security solutions, rather than simply operate security tools.Understands how security fits into modern software engineering and CI/CD practices.Is comfortable working in an environment where the AppSec tooling strategy is still evolving.Can operate with ambiguity and contribute technically to defining the future-state solution.Brings a pragmatic engineering mindset focused on automation, scalability, and developer enablement.