Senior Application Security Engineer
Summary
Senior engineer who codes security features into a science-communication SaaS (Node.js/React/Python on AWS) while running penetration tests, bug-bounty triage, and AI-native tooling.
What you'll do
- Contribute production-quality code directly to the application (Node.js/React) and infrastructure (Python, Terraform) – you ship fixes and hardening yourself, not just findings for others to action.
- Build and maintain security and CI/CD tooling for automation, keeping the secure path the default path.
- Act as a security reviewer on RFCs and design documents, and pair with engineers to resolve issues at the source.
- Define secure-by-design patterns and drive standards for authentication, authorization, and API security.
- Lead threat modeling on new and existing systems and turn those models into shipped controls.
- Own and evolve the Secure SDLC and CI/CD security integration (SAST/DAST/SCA/secrets) – tuned for high signal and low noise.
- Work AI-natively: use AI coding assistants and agentic tooling to accelerate code review, triage, and tooling development.
- Secure AI-integrated product features – reasoning about prompt injection, data leakage, and over-scoped tool, token, and data access.
- Automate recurring security work so the team scales through leverage, not headcount.
- Perform penetration testing and code reviews (Node.js/React) using OWASP methodology.
- Drive identification and remediation of application security vulnerabilities (SAST/DAST/HackerOne).
- Own the bug bounty program end to end – issue evaluation, reproduction, and closing findings by shipping fixes.
What you bring
- Demonstrable software engineering ability – you read code fluently, write production-quality code that engineers respect, and have contributed to real codebases (Node.js/React; Python a plus).
- Fluency using AI development tools (AI coding assistants, agentic workflows) to get the job done, and a clear-eyed view of the security risks they introduce.
- Expertise in web application security and secure-coding best practices, and the ability to review code and application findings.
- Experience integrating and maintaining SAST/DAST systems within CI/CD, and with Secure Software Development Life Cycles.
- Hands-on experience securing cloud workloads on AWS and comfort with infrastructure-as-code (Terraform or equivalent); familiarity with Cloudflare a plus.
- Threat-modeling experience and command of common code and network vulnerability types, their impact, and remediation.
- Applied knowledge of cryptography, PKI, and TLS and their practical implementation.
- Experience hardening LLM-integrated or AI-powered features in production.
- Experience operating a bug bounty program (e.g. HackerOne).
- Contributions to SOC 2 control design and audit readiness from the engineering side.
- Relevant certifications (e.g. OSCP, OSWE, AWS Security Specialty) – valued, but not a substitute for engineering ability.
- We are mission-driven: we work collaboratively towards our shared vision of improving scientific communication and accelerating scientific discovery. BioRender figures have appeared in more than 54,000 publications!
- BioRender is loved by millions! We have a world-class NPS and a community of loyal fans and users in 200+ countries!
- Our company is backed by top investors and accelerators like Y Combinator, and we are on a growth trajectory comparable to many top-performing SaaS companies
- We’re remote-first with team members across Canada and the U.S., offering you the flexibility to work from anywhere.