Senior Application Security Engineer at BioRender Inc.
Canada
<div><span style="color: rgb(0, 0, 0); background-color: transparent;">At BioRender, we’re on a mission to accelerate the world’s ability to learn, discover, and communicate science – transforming how knowledge is shared and making science open, collaborative, and easily understandable by all.</span></div><div>We’re shaping the future of science communication and are looking for talented individuals to help bring this vision to life! 🚀</div><div><br></div><div><span style="background-color: transparent; color: rgb(0, 0, 0);">BioRender is seeking a Senior Application Security Engineer to join our Security team – an engineer first, who contributes directly to the codebase rather than managing security from the sidelines. You'll help define how security is built into our engineering organization, contributing production code across our application (Node.js/React/Python) and infrastructure (Python, Terraform, AWS, Cloudflare) while shaping secure-by-design patterns, CI/CD automation, and engineering workflows that let the company move quickly and safely.</span></div><div><br></div><div><span style="background-color: transparent; color: rgb(0, 0, 0);">You'll work AI-natively, using AI coding assistants and agentic tooling to accelerate your own work while helping secure the AI-powered capabilities we're building. If you're excited by building developer-friendly security systems, solving meaningful engineering problems, and focusing on the threats that actually matter, we'd love to hear from you.</span></div><div><br></div><h3><strong>What you'll do </strong></h3><div><br></div><div><strong style="background-color: transparent;">Hands-on engineering & codebase contribution</strong></div><ul><li class=""><span style="background-color: transparent;">Contribute production-quality code directly to the application (Node.js/React) and infrastructure (Python, Terraform) – you ship fixes and hardening yourself, not just findings for others to action.</span></li><li class=""><span style="background-color: transparent;">Build and maintain security and CI/CD tooling for automation, keeping the secure path the default path.</span></li><li class=""><span style="background-color: transparent;">Act as a security reviewer on RFCs and design documents, and pair with engineers to resolve issues at the source.</span></li></ul><div><strong style="background-color: transparent;">Architecture, design & secure SSDLC</strong></div><ul><li class=""><span style="background-color: transparent;">Define secure-by-design patterns and drive standards for authentication, authorization, and API security.</span></li><li class=""><span style="background-color: transparent;">Lead threat modeling on new and existing systems and turn those models into shipped controls.</span></li><li class=""><span style="background-color: transparent;">Own and evolve the Secure SDLC and CI/CD security integration (SAST/DAST/SCA/secrets) – tuned for high signal and low noise.</span></li></ul><div><strong style="background-color: transparent;">AI-native security & automation</strong></div><ul><li class=""><span style="background-color: transparent;">Work AI-natively: use AI coding assistants and agentic tooling to accelerate code review, triage, and tooling development.</span></li><li class=""><span style="background-color: transparent;">Secure AI-integrated product features – reasoning about prompt injection, data leakage, and over-scoped tool, token, and data access.</span></li><li class=""><span style="background-color: transparent;">Automate recurring security work so the team scales through leverage, not headcount.</span></li></ul><div><strong style="background-color: transparent;">Web & product security (active defense)</strong></div><ul><li class=""><span style="background-color: transparent;">Perform penetration testing and code reviews (Node.js/React) using OWASP methodology.</span></li><li class=""><span style="background-color: transparent;">Drive identification and remediation of application security vulnerabilities (SAST/DAST/HackerOne).</span></li><li class=""><span style="background-color: transparent;">Own the bug bounty program end to end – issue evaluation, reproduction, and closing findings by shipping fixes.</span></li></ul><div><br></div><h3><strong>What you bring</strong></h3><div><br></div><ul><li class=""><span style="background-color: transparent;">Demonstrable software engineering ability – you read code fluently, write production-quality code that engineers respect, and have contributed to real codebases (Node.js/React; Python a plus).</span></li><li class=""><span style="background-color: transparent;">Fluency using AI development tools (AI coding assistants, agentic workflows) to get the job done, and a clear-eyed view of the security risks they introduce.</span></li><li class=""><span style="background-color: transparent;">Expertise in web application security and secure-coding best practices, and the ability to review code and application findings.</span></li><li class=""><span style="background-color: transparent;">Experience integrating and maintaining SAST/DAST systems within CI/CD, and with Secure Software Development Life Cycles.</span></li><li class=""><span style="background-color: transparent;">Hands-on experience securing cloud workloads on AWS and comfort with infrastructure-as-code (Terraform or equivalent); familiarity with Cloudflare a plus.</span></li><li class=""><span style="background-color: transparent;">Threat-modeling experience and command of common code and network vulnerability types, their impact, and remediation.</span></li><li class=""><span style="background-color: transparent;">Applied knowledge of cryptography, PKI, and TLS and their practical implementation.</span></li></ul><div><br></div><div><strong style="background-color: transparent; color: rgb(0, 0, 0);">Nice to have:</strong></div><ul><li class=""><span style="background-color: transparent;">Experience hardening LLM-integrated or AI-powered features in production.</span></li><li class=""><span style="background-color: transparent;">Experience operating a bug bounty program (e.g. HackerOne).</span></li><li class=""><span style="background-color: transparent;">Contributions to SOC 2 control design and audit readiness from the engineering side.</span></li><li class=""><span style="background-color: transparent;">Relevant certifications (e.g. OSCP, OSWE, AWS Security Specialty) – valued, but not a substitute for engineering ability.</span></li></ul><div><br></div><div><br></div><div><strong>Why join us?</strong></div><ul><li class=""><strong>We are mission-driven</strong>: we work collaboratively towards our shared vision of improving scientific communication and accelerating scientific discovery. BioRender figures have appeared in more than 54,000 publications! </li><li class=""><strong>BioRender is loved by millions!</strong> We have a world-class NPS and a community of loyal fans and users in 200+ countries!</li><li class=""><strong>Our company is backed by top investors</strong> and accelerators like Y Combinator, and we are on a growth trajectory comparable to many top-performing SaaS companies </li><li class=""><strong>We’re remote-first</strong> with team members across Canada and the U.S., offering you the flexibility to work from anywhere. </li></ul><div><br></div><div>BioRender is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.</div>
Apply Now