This job has expired

This job posting is no longer active and is not accepting applications. Explore similar roles below!

HelloFresh
Posted 2mo ago

Application Security Engineer

HelloFresh
Toronto, Ontario, Canada
$105-$115/yrHybridFull Time
Responsibilities
  • improving security
  • securing containers
  • conducting reviews
Requirements
  • Proficiency in Python or Go
  • 2+ years security experience
  • Exposure to Terraform
  • Docker
  • Container management, CI/CD, and secrets management
  • Experience designing security controls
  • Familiarity with agile, Jira, and Slack
Technical tools mentioned
PythonGoTerraformDockerCI/CDJiraSlack

Job description

S'more about the team

We’re looking for a new teammate to join us on the journey of keeping HelloFresh a trusted name - someone with a passion for security and appetite for new challenges. Security Engineers work in a variety of ways to constantly iterate and improve HelloFresh’s security posture. 

You will be the first port of call for responding to any of HelloFresh’s security related questions and concerns. You will also develop and deliver tools and processes to enable colleagues to achieve their goals and objectives.

Lettuce share what this role will be responsible for

  • Improve the application security function at HelloFresh to harden the apps & services against abuse and nefarious activity
  • Secure containers, CI/CD pipelines and implement guardrails for the developers aligned with the DevSecOps principles
  • Conduct design, RFC and code reviews.
  • Mentor and train the devs following the shift-left approach through the Security Champion program.
  • Develop practices and processes to help us scale further securely through automated workflows.

Sound a-peeling? Here's what we're looking for

  • Proven proficiency in one modern scripting language like Python or Go
  • 2-3 years experience in the security domain
  • Decent exposure to Terraform, Docker, container mgmt. services, CI/CD and secrets management in microservices-based architectures
  • Experience in designing and implementing security controls specific to modern dev and deployment stack
  • Strong knowledge of agile methodologies and modern collaboration tools like Jira, Slack
  • Enthusiasm and passion for security and automation

A skeptical, data driven mindset that is eager to go under the hood in the face of challenges

Let’s cut to the cheese, this is why you'll love it here

  • Box Discount - Amazing discounts on 1 box per week! 75% discount on weekly HelloFresh and Chefs Plate meal kits AND 50% off weekly Factor meal box.
  • Health & Wellness - Health & Dental benefits from day 1, a Health Spending Account, unlimited access to the Headspace app to meet your self-care needs, and 25% discount on GoodLife fitness memberships!
  • Vacation & PTO - Time off is also an important part of self-care! We offer generous vacation and PTO to help you create a good work-life balance. 
  • Family Benefits - A parental leave top-up program for expectant parents.
  • Growth & Development - We support your career progression and invest in your continued learning through experiences and initiatives owned by our dedicated L&D team
  • Work Hard & Have Fun - From team socials to engaging company days, you’ll have plenty of opportunity to experience the fun!
  • Diversity & Inclusion Initiatives - With impactful ERG’s like FreshPride, Women Empowered and LIMES, we are committed to our diversity, equity & inclusion efforts.
  • Food Puns - this one is kind of a big dill if you haven’t already noticed. We even have some punny meeting room names!

Flexible Hybrid Approach

At HelloFresh, we know that flexible work arrangements are essential in enabling you to do your best work, while balancing your personal and life needs. Offering remote work flexibility, along with the opportunity to interact and collaborate in the office are all a part of creating a great employee experience. 

To meet these needs, we are pleased to provide Flexible Hybrid work. Flexible Hybrid is a people-first approach that is based on choice, trust, personalization, and empowers teams to choose when and how often they work from the office and work from home, in addition to team days and company days. This means a minimum of 2 days in office per week, with most teams in office between 2-3 days a week.

#LI-HYBRID

HelloFresh Canada uses AI-integrated technology to help us process and evaluate applications more efficiently. This includes tools that screen and assess candidate qualifications based on the requirements for this role. While these tools assist our workflow, all final selection decisions are made by our hiring team.

This is a posting for an existing vacancy. We are actively seeking to fill this position.

Toronto, ON Pay Range
$104.74$114.74 CAD

About HelloFresh

Global meal kit delivery service and food solutions provider.

Similar jobs

Application Security Engineer roles near Toronto, Ontario
2d
Save
Mark Applied
Hide
Ingénieur(e) sécurité applicative - Cybersécurité - Toulouse
Colomiers or Toulouse or Toronto or Singapore
HybridFull Time
Sopra Steria
Sopra SteriaEuronext Paris: SOPR: Provides digital transformation consulting and information technology services.
6+ YOEEngineering or university-equivalent degree and at least 6 years in application security; experience with security projects, governance, DevSecOps tools, programming languages, security frameworks, and fluent written and spoken English.
Java, .Net, JavaScript, Angular, GitLab, Jenkins, Checkmarx, Sysdig, HashiCorp Vault, Kubernetes, OWASP, OWASP Top Ten, MITRE ATT&CK, SAMM, ASVS, NIST
3d
Save
Mark Applied
Hide
Senior Application Security Engineer
Toronto or London or New York City or Pune
OnsiteFull Time
TripleLift
TripleLift: Programmatic advertising platform for high-quality digital ad experiences.
5+ YOERequires 5+ years in application security or security engineering, secure coding, SAST/DAST/SCA, CI/CD security, penetration testing, threat modeling, AWS security, and cybersecurity frameworks.
GitHub Advanced Security, SAST, DAST, SCA, CodeQL, Burp Suite, OWASP ZAP, Snyk, Checkmarx, Veracode, CI/CD, Python, Java, TypeScript, Go, NIST CSF, PCI, SOC2, HITRUST, ISO 27001/2, AWS, IAM, VPC, KMS, GuardDuty, CloudTrail, Claude
4d
Save
Mark Applied
Hide
Senior Application Security Engineer II
Toronto, Ontario, Canada
$180k-$220k/yr HybridFull Time
Relay
Relay: Digital banking and cash flow management for small businesses.
5+ YOERequires 5–6 years of professional security experience, production software development, application security or penetration testing expertise, OWASP Top 10 knowledge, AI tooling experience, communication, ownership, and mentoring skills.
TypeScript, Node.js, Postgres, AWS, Datadog, Burp Suite, Claude Code, Cursor, Hack The Box, Google Meet, OWASP Top 10, SBOM, SCA, Certn
2w
Save
Mark Applied
Hide
Application Security Engineer - ADR
Quincy or Toronto or Austin or Atlanta
$120k-$203k/yr OnsiteFull Time
State Street
State StreetNYSE: STT: Provides investment servicing and management to institutional investors.
6+ YOEHands-on experience with application security, ADR/RASP/WAAP, SAST/DAST/SCA, cloud (Azure/AWS), DevSecOps, secure SDLC, threat detection, incident response, and relevant security certifications.
Java, .NET, Python, Node.js, Azure, AWS, SAST, DAST, SCA, API Security, Container Security, Runtime Application Self-Protection (RASP), Web Application and API Protection (WAAP), Ansible, Terraform, Kubernetes, Infrastructure as Code (IaC), Agile, DevOps
1mo
Save
Mark Applied
Hide
Application Security Developer
Toronto or Vancouver or Calgary or Canada
$117k-$158k/yr HybridFull Time
Clio
Clio: Cloud-based legal practice management software and AI solutions.
Experience in application/product security and offensive testing, vulnerability identification and remediation, threat modeling, proficiency in at least one language (Python, .NET, Ruby, JavaScript), cloud security (AWS/Azure/GCP), and common app-security tools.
Python, .NET, Ruby, JavaScript, AWS, Azure, GCP, Burp Suite, SAST, SCA, SIEM, ELK, Ruby on Rails, Puppet, Kubernetes, Terraform, Elastic, Logtash, Kibana
1mo
Save
Mark Applied
Hide
Application Security Engineer
Toronto, Ontario, Canada
HybridFull Time
Opendoor
OpendoorNASDAQ: OPEN: Online platform for buying and selling residential real estate.
5+ YOE5+ years application security or security-focused software engineering; strong in Python, Go, TypeScript, or Ruby; experience with AppSec tooling (GitHub Advanced Security, Semgrep, HackerOne, Burp); cloud and Kubernetes security experience; practical threat modeling skills.
Go, Python, TypeScript, Ruby, Terraform, AWS, GCP, Azure, Kubernetes, Apollo GraphQL, GitHub Advanced Security, CodeQL, Dependabot, Semgrep, HackerOne, Burp Suite, Cloudflare WAF, Claude, OpenAI, MCP, GitHub, Linear, Slack
1mo
Save
Mark Applied
Hide
Application Security Engineer
Toronto, Ontario, Canada
HybridFull Time
Opendoor
OpendoorNASDAQ: OPEN: Digital marketplace for buying and selling residential real estate.
5+ YOE5+ years application security or security-focused software engineering; hands-on with Go/Python/TypeScript/Ruby; experience with AppSec toolchains, cloud/Kubernetes security, threat modeling, and automation.
Go, Python, TypeScript, Ruby, Terraform, AWS, GCP, Azure, Kubernetes, Apollo GraphQL, GitHub Advanced Security (CodeQL, Dependabot, secret scanning), Semgrep, HackerOne, Burp Suite, Cloudflare WAF, Claude, OpenAI, MCP
3mo
Save
Mark Applied
Hide
Senior Application Security Developer , AI Security
Toronto, Ontario, Canada
$101k-$149k/yr HybridFull Time
Autodesk
AutodeskNASDAQ: ADSK: Developing software for architecture, engineering, and entertainment industries.
5+ YOE5+ years in application security; strong OWASP knowledge; secure development practices; experience with AI/LLM security; scripting programming; CI/CD integration; clear communication.
Python, JavaScript, Go, Cursor, Claude, CI/CD, LLM, AI Security
This job has expired