Clio Logo

Clio

Application Security Developer

Posted 11 Days Ago
Be an Early Applicant
In-Office or Remote
Hiring Remotely in Vancouver, BC, CAN
Entry level
In-Office or Remote
Hiring Remotely in Vancouver, BC, CAN
Entry level
Perform offensive application security work: pentesting, exploit identification, threat modeling, vulnerability remediation guidance, automate scanning and static analysis, support incident response and forensics, research new attack vectors, and drive security education across engineering teams.
The summary above was generated by AI

Clio is the global leader in legal AI technology, empowering legal professionals and law firms of every size to work smarter, faster, and more securely. 

We are transforming the legal experience for all by bettering the lives of legal professionals while increasing access to justice.

Summary:

What your team does: 

We are currently seeking an Application Security Engineer to join our rapidly growing Security team. The Application Security team is responsible for emulating real-world adversaries to proactively discover, exploit, and help remediate critical security vulnerabilities across our applications. We provide a vital adversarial perspective, challenging our defences and partnering with development teams to eliminate flaws before they can be exploited.
This role is for someone who is passionate about building innovative solutions and being exposed to new challenges and technologies while making an impact. This role is available to candidates across Canada (excluding Quebec). If you are local to one of our hubs (Burnaby, Calgary, or Toronto), you will be expected to be in office a minimum of two days per week for our Anchor Days.

A day in the life might look like:
  • Write, review, debug, and implement tools to help developers avoid security flaws;

  • Build partnerships with development teams and advise on security best practices;

  • Contribute to collective developer education by driving security awareness and knowledge amongst the product organization;

  • Provide detailed guidance and support to teams in vulnerability remediation, and develop frameworks, guidelines, and systematic fixes for recurring vulnerabilities;

  • Resolve issues, navigate ambiguity, and maintain positive working relationships with researchers in our Bug Bounty program;

  • Identify and implement tools for automated application scanning, static analysis and related tools;

  • Perform penetration testing, and offensive campaigns against internal assets;

  • Perform reactive incident response and forensics when a security event occurs;

  • Perform proactive research to detect new attack vectors;

  • Elevate and educate our security culture within Clio, contributing to our cultural values;

What you may have:
  • Experience in Application or Product Security, with a focus on offensive security and penetration testing

  • Hands-on expertise identifying and exploiting complex vulnerabilities (e.g., SSRF, Deserialization, logic bypasses)

  • Proven ability to lead and conduct formal threat modeling sessions

  • Strong proficiency in at least one major programming language (e.g., Python, .NET, Ruby, JavaScript)

  • Experience securing applications in modern cloud environments (AWS, Azure, or GCP) 

  • Expertise with common application security tools and platforms (e.g., Burp Suite, SAST, SCA)

  • Experience with log aggregation and SIEM technologies

  • Ability to identify malicious behaviour and emerging threats via log analysis

  • Demonstrate a keen interest in improving your craft by using AI

Serious bonus points if you have:
  • Security certifications such as OSCP or OSWE

  • Active participation in the security community (e.g., presenting at conferences, contributing to open-source tools).

  • Experience with Ruby on Rails, Puppet, Kubernetes, Terraform, ELK (Elastic, Logtash and Kibana)

  • Strong AWS security experience on EC2 and managed services

  • Infrastructure security (WAF, ACLs, authentication, device hardening)

What you will find here:

Compensation is one of the main components of Clio’s Total Rewards Program. We have developed a series of programs and processes to ensure we are creating fair and competitive pay practices that form the foundation of our human and high-performing culture.
 

Some highlights of our Total Rewards program include:

  • Competitive, equitable salary with top-tier health benefits, dental, and vision insurance 

  • Hybrid work environment, with expectation for local Clions (Vancouver, Calgary, Toronto, Dublin, London, New York City and Sydney) to be in office min. twice per week. 

  • Flexible time off policy, with an encouraged 20 days off per year.

  • $2000 annual counseling benefit

  • RRSP matching and RESP contribution 

  • Clioversary recognition program with special acknowledgement at 3, 5, 7, and 10 years

The expected salary range for this role is $119,000 to $161,000 CAD. Initial placement within the range is informed by geographic region, experience, and skillset, with room to progress as impact and tenure grow. Final offer amounts will vary based on candidate profile.

Diversity, Inclusion, Belonging and Equity (DIBE) & Accessibility 

Our team shows up as their authentic selves, and are united by our mission. We are dedicated to diversity, equity and inclusion. We pride ourselves in building and fostering an environment where our teams feel included, valued, and enabled to do the best work of their careers, wherever they choose to log in from. We believe that different perspectives, skills, backgrounds, and experiences result in higher-performing teams and better innovation. We are committed to equal employment and we encourage candidates from all backgrounds to apply.

Clio provides accessibility accommodations during the recruitment process. Should you require any accommodation, please let us know and we will work with you to meet your needs.

Learn more about our culture at clio.com/careers

We're a Human and High Performing AI company, meaning we use artificial intelligence to improve all of our operations. In recruitment, AI helps us streamline the process for greater efficiency. However, we've built our systems to ensure that a human always reviews AI-generated output, and we never make automated hiring decisions.

Disclaimer: We only communicate with candidates through official @clio.com email addresses.

HQ

Clio Burnaby, British Columbia, CAN Office

Suite 300, 4611 Canada Way, Burnaby, BC, Canada, V6C 3E2

Clio Vancouver, British Columbia, CAN Office

Vancouver, Canada

Similar Jobs

6 Days Ago
Remote or Hybrid
Senior level
Senior level
Healthtech • Social Impact • Software
Build and advance application and product security across the engineering organization. Responsibilities include establishing secure defaults, CI guardrails, security requirements, threat modeling, risk assessments, penetration testing, vulnerability remediation, secure coding education, roadmap ownership, and hands-on code review. The role partners closely with product, engineering, DevOps, and services teams to secure applications, microservices, and AI features while enabling efficient development.
Top Skills: Ci/CdDastMicroservicesPenetration TestingSastSbomThreat Modeling
11 Days Ago
Remote
Canada
Senior level
Senior level
Information Technology • Software
Lead end-to-end application and product security for a Kubernetes-based multi-tenant platform. Perform deep security reviews of Go services, Kubernetes controllers, and frontends; lead threat modeling; integrate automated security checks into CI; manage vulnerability lifecycle; develop security-related features; and train developers on secure coding and attack vectors.
Top Skills: CiContainer Runtime SecurityGoGpuKubernetesMulti-CloudNvidia DgxPythonRbacVcluster
26 Days Ago
Easy Apply
Remote
Canada
Easy Apply
Senior level
Senior level
Artificial Intelligence • Enterprise Web • Information Technology • Productivity • Sales • Software • Database
Lead AppSec efforts across product, platform, and AI features by owning secure SDLC, performing threat modeling and deep code reviews, driving vulnerability management and remediation, building AppSec tooling and automations (including AI-assisted workflows), and enabling engineering teams with secure design guidance and training.
Top Skills: AIAi ApisBug BountyCryptographyCsrfDeserializationGCPLinuxOauthPentestingPythonRubySastScaSsrf

What you need to know about the Vancouver Tech Scene

Raincouver, Vancity, The Big Smoke — Vancouver is known by many names, and in recent years, it has gained a reputation as a growing hub for both tech and sustainability. Renowned for its natural beauty, the city has become a magnet for professionals eager to create environmental solutions, and with an emphasis on clean technology, renewable energy and environmental innovation, it's attracted companies across various industries, all working toward a shared goal: advancing clean technology.

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account