anvil

anvil

Senior Application Security Engineer

Ottawa, Ontario, Canada · Senior · Full-time

Sponsorship not specified$125k-$165kDetected 18 days ago
PythonGoBashCode ReviewPostgreSQLElasticsearchGCPCloud PlatformsDockerKubernetesCI/CDDevOpsAPI DevelopmentKafkaOAuthMachine LearningCybersecurityPenetration TestingIncident ResponseComplianceAgileSupply ChainCustomer SupportResearch

About the role

  • You will embed security practices across the software development lifecycle and provide hands-on expertise in threat modeling, penetration testing, and secure deployment architecture.
  • ANVIL's products are primarily deployed in air-gapped, classified environments - which means the security decisions you make have real operational weight and must hold up without the safety net of perimeter-based cloud controls.
  • You will work closely with engineering teams to ensure that security is not an afterthought but an intrinsic quality of everything we ship.

Responsibilities

  • Assist the Director of Security Engineering in building and maturing ANVIL's application security program across all product lines and delivery mechanisms
  • Integrate and maintain AppSec tooling (SAST, DAST, SCA, container scanning, secrets detection) within CI/CD pipelines
  • Advise on and implement DevSecOps best practices across the full platform, ensuring security keeps pace with the speed of development
  • Lead threat modeling sessions for new and evolving system architectures using structured methodologies (STRIDE, PASTA, LUNDUN or equivalent)
  • Perform security architecture reviews at design and code review stages, identifying systemic risks before they reach production
  • Develop and maintain reusable threat libraries, security design patterns, and architecture guidance documents
  • Collaborate with engineering teams to validate that security controls address identified threats end-to-end
  • Partner with engineering leadership to incorporate security requirements into product roadmaps and sprint planning

Requirements

  • Bachelor's degree in Software Engineering, Computer Science, Cybersecurity, or a related technical field, or 10+ years of professional software or security engineering experience
  • Minimum of 7+ years of experience in application security, penetration testing, or security engineering roles
  • A minimum of 3+ years of hands-on experience with threat modeling methodologies (e.g., STRIDE, PASTA, LINDDUN, or Attack Trees)
  • A minimum of 3+ years of experience embedding security into CI/CD pipelines and secure SDLC practices
  • Demonstrated experience conducting application and infrastructure penetration tests and red team assessments in production or pre-production environments
  • Proven experience securing applications and infrastructure in air-gapped, on-premises, or classified deployment environments
  • Experience with GCP or equivalent cloud platform for dev/staging environment security
  • Expert knowledge of application security principles and secure development practices (OWASP Top 10, SANS CWE, NIST SSDF)
  • Expert knowledge of threat modeling techniques and architecture security review practices
  • Strong knowledge of penetration testing methodologies for web applications, APIs, and cloud environments

Nice to have

  • Relevant security certifications (OSCP, GWAPT, GWEB, CSSLP, CISSP, or equivalent)
  • Scripting and automation experience (Python, Go, Bash, Rust, or other)
  • Experience with red team tooling and adversary simulation frameworks (Metasploit, Cobalt Strike, Burp Suite Pro, or equivalent)
  • Experience with PostgreSQL, OpenSearch, and Elasticsearch security hardening
  • Stream processing security experience (Kafka, message brokers)
  • Experience with secret management platforms suited to air-gapped environments (HashiCorp Vault, OpenBoa, or equivalent on-premises solutions)
  • Bilingualism French/English
  • Experience working in or closely with defence, public safety, or national security organizations

Skills

  • Senior Application Security Engineer

Compensation

  • CAD $125,000 to $165,000 base salary - Placement within range based on experience and qualifications
  • As a Senior Application Security Engineer, you will be a cornerstone of ANVIL's security posture - reporting directly to the Director of Security Engineering and playing a key role in building out our application security program from the ground up.
  • You will embed security practices across the software development lifecycle and provide hands-on expertise in threat modeling, penetration testing, and secure deployment architecture.
  • ANVIL's products are primarily deployed in air-gapped, classified environments - which means the security decisions you make have real operational weight and must hold up without the safety net of perimeter-based cloud controls.
  • You will work closely with engineering teams to ensure that security is not an afterthought but an intrinsic quality of everything we ship.
  • Working alongside the Director of Security Engineering, you will help shape AppSec strategy, conduct architecture reviews, perform application and infrastructure penetration testing, and drive the maturation of our secure development practices.

Benefits

  • Establish and track security KPIs and provide regular reporting on program health to the Director of Security Engineering
  • Education & Experience

Company info

  • This is more than just a job; you'll be part of a team of dedicated professionals who share a common goal: to increase the safety and security of Western democracies through the effective use of data.
  • Our workplace is not just a job; it's a community of like-minded people working together to make a positive impact on the world we live in.

Visa & Work Authorization

  • Eligible candidates must either possess or be eligible to obtain a Government of Canada Secret or Top Secret security clearance

This listing is sourced directly from anvil's careers page and normalized into a canonical job model.