anvil
Intermediate Application Security Engineer
Ottawa, Ontario, Canada · Mid · Full-time
Sponsorship not specified$105k-$145kDetected 19 days ago
PythonGoBashCode ReviewGitPostgreSQLElasticsearchGCPCloud PlatformsDockerKubernetesCI/CDLinuxMachine LearningCybersecurityIncident ResponseAgileCustomer SupportCommunicationCollaborationMentoring
About the role
- This is a hands-on, execution-focused role - you will be the person keeping our AppSec tooling running, our vulnerability SLAs on track, and our security gates functioning reliably across the software development lifecycle.
- You will operate across a diverse and technically demanding environment: ANVIL's products are primarily deployed in air-gapped, classified customer environments, while our development and demo infrastructure runs on GCP.
- You will need to be comfortable navigating both Linux and Windows systems and applying sound security judgment in contexts where external connectivity cannot be assumed.
Responsibilities
- Operate and maintain ANVIL's AppSec tooling suite, including SAST, DAST, SCA, container scanning, and secrets detection
- Support the onboarding of new repositories and services into existing AppSec tooling workflows
- Document tooling configurations, known issues, and operational runbooks to support team continuity
- Maintain and report on the vulnerability register, providing regular status updates on remediation progress
- Work collaboratively with development teams to unblock remediation efforts and validate fixes once deployed
- Threat Modeling Support
- Help maintain threat libraries and reusable security design pattern documentation as the program matures
- Develop familiarity with ANVIL's architecture and deployment patterns to contribute meaningfully to future threat modeling engagements
- Participate in code reviews and design discussions as a security contributor, flagging concerns and suggesting mitigations
- Support the enforcement of security review gates and assist developers in understanding and resolving security findings
Requirements
- Bachelor's degree in Software Engineering, Computer Science, Cybersecurity, or a related technical field, or equivalent practical experience
- 2-4 of years of experience in application security, security engineering, or a closely related role
- Demonstrated experience tracking, triaging, and driving remediation of security vulnerabilities in a development environment
- Familiarity with secure software development practices and at least one SDLC methodology
- Familiarity with Linux and Windows operating environments from a security perspective
- Familiarity with threat modeling methodologies (e.g., STRIDE, PASTA, LINDDUN, or Attack Trees)
- Experience with GCP or equivalent cloud platform for dev/staging environment security
- Working knowledge of application security principles and common vulnerability classes (OWASP Top 10, SANS CWE)
- Hands-on experience with one or more AppSec tooling categories: SAST, DAST, SCA, container scanning, or secrets detection
- Proven ability to triage vulnerability findings, assess exploitability and risk, and communicate remediation priorities clearly to development teams
Nice to have
- Relevant certifications or coursework (CompTIA Security+, eJPT, CEH, GWEB, or equivalent entry/intermediate security credentials)
- Scripting and automation experience (Python, Go, Bash, Rust, or other)
- Experience with PostgreSQL, OpenSearch, or Elasticsearch from a security or operations perspective
- Experience with vulnerability management platforms or risk registers
- Experience with secret management platforms suited to air-gapped environments (HashiCorp Vault, OpenBoa, or equivalent on-premises solutions)
- Bilingualism French/English
- Experience working in or closely with defence, public safety, or national security organizations
- AppSec Tooling & Pipeline Integration
Skills
- Intermediate Application Security Engineer
Compensation
- CAD $105,000 to $145,000 base salary - Placement within range based on experience and qualifications
- As an Intermediate Application Security Engineer, you will be an active contributor to ANVIL's growing application security program, working under the mentorship of our Senior Application Security Engineer and reporting to the Director of Security Engineering.
- This is a hands-on, execution-focused role - you will be the person keeping our AppSec tooling running, our vulnerability SLAs on track, and our security gates functioning reliably across the software development lifecycle.
- Role (Description)
- You will operate across a diverse and technically demanding environment: ANVIL's products are primarily deployed in air-gapped, classified customer environments, while our development and demo infrastructure runs on GCP.
- You will need to be comfortable navigating both Linux and Windows systems and applying sound security judgment in contexts where external connectivity cannot be assumed.
Benefits
- Participate in threat modeling sessions alongside the Senior Application Security Engineer, contributing findings and learning structured methodologies (STRIDE, PASTA, or equivalent)
- Education & Experience
Company info
- This is more than just a job; you'll be part of a team of dedicated professionals who share a common goal: to increase the safety and security of Western democracies through the effective use of data.
- Our workplace is not just a job; it's a community of like-minded people working together to make a positive impact on the world we live in.
Visa & Work Authorization
- Eligible candidates must either possess or be eligible to obtain a Government of Canada Secret or Top Secret security clearance
This listing is sourced directly from anvil's careers page and normalized into a canonical job model.