Senior Application Security Engineer
Ship security code, not just findings.
BioRender · Remote, USA/Canada
BioRender is the “Canva for science” — a platform empowering scientists to visually communicate their research. The company is profitable with $60M+ ARR and backed by Y Combinator and Dimension.
Join a 250-person team that moves like an early-stage startup but has real money in the bank. Every team uses AI daily, and you'll work with cutting-edge agentic tooling while securing products used by top pharma companies like Roche and AstraZeneca.
"As Senior AppSec Engineer you'll ship production code directly into the codebase — not just file findings. You'll define how security gets built into the engineering org and automate away manual security work so the team scales through leverage."
We are looking for a Senior Application Security Engineer with 6+ years of experience to join a small but high-impact security team and bring an engineering-first mindset to application security. You're someone who started as a software engineer or has always been hands-on with code — you read it fluently, write production-quality fixes, and ship them yourself rather than throwing findings over the fence.
You'll help automate away manual security work using AI-native tooling so the team can scale through leverage and focus on broader security architecture. This is a rare opportunity to shape how security is built into an engineering organization that's moving fast, innovating with AI, and serving highly regulated customers.
- Contribute production-quality code directly to the application (Node.js/Python) — shipping security fixes and hardening features yourself, not just filing tickets for engineers to action
- Build AI-powered automation to eliminate manual security work (e.g., PR analysis, vulnerability triage) so the team can scale faster and focus on higher-leverage architecture work
- Manage the HackerOne bug bounty program end-to-end — evaluating submissions, reproducing issues, and closing findings by shipping fixes
- Define secure-by-design patterns and drive security standards across the application architecture, including for AI-integrated product features
- Act as a security reviewer on RFCs and design documents, pairing with engineers to resolve issues at the source rather than blocking them
- 6–10 years of experience in application security engineering
- Cloud security experience (AWS preferred) or GRC/compliance knowledge
- Owned application-level security at a VC-backed startup
- Actively ships production security code — not just advisory
- Node.js and/or Python proficiency
- Uses AI coding assistants (Claude, Copilot, Codex) in daily workflow
- Located in Canada or USA; no visa sponsorship available
- Extensive experience shipping code as a traditional SWE at a strong company (FAANG or better), later converting to a security-focused SWE role at a startup with <1,000 employees
- Managed or contributed to a bug bounty program (e.g., HackerOne)
- Bachelor's degree in CS or related field
- Only big-tech experience — never worked at a company under 1,000 employees
- Pure GRC/audit/IT security background — doesn't write code
- Resistant to or unfamiliar with AI tooling in their workflow
Recruiter Screen (30 min)
30-minute introductory call covering background, motivations, AI setup, and role fit.
Hiring Manager Interview w/ Director of Engineering (30 min)
Conversational interview discussing experience, security philosophy, and team fit.
Coding Interview w/ Engineering Team (1 hr)
Technical coding exercise in Node.js or Python evaluating production-quality code skills.
Systems Design Interview w/ Engineering Team (1 hr)
Systems design and architecture discussion evaluating secure design thinking and threat modeling.
Work History Interview w/ Hiring Manager (1 hr)
Deep-dive walkthrough of career history, lessons learned, and growth trajectory.
Values Interview w/ Co-Founder (30 min)
Bar-raiser interview assessing cultural alignment and company values fit.
