Senior Application Security Engineer · Remote (USA/Canada) – BioRender
Application Security · Engineering-First

Senior Application Security Engineer
Ship security code, not just findings.

BioRender · Remote, USA/Canada

Remote — USA or Canada Full-time · Remote $150,000 – $230,000 + Equity Profitable · $60M+ ARR · ~250 employees

BioRender is the “Canva for science” — a platform empowering scientists to visually communicate their research. The company is profitable with $60M+ ARR and backed by Y Combinator and Dimension.

Join a 250-person team that moves like an early-stage startup but has real money in the bank. Every team uses AI daily, and you'll work with cutting-edge agentic tooling while securing products used by top pharma companies like Roche and AstraZeneca.

"As Senior AppSec Engineer you'll ship production code directly into the codebase — not just file findings. You'll define how security gets built into the engineering org and automate away manual security work so the team scales through leverage."

We are looking for a Senior Application Security Engineer with 6+ years of experience to join a small but high-impact security team and bring an engineering-first mindset to application security. You're someone who started as a software engineer or has always been hands-on with code — you read it fluently, write production-quality fixes, and ship them yourself rather than throwing findings over the fence.

You'll help automate away manual security work using AI-native tooling so the team can scale through leverage and focus on broader security architecture. This is a rare opportunity to shape how security is built into an engineering organization that's moving fast, innovating with AI, and serving highly regulated customers.

  • Contribute production-quality code directly to the application (Node.js/Python) — shipping security fixes and hardening features yourself, not just filing tickets for engineers to action
  • Build AI-powered automation to eliminate manual security work (e.g., PR analysis, vulnerability triage) so the team can scale faster and focus on higher-leverage architecture work
  • Manage the HackerOne bug bounty program end-to-end — evaluating submissions, reproducing issues, and closing findings by shipping fixes
  • Define secure-by-design patterns and drive security standards across the application architecture, including for AI-integrated product features
  • Act as a security reviewer on RFCs and design documents, pairing with engineers to resolve issues at the source rather than blocking them
Required
  • 6–10 years of experience in application security engineering
  • Cloud security experience (AWS preferred) or GRC/compliance knowledge
Must-Have
  • Owned application-level security at a VC-backed startup
  • Actively ships production security code — not just advisory
  • Node.js and/or Python proficiency
  • Uses AI coding assistants (Claude, Copilot, Codex) in daily workflow
  • Located in Canada or USA; no visa sponsorship available
👍 Nice to Have
  • Extensive experience shipping code as a traditional SWE at a strong company (FAANG or better), later converting to a security-focused SWE role at a startup with <1,000 employees
  • Managed or contributed to a bug bounty program (e.g., HackerOne)
  • Bachelor's degree in CS or related field
Traits to Avoid
  • Only big-tech experience — never worked at a company under 1,000 employees
  • Pure GRC/audit/IT security background — doesn't write code
  • Resistant to or unfamiliar with AI tooling in their workflow
Node.js Python Terraform AWS HackerOne
1

Recruiter Screen (30 min)

30-minute introductory call covering background, motivations, AI setup, and role fit.

2

Hiring Manager Interview w/ Director of Engineering (30 min)

Conversational interview discussing experience, security philosophy, and team fit.

3

Coding Interview w/ Engineering Team (1 hr)

Technical coding exercise in Node.js or Python evaluating production-quality code skills.

4

Systems Design Interview w/ Engineering Team (1 hr)

Systems design and architecture discussion evaluating secure design thinking and threat modeling.

5

Work History Interview w/ Hiring Manager (1 hr)

Deep-dive walkthrough of career history, lessons learned, and growth trajectory.

6

Values Interview w/ Co-Founder (30 min)

Bar-raiser interview assessing cultural alignment and company values fit.