436,598open jobs
15,340companies
63,766added this week
Browse all
Salary
$108k – $220k per year (Estimated)
Location
Remote (Canada)
Seniority
Senior
Employment
Full-Time
Overview
Company
Impact
Profile match
BioRender is a Toronto software company founded in 2017 that helps scientists draw professional figures. Its library of accurate biological icons replaced the hours researchers spent assembling diagrams in generic drawing tools. The company is used by hundreds of thousands of scientists and by most major pharmaceutical firms.

At BioRender, we’re on a mission to accelerate the world’s ability to learn, discover, and communicate science - transforming how knowledge is shared and making science open, collaborative, and easily understandable by all.

We’re shaping the future of science communication and are looking for talented individuals to help bring this vision to life!

BioRender is seeking a Senior Application Security Engineer to join our Security team - an engineer first, who contributes directly to the codebase rather than managing security from the sidelines. You'll help define how security is built into our engineering organization, contributing production code across our application (Node.js/React/Python) and infrastructure (Python, Terraform, AWS, Cloudflare) while shaping secure-by-design patterns, CI/CD automation, and engineering workflows that let the company move quickly and safely.

You'll work AI-natively, using AI coding assistants and agentic tooling to accelerate your own work while helping secure the AI-powered capabilities we're building. If you're excited by building developer-friendly security systems, solving meaningful engineering problems, and focusing on the threats that actually matter, we'd love to hear from you.

What you'll do

Hands-on engineering & codebase contribution

  • Contribute production-quality code directly to the application (Node.js/React) and infrastructure (Python, Terraform) - you ship fixes and hardening yourself, not just findings for others to action.
  • Build and maintain security and CI/CD tooling for automation, keeping the secure path the default path.
  • Act as a security reviewer on RFCs and design documents, and pair with engineers to resolve issues at the source.

Architecture, design & secure SSDLC

  • Define secure-by-design patterns and drive standards for authentication, authorization, and API security.
  • Lead threat modeling on new and existing systems and turn those models into shipped controls.
  • Own and evolve the Secure SDLC and CI/CD security integration (SAST/DAST/SCA/secrets) - tuned for high signal and low noise.

AI-native security & automation

  • Work AI-natively: use AI coding assistants and agentic tooling to accelerate code review, triage, and tooling development.
  • Secure AI-integrated product features - reasoning about prompt injection, data leakage, and over-scoped tool, token, and data access.
  • Automate recurring security work so the team scales through leverage, not headcount.

Web & product security (active defense)

  • Perform penetration testing and code reviews (Node.js/React) using OWASP methodology.
  • Drive identification and remediation of application security vulnerabilities (SAST/DAST/HackerOne).
  • Own the bug bounty program end to end - issue evaluation, reproduction, and closing findings by shipping fixes.

What you bring

  • Demonstrable software engineering ability - you read code fluently, write production-quality code that engineers respect, and have contributed to real codebases (Node.js/React; Python a plus).
  • Fluency using AI development tools (AI coding assistants, agentic workflows) to get the job done, and a clear-eyed view of the security risks they introduce.
  • Expertise in web application security and secure-coding best practices, and the ability to review code and application findings.
  • Experience integrating and maintaining SAST/DAST systems within CI/CD, and with Secure Software Development Life Cycles.
  • Hands-on experience securing cloud workloads on AWS and comfort with infrastructure-as-code (Terraform or equivalent); familiarity with Cloudflare a plus.
  • Threat-modeling experience and command of common code and network vulnerability types, their impact, and remediation.
  • Applied knowledge of cryptography, PKI, and TLS and their practical implementation.

Nice to have:

  • Experience hardening LLM-integrated or AI-powered features in production.
  • Experience operating a bug bounty program (e.g. HackerOne).
  • Contributions to SOC 2 control design and audit readiness from the engineering side.
  • Relevant certifications (e.g. OSCP, OSWE, AWS Security Specialty) - valued, but not a substitute for engineering ability.

Why join us?

  • We are mission-driven: we work collaboratively towards our shared vision of improving scientific communication and accelerating scientific discovery. BioRender figures have appeared in more than 54,000 publications!
  • BioRender is loved by millions! We have a world-class NPS and a community of loyal fans and users in 200+ countries!
  • Our company is backed by top investors and accelerators like Y Combinator, and we are on a growth trajectory comparable to many top-performing SaaS companies
  • We’re remote-first with team members across Canada and the U.S., offering you the flexibility to work from anywhere.

BioRender is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
436,598 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$21k – $50k per year (Estimated) • Remote/Hybrid • Full-Time • 10+ years exp • Bachelor's Degree • Hyderabad
Python
Go
JavaScript
TypeScript
SQL
C#
C++
Scala
C#
ASP.NET Core
Entity Framework Core
gRPC for .NET
Databases
PostgreSQL
RabbitMQ
Apache Kafka
Azure Cosmos DB
Frontend
React.js
DevOps
Rest API
gRPC
Terraform
Azure
CI/CD
Docker
Kubernetes
Bicep
Azure AKS
Analytics
ETL/ELT
Apply
$23k – $65k per year (Estimated) • Remote/Hybrid • 2+ years exp • Hong Kong
JavaScript
TypeScript
SQL
Node JS
Databases
MS SQL
AI/ML
AI Agents
LLM
RAG
Agentic Workflows
Frontend
React.js
DevOps
Azure DevOps
Azure
Git
Configuration Management
Apply
$15k – $38k per year (Estimated) • Remote • Moscow
Python
JavaScript
SQL
Python
SQLAlchemy
FastAPI
Databases
PostgreSQL
Frontend
React.js
DevOps
Rest API
Git
Docker
QA
Pytest
Apply
$19k – $53k per year (Estimated) • In office • Bachelor's Degree • Moscow
Python
AI/ML
NLP
TensorFlow
Keras
OCR
DevOps
Git
Apply
$14k – $28k per year (Estimated) • Remote • 2+ years exp • Moscow
Python
SQL
Apply
$143k – $262k per year (Estimated) • Remote • Full-Time • 10+ years exp
AI/ML
Model Context Protocol
AI Agents
LLM
Agentic Workflows
DevOps
Terraform
Cybersecurity
GDPR
Apply
$84k – $171k per year (Estimated) • Remote • Full-Time
DevOps
Git
Platform Engineering
Cybersecurity
Okta
GDPR
Apply
$82k – $155k per year (Estimated) • Remote • Full-Time • 5+ years exp
Cybersecurity
GDPR
Apply
Remote • Full-Time
Cybersecurity
GDPR
Marketing
Salesforce
Zendesk
Apply
Remote • Full-Time
Cybersecurity
GDPR
Marketing
Salesforce
Zendesk
Apply
See all jobs
This is one of many
436,598 more open roles from verified company boards, updated every day.