368,611open jobs
9,439companies
50,719added this week
Browse all
Salary
$121k – $247k per year (Estimated)
Location
Remote (Canada)
Seniority
Staff · 5+ years exp
Overview
Company
Impact
Profile match
Workleap is a company that provides an integrated platform designed to improve the employee experience by focusing on engagement, performance, and development. Their suite of products includes Officevibe, Pingboard, and various Learning Management Systems (LMS) that help businesses tackle challenges like hybrid work, onboarding, professional development, and performance management. Workleap aims to create happier and more productive workplaces by making it easier for HR teams to manage and enhance their HR strategies.

Company Description

Workleap is a Montreal-based tech company, founded in 2006. We're builders at heart, we make simple products that actually matter to the people who use them. We have two product lines: Workleap Agent, our newest solution built to make every manager more effective, and ShareGate, the world's leading solution for Microsoft 365 migration and governance. More than 15,000 companies worldwide trust us to do exactly that. We're intentional about who joins us. If you're the kind of person who gets excited by a hard problem and wants to help shape what comes next, there's a place for you here.

Your role

You will build the security layer for how Workleap writes software, and then you will teach it to run itself.

Today that means the traditional stack done properly. SAST, DAST, SCA, and secret scanning wired into GitHub Actions so findings land where developers already work, with the noise tuned out rather than tolerated. Threat modeling on architectural changes. Vulnerability intake and triage that closes the loop instead of filling a backlog.

Where it goes next is the actual reason this role exists. We are moving toward agentic security review, where agents perform the first pass on every pull request, reason about the change in context, and escalate what matters to a human. Nobody has fully solved this. Rules engines miss intent, models hallucinate findings, and the gap between the two is where the interesting work is. You will close that gap, and you will decide how much trust the system earns at each step.

You will be a hands on individual contributor. You will write the code.

Your impact: 

  • Build the security guardrails for AI assisted and agentic development so speed and safety stop being a tradeoff
  • Move security review from human bottleneck to automated first pass with human judgment reserved for what is genuinely ambiguous
  • Achieve near-zero developer friction on security signals by wiring SAST/DAST/SCA into CI/CD with noise tuned low enough that findings actually get fixed.
  • Lead threat modeling on new features and architectural changes
  • Drive real remediation of application security vulnerabilities, measured by risk retired and not tickets closed
  • Harden Azure environments and deployment patterns alongside Infrastructure SecOps

Your team

You will join LeapSec and report to the Director of Infrastructure and Security. We're a small team with broad reach covering product security, cloud security, and governance across Workleap and ShareGate. That means your work ships, you own it end to end, and you set the priorities that matter. The scope is real, and so is the autonomy that comes with it.

You will partner closely with the AI SDLC team, which builds the internal platform that lets AI agents operate across the development lifecycle, and with product engineering across the organization.

What you'll bring

  • Five or more years in application security, DevSecOps, or security focused software development, with a real engineering background behind it
  • Deep working knowledge of web application security, OWASP Top 10, and CWE Top 25
  • Proven experience building security automation into CI/CD pipelines, GitHub Actions preferred
  • Built and shipped real agent tooling, not just used it. MCP servers, Claude skills, subagents, and custom tools that other people depend on
  • Context engineering as a discipline. Knowing what an agent needs in front of it to reason correctly about a codebase, and what to leave out
  • Understanding of the security model of agentic systems themselves. Prompt injection, tool permission scoping, credential handling in agent workflows, and what an agent with repo write access can do when it is wrong
  • Proficiency in Python for building tooling, not just scripting around it
  • Hands on experience with AI assisted and agentic development workflows and a clear view of where they break
  • Solid grasp of Azure services, infrastructure security, and deployment patterns
  • The ability to explain a risk tradeoff to an engineer and to an executive in the same week and be understood by both

Strong assets

  • Secure code review experience in C#/.NET
  • Experience integrating SAST, DAST, SCA, and secret scanning at scale
  • Familiarity with OIDC, SAML, and OAuth
  • Exposure to SOC2 requirements
  • Experience running vulnerability discovery and triage with a developer community

What the job comes with

  • Annual bonus program.
  • LTIP program, share in Workleap's long-term growth.
  • RRSP + Family health insurance + telemedicine + annual wellness budget.
  • Flexible vacation policy.
  • Remote work, with access to our Montreal office.
  • In-person gathering twice a year.
  • Claude access, for everyone.

What drives us

At Workleap, we build software that sits at the center of how people experience work, every day, at every level.

We move fast. Priorities shift, decisions get made with the information we have, and we iterate. If you thrive on intensity and ambiguity doesn't slow you down, you'll feel right at home.

We're builders. We do what it takes to move forward. AI is part of our toolkit. We use it to go faster and decide smarter, not to replace judgment.

If you want real impact and a place where your decisions matter, this is it.

How we hire 

Transparency is how we hire - for you as much as for us.

Here's how it works: a first call with a recruiter, then a virtual interview with the hiring manager. You'll then complete a take-home case study, followed by a meet with future colleagues to discuss it together. Depending on the role, the process may vary slightly - your recruiter will walk you through it on your first call.

We use AI to support certain steps of the process, but every hiring decision remains human.

We can't wait to meet you.

By applying, you confirm that you have read and agree to our privacy policy.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,611 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
In your city
$25k – $42k per year • Equity 0–0.2% • Remote • Full-Time • 3+ years exp
Bash
Go
JavaScript
Python
TypeScript
DevOps
AWS
Azure
CI/CD
Datadog
Docker
GCP
GitHub Actions
GitLab CI
Grafana
Incident Management
Kubernetes
Platform Engineering
Prometheus
Terraform
Amazon CloudWatch
GitHub
GitLab
IAM
Cybersecurity
Least Privilege
Apply
$100k – $210k per year • Equity 0–0.5% • Remote • Full-Time • 3+ years exp • San Francisco
Bash
Go
JavaScript
Python
TypeScript
DevOps
AWS
Azure
CI/CD
Datadog
Docker
GCP
GitHub Actions
GitLab CI
Grafana
Incident Management
Kubernetes
Platform Engineering
Prometheus
Terraform
Amazon CloudWatch
GitHub
GitLab
IAM
Cybersecurity
Least Privilege
Apply
$100k – $200k per year • Equity 0.5–5% • In office • Full-Time • 1+ year exp • New York
Python
TypeScript
JavaScript
Python
FastAPI
Databases
DynamoDB
PostgreSQL
AI/ML
Claude
LLM
OpenAI
AI Agents
Frontend
Next.js
Tailwind CSS
React.js
DevOps
AWS
Docker
Vercel
GitHub
Management
Slack
Apply
$19k – $28k per year (net) • Remote • Full-Time • Moscow
C#
C++
C++
CMake
DevOps
CI/CD
Git
Management
Jira
Slack
Apply
$230k – $300k per year • Equity 0.1–0.2% • In office • Full-Time • 3+ years exp • PhD • New York
TypeScript
Databases
PostgreSQL
AI/ML
AI Agents
Claude
Claude Code
Cursor
Devin
OpenAI Codex
Frontend
Next.js
tRPC
DevOps
Platform Engineering
Vercel
Apply
$121k – $247k per year (Estimated) • Remote • Full-Time • 5+ years exp • Montreal
C#
Python
AI/ML
AI Agents
Claude
Context Engineering
LLM Guardrails
Model Context Protocol
DevOps
Azure
CI/CD
GitHub Actions
GitHub
Cybersecurity
CWE
OWASP Top 10
SOC 2
Threat Modeling
Apply
$96k – $189k per year (Estimated) • Remote • 5+ years exp
C#
TypeScript
JavaScript
C#
.NET
AI/ML
Claude
Copilot
Frontend
React.js
DevOps
Azure
GitHub
Cybersecurity
Microsoft Entra ID
Apply
See all jobs
This is one of many
368,611 more open roles from verified company boards, updated every day.