Build and lead Workleap's application security program, focusing on automating security review through agentic AI systems. You'll develop security guardrails for AI-assisted development, integrate SAST/DAST/SCA into CI/CD pipelines, and close the gap between rules engines and AI models for intelligent security analysis.
Five or more years in application security, DevSecOps, or security focused software development with engineering background
Deep working knowledge of web application security, OWASP Top 10, and CWE Top 25
Proven experience building security automation into CI/CD pipelines, GitHub Actions preferred
Built and shipped real agent tooling including MCP servers, Claude skills, subagents, and custom tools
Context engineering as a discipline for agent reasoning about codebases
Understanding of security model of agentic systems including prompt injection and tool permission scoping
Proficiency in Python for building tooling, not just scripting
Hands on experience with AI assisted and agentic development workflows
Solid grasp of Azure services, infrastructure security, and deployment patterns
Ability to explain risk tradeoffs to both engineers and executives effectively
Build security guardrails for AI assisted and agentic development so speed and safety stop being a tradeoff
Move security review from human bottleneck to automated first pass with human judgment for ambiguous cases
Achieve near-zero developer friction on security signals by wiring SAST/DAST/SCA into CI/CD with tuned noise levels
Lead threat modeling on new features and architectural changes
Drive real remediation of application security vulnerabilities measured by risk retired not tickets closed
Harden Azure environments and deployment patterns alongside Infrastructure SecOps
Write code as a hands on individual contributor
Partner closely with AI SDLC team and product engineering across the organization
You will join LeapSec and report to the Director of Infrastructure and Security
Small team with broad reach covering product security, cloud security, and governance across Workleap and ShareGate
Work ships end to end with real scope and autonomy
Hiring process includes recruiter call, virtual interview with hiring manager, take-home case study, and team discussion
AI supports certain hiring steps but every decision remains human
Annual bonus program and LTIP program for long-term growth sharing
Family health insurance, telemedicine, and annual wellness budget provided
In-person gathering twice a year with access to Montreal office
Claude access provided for everyone
135,482 – 227,700 USD
/ year
184,000 – 356,500 USD
/ year
170,000 – 190,000 USD
/ year
181,000 – 241,000 CAD
/ year
80,000 – 95,000 USD
/ year