JobsBackendApplication Security Manager
Workleap

Workleap

·

Backend

Application Security Manager

RemoteSeniorPosted Aug 17, 2026
PythonAzureGitHub ActionsCI/CDLLMsLangChainC#.NET+16 more

About this role

Build and lead Workleap's application security program, focusing on automating security review through agentic AI systems. You'll develop security guardrails for AI-assisted development, integrate SAST/DAST/SCA into CI/CD pipelines, and close the gap between rules engines and AI models for intelligent security analysis.

Must have

Five or more years in application security, DevSecOps, or security focused software development with engineering background

Deep working knowledge of web application security, OWASP Top 10, and CWE Top 25

Proven experience building security automation into CI/CD pipelines, GitHub Actions preferred

Built and shipped real agent tooling including MCP servers, Claude skills, subagents, and custom tools

Context engineering as a discipline for agent reasoning about codebases

Understanding of security model of agentic systems including prompt injection and tool permission scoping

Proficiency in Python for building tooling, not just scripting

Hands on experience with AI assisted and agentic development workflows

Solid grasp of Azure services, infrastructure security, and deployment patterns

Ability to explain risk tradeoffs to both engineers and executives effectively

Technologies

Python.NETAzureC#GitDockerRESTLinuxTerraformJSONGitHubOAuthOpen sourceAIKubernetesCI/CDLLMsLangChainPrompt engineeringSAMLOIDCGitHub ActionsMCP serversClaude

Responsibilities

Build security guardrails for AI assisted and agentic development so speed and safety stop being a tradeoff

Move security review from human bottleneck to automated first pass with human judgment for ambiguous cases

Achieve near-zero developer friction on security signals by wiring SAST/DAST/SCA into CI/CD with tuned noise levels

Lead threat modeling on new features and architectural changes

Drive real remediation of application security vulnerabilities measured by risk retired not tickets closed

Harden Azure environments and deployment patterns alongside Infrastructure SecOps

Write code as a hands on individual contributor

Partner closely with AI SDLC team and product engineering across the organization

Benefits

RRSP and 401k matchHealth insuranceCompetitive salary and stock option planWellness allowanceFlexible vacation timeRemote workProfessional development

Amenities

Remote work with access to Montreal officeIn-person gathering twice a yearClaude access for everyone

Recruitment process

1

You will join LeapSec and report to the Director of Infrastructure and Security

2

Small team with broad reach covering product security, cloud security, and governance across Workleap and ShareGate

3

Work ships end to end with real scope and autonomy

4

Hiring process includes recruiter call, virtual interview with hiring manager, take-home case study, and team discussion

5

AI supports certain hiring steps but every decision remains human

6

Annual bonus program and LTIP program for long-term growth sharing

7

Family health insurance, telemedicine, and annual wellness budget provided

8

In-person gathering twice a year with access to Montreal office

9

Claude access provided for everyone