Role : Senior AppSec Engineer - Remote / Canada
Hiring Company: Epik Solutions
Assignment End Date: Dec 30, 2026
Work model: Remote
Location requirement: Canada
Pay Rate Range: CAD $55.00 - $65.00 (All inclusive, no benefits) with Epik Solutions
Interview stages: Two ThoughtWorks interviews + Two End Client interviews
Job Description:
About the Role
As an Application Security Engineer (Secure Design & Architecture), you will embed security into every stage of the Software Development Life Cycle (SDLC) across web, mobile, and platform engineering teams.
Your primary focus is proactive risk mitigation—partnering directly with development teams on threat modeling, security architecture reviews, and developer enablement rather than reactive firefighting. You will ensure that Peloton’s next-generation services, AI integrations, and microservices ecosystem are designed, built, and deployed with security and privacy at their core.
Key Responsibilities
Security Design & Threat Modeling
Architectural Reviews: Lead threat modeling and security architecture reviews for complex features across a diverse microservices ecosystem spanning Go, Node.js, TypeScript/Next.js, Python/Django, C#/.NET, and Rust.
Trust Boundaries & Emerging Tech: Analyze attack surfaces across internal APIs (REST, GraphQL), the Model Context Protocol (MCP) layer, and AI/LLM-integrated services.
Identity & Auth Architecture: Evaluate and refine OAuth 2.0 / OIDC implementations via Auth0, focusing on token issuance, scope design, redirect URI validation, client registration, and third-party integrations.
Developer Enablement & DevSecOps
Tooling & Automation: Tune, operationalize, and integrate SAST, DAST, and SCA tooling into existing CI/CD workflows, triaging high-fidelity findings without creating friction for developers.
Secrets Management: Drive best practices for secrets hygiene, including automated rotation with AWS Secrets Manager, Kubernetes ExternalSecrets patterns, and pre-commit/PR credential scanning.
Vulnerability Management & Code Review
Triage & Remediation: Prioritize and remediate vulnerabilities across Peloton’s attack surface, utilizing inputs from Cloudflare WAF/Bot Management, OWASP Top 10 indicators, and mobile security tools (iOS/Android).
Targeted Code Reviews: Perform deep-dive, hands-on code reviews in Go, TypeScript, and Python to provide clear, actionable remediation guidance for high-severity findings.
Required Qualifications & Skills
Experience: 5+ years in Application Security, Security Architecture, or Software Engineering with an explicit security focus.
Identity & Authentication: Expert-level mastery of OAuth 2.0, OIDC, SAML, and JWT. Hands-on experience with Auth0 (or similar enterprise IdPs) in microservice architectures, as well as Cloudflare Access and Zero Trust patterns.
Polyglot Code Literacy: Strong ability to read and perform security reviews across at least two of the following: Go, TypeScript, Python, or C#. Must be capable of identifying business logic flaws, auth misconfigurations, and injection vectors independently.
API Security Depth: Strong command of REST and GraphQL security, schema authorization, batching attack mitigation, introspection protection, and injection prevention.
CI/CD & Supply Chain Security: Hands-on experience securing GitHub Actions pipelines, self-hosted/ephemeral runners, dependency pinning, and software supply chain integrity.
Edge & Network Security: Practical knowledge of Cloudflare edge products (WAF, Bot Management, DLP, CASB) and their interactions with origin infrastructure.
Preferred Qualifications
AI & LLM Security: Experience securing AI/LLM integrations, including mitigations for prompt injection, tool-call abuse, and credential leakages via agent frameworks (e.g.,
AWS Bedrock, MCP protocol).
Mobile Security: Familiarity with iOS and Android security controls, secure enclave storage, certificate pinning, and binary hardening techniques.
Pay: $55.00-$65.00 per hour
Work Location: Remote