PB✓
PBridge

Full-time jobsCanada

Senior Application Security Engineer

hellofresh · Toronto, Ontario, Canada · Full-time

About this role

S'more about the team

We’re looking for a new teammate to join us on the journey of keeping HelloFresh a trusted name - someone with a passion for security and appetite for new challenges. Security Engineers work in a variety of ways to constantly iterate and improve HelloFresh’s security posture. 

You will be part of the squad responsible for maintaining and improving HelloFresh’s Vulnerability Management Program which provides umbrella coverage to Pentest, Red Teaming, Cloud Assessment, Source Code Review, use of vulnerable dependencies, Supply Chain Audits and Bug Bounty program.

Lettuce share what this role will be responsible for

• Perform network/cloud penetration, web and mobile application testing, source code reviews, threat analysis, wireless network assessments, and social-engineering assessments

• Develop comprehensive and accurate reports and presentations for both technical and executive audiences

• Effectively communicate findings and strategy to client stakeholders including technical staff, executive leadership, and legal counsel

• Use formal project management skills in planning, tracking, and reporting to close the remediation loop

• Recognize and safely utilize attacker tools, tactics, and procedures used to perform analysis and identify vulnerabilities

• Develop scripts, tools, or methodologies to improve HelloFresh's Vulnerability Management Program

Sound a-peeling? Here's what we're looking for

• 4-7 years' experience demonstrating above average ability in any 4 of the following areas of offensive security: Network, Wireless, Cloud, Web, Mobile, API Assessments, Source Code Review, Red Teaming, Social Engineering

• Thorough understanding of network protocols, data on the wire, client-server model, application design and architecture, and different classes of application security flaws

• Proven proficiency in one modern scripting language like Python or Go

• Relevant application penetration testing certifications such as Offensive Security Web Expert (OSWE) certification, GIAC Web Application Penetration Tester (GWAPT), or equivalent mobile/web certification

• Participation in web hacking challenges , competitions or bug bounties

• Development of tools or plugins used to conduct security testing and analysis

• Developing, extending, or modifying exploits , shellcode or exploit tools

• Source code review for control flow and security flaws

• Strong knowledge of tools used for cloud, wireless, web application, and network security testing

Let’s cut to the cheese, this is why you'll love it here

• Box Discount - Amazing discounts on 1 box per week! 75% discount on weekly HelloFresh and Chefs Plate meal kits AND 50% off weekly Factor meal box.

• Health & Wellness - Health & Dental benefits from day 1, a Health Spending Account, unlimited access to the Headspace app to meet your self-care needs, and 25% discount on GoodLife fitness memberships!

• Vacation & PTO - Time off is also an im

Tired of applying one by one?

Our Career Success Team finds roles in Canada that fit you, tailors your CV to each, and submits the applications — tracked end to end. You just show up to interviews.

We apply, you interview →