Job Opportunities API

The Public Ledger of Openings

← Back to the ledger

Principal Application Security Specialist

Relay
CompanyRelay
CategoryEngineering
LocationVancouver
RemoteOn-site (inferred)
EmploymentNot stated
LevelSenior
SalaryNot stated by the employer
Posted13 Jul 2026
Last verified30 Jul 2026
SourceEmployer career page (greenhouse)
Applications are handled by the employer, not by us.Apply on the employer's site →
Description
Who we are: For over 25 years, Global Relay has set the standard in enterprise information archiving with industry-leading cloud archiving, surveillance, eDiscovery, and analytics solutions. We securely capture and preserve the communications data of the world’s most highly regulated firms, giving them greater visibility and control over their information and ensuring compliance with stringent regulations. Though we offer competitive compensation and benefits and all the other perks one would expect from an established company, we are not your typical technology company. Global Relay is a career-building company. A place for big ideas. New challenges. Groundbreaking innovation. It’s a place where you can genuinely make an impact – and be recognized for it. We believe great businesses thrive on diversity, inclusion, and the contributions of all employees. To that end, we recruit candidates from different backgrounds and foster a work environment that encourages employees to collaborate and learn from each other, completely free of barriers. Your role: The Principal Application Security Specialist is the most senior individual contributor across Global Relay's Software & Application Security function. Combining deep application security testing mastery with DevSecOps leadership, you set the technical direction for how Global Relay tests the security of its applications and for how security is engineered into the software development lifecycle. You lead the most complex and novel assessments, define testing methodology and standards, and drive the integration of automated security controls into CI/CD pipelines. You act as the organization’s authority on application, mobile and AI/LLM security, and partner with engineering, platform and product leadership so that security is built in and aligned with business objectives. Your responsibilities: Testing & methodology leadership Collaborate with the Team Lead, Application & Software Security to develop and own the application security testing methodology and standards across web, API, mobile and AI/LLM domains. Lead the most complex, novel and high-risk security assessments, including original research and the development of new testing techniques and tooling. Own the organization-wide triage, escalation and evidence-quality framework across all security testing and scanning functions and define how L1–L3 teams are trained and measured against it. Support the direction for the penetration testing and offensive security program. Own the most advanced threat modelling for critical and cross-cutting architecture. Serve as the organization's authority and final technical escalation point for application security. DevSecOps & secure SDLC Drive the integration of security into the SDLC and CI/CD pipelines, championing a proactive, risk-based, “shift-left” approach. Develop the organization-wide standards for remediation verification, retest evidence and release closure, ensuring security gating is consistently and appropriately applied across all release pipelines. Design and deploy an automated security framework for robust tooling and processes, using scripting and open-source solutions. Collaborate with Engineering for the selection, deployment and management of security scanning tools (SAST, DAST, SCA, container) within CI/CD pipelines, integrating them via APIs and plugins using agile delivery methods. Serve as the liaison for DevSecOps standards and provide input into new standards and policies. Review and analyze vulnerability data to identify risk across applications, infrastructure and network, and manage false positives. Set the organization's standards for root-cause analysis and remediation guidance on the most complex or systemic security defects and define how remediation quality is assessed across teams. Influence, measurement & people Define how testing coverage, quality an
HOUSE ADYou found the opening. Now track it.Tracker, radar and AI drafts in one place.erioun.com →