Security Engineer
Your primary focus is proactive risk mitigation—partnering directly with development teams on threat modeling, security architecture reviews, and developer enablement rather than reactive firefighting.
Role : Senior AppSec Engineer - Remote / Canada
Hiring Company: Epik Solutions Assignment End Date: Dec 30, 2026 Work model: Remote Location requirement: Canada Pay Rate Range: CAD $55.00 - $65.00 (All inclusive, no benefits) with Epik Solutions
Interview stages: Two ThoughtWorks interviews + Two End Client interviews
Job Description:
About the Role As an Application Security Engineer (Secure Design & Architecture), you will embed security into every stage of the Software Development Life Cycle (SDLC) across web, mobile, and platform engineering teams. Your primary focus is proactive risk mitigation—partnering directly with development teams on threat modeling, security architecture reviews, and developer enablement rather than reactive firefighting. You will ensure that Peloton’s next-generation services, AI integrations, and microservices ecosystem are designed, built, and deployed with security and privacy at their core.
Key Responsibilities Security Design & Threat Modeling Architectural Reviews: Lead threat modeling and security architecture reviews for complex features across a diverse microservices ecosystem spanning Go, Node.js, TypeScript/Next.js, Python/Django, C#/.NET, and Rust.
Trust Boundaries & Emerging Tech: Analyze attack surfaces across internal APIs (REST, GraphQL), the Model Context Protocol (MCP) layer, and AI/LLM-integrated services.
Identity & Auth Architecture: Evaluate and refine OAuth 2.0 / OIDC implementations via Auth0, focusing on token issuance, scope design, redirect URI validation, client registration, and third-party integrations.
Developer Enablement & DevSecOps Tooling & Automation: Tune, operationalize, and integrate SAST, DAST, and SCA tooling into existing CI/CD workflows, triaging high-fidelity findings without creating friction for developers.
Secrets Management: Drive best practices for secrets hygiene, including automated rotation with AWS Secrets Manager, Kubernetes ExternalSecrets patterns, and pre-commit/PR credential scanning.
Vulnerability Management & Code Review Triage & Remediation: Prioritize and remediate vulnerabilities across Peloton’s attack surface, utilizing inputs from Cloudflare WAF/Bot Management, OWASP Top 10 indicators, and mobile security tools (iOS/Android).
Targeted Code Reviews : Perform deep-dive, hands-on code reviews in Go, TypeScript, and Python to provide clear, actionable remediation guidance for high-severity findings.
Required Qualifications & Skills Experience : 5+ years in Application Security, Security Architecture, or Software Engineering with an explicit security focus.
Identity & Authentication: Expert-level mastery of OAuth 2.0, OIDC, SAML, and JWT. Hands-on experience with Auth0 (or similar enterprise IdPs) in microservice architectures, as well as Cloudflare Access and Zero Trust patterns.
Posted July 31, 2026