Sardine

Senior Application Security Engineer

Canada

CA$175,000 – CA$215,000Compensation
Senior (5 to 8 years), Expert & Leadership (9+ years)Experience Level
Full TimeJob Type
UnknownVisa
Fraud Prevention, AML Compliance, Fintech, Banking, RetailIndustries

About Sardine

We are a leader in fraud prevention and AML compliance. Our platform uses device intelligence, behavior biometrics, machine learning, and AI to stop fraud before it happens. Today, over 300 banks, retailers, and fintechs worldwide use Sardine to stop identity fraud, payment fraud, account takeovers, and social engineering scams. We have raised $145M from world-class investors, including Andreessen Horowitz, Activant, Visa, Experian, FIS, and Google Ventures.

Our Culture

We have hubs in the Bay Area, NYC, Austin, and Toronto. However, we maintain a remote-first work culture. #WorkFromAnywhere

We hire talented, self-motivated individuals with extreme ownership and high growth orientation. We value performance and not hours worked. We believe you shouldn't have to miss your family dinner, your kid's school play, friends get-together, or doctor's appointments for the sake of adhering to an arbitrary work schedule.

Location

Remote - Canada (From Home / Beach / Mountain / Cafe / Anywhere!)

We are a remote-first company with a globally distributed team. So you can find your productive zone and work from there.

About the Role

As an Application Security (AppSec) Engineer at Sardine, you will play a critical role in ensuring the security and integrity of our services. You will be a key security partner for our development teams, embedding security principles directly into the Software Development Lifecycle (SDLC). This is a hands-on role for a motivated individual who is passionate about proactively identifying and mitigating security risks, building secure systems, and fostering a strong security culture. You will be instrumental in protecting our company and our customers' data from emerging threats.

What You'll Be Doing

  • Perform security code reviews, vulnerability assessments, and penetration tests on our web applications, mobile applications, and APIs.
  • Integrate and manage security tools within our CI/CD pipelines, including Static Application Security Testing (SAST), Dynamic Application Security Testing (DAST), and Software Composition Analysis (SCA).
  • Lead and conduct threat modeling exercises for new features and services to identify potential security risks in the design phase.
  • Triage, validate, and prioritize vulnerabilities discovered through automated tools, manual testing, and external bug bounty programs.
  • Collaborate with engineering and product teams to design secure solutions and provide expert guidance on remediation strategies for identified vulnerabilities.
  • Develop and maintain security standards, best practices, and documentation for our development teams.
  • Manage security training to educate developers on secure coding practices and emerging threats.
  • Develop custom scripts and automation to enhance our security testing capabilities and streamline security operations.
  • Assist in incident response activities related to application security events.

What You'll Bring

  • 7+ years of professional experience in an application security, product security, or offensive security role.
  • Deep understanding of common application vulnerabilities, such as those listed in the OWASP Top 10, and their mitigation techniques (e.g., Cross-Site Scripting (XSS), SQL Injection, Cross-Site Request Forgery (CSRF), Insecure Deserialization).
  • Strong proficiency in reading and auditing code in at least one of the following languages: Python, Go, or JavaScript/TypeScript.
  • Hands-on experience with security tools for SAST, DAST, IAST, and SCA.
  • Solid understanding of security principles for cloud environments (GCP & AWS) and containerized services (Docker, Kubernetes).
  • Proven experience integrating security into various stages of the SDLC.
  • Strong analytical, problem-solving, and incident response skills.
  • Excellent communication and interpersonal skills, with the ability to effectively interact with technical and non-technical stakeholders.

Compensation

  • Salary: CA$175K - CA$215K
  • Employment Type: FullTime

Skills

Application Security
Security Code Reviews
Vulnerability Assessments
Penetration Testing
Web Applications
Mobile Applications
APIs
SDLC
Security Tools Integration
Security Culture

Sardine

Fraud prevention and compliance platform

About Sardine

Sardine.ai focuses on fraud prevention and compliance for banks, retailers, and fintech companies. Its platform offers tools for risk scoring, transaction monitoring, and customer due diligence, helping clients detect fraud and prevent money laundering. What sets Sardine.ai apart is its ability to monitor customer interactions for fraud signals, using data from over 35 providers to generate accurate risk scores. The company's goal is to enhance security and compliance for financial institutions and retailers.

San Francisco, CaliforniaHeadquarters
2020Year Founded
$73.5MTotal Funding
SERIES_BCompany Stage
Fintech, Financial ServicesIndustries
51-200Employees

Benefits

Generous compensation in cash and equity
7-year for post-termination option exercise (vs. standard 90 days)
Early exercise for all options, including pre-vested
Work from anywhere: Remote-first Culture
Unlimited paid time off and minimum 2 weeks/year of mandatory vacation
100% of health insurance, dental, and vision coverage for employees and 60% for dependents
4% matching in 401k
Company-wide offsites, the last one was at Miami
MacBook Pro delivered to your door
One-time stipend to set up a home office — desk, monitors, etc.
Monthly meal stipend
Monthly health and wellness stipend
Monthly meet-up stipend
Unlimited access to an expert financial advisory

Risks

Sophisticated synthetic identity fraud challenges traditional detection methods.
Real-time payment systems increase fraud risk, straining current detection capabilities.
Dollar-to-crypto conversion partnership may attract regulatory scrutiny.

Differentiation

Sardine offers instant settlement for NFT and cryptocurrency transactions, enhancing transaction speed.
The platform uses behavioral biometrics to monitor interactions, providing precise risk scores.
Sardine integrates data from over 35 providers for comprehensive fraud detection.

Upsides

Partnership with Experian enhances product offerings with behavioral biometrics and device intelligence.
Collaboration with Airbase expands market reach in integrated risk management solutions.
Launch of GenAI assistant, Finley, leverages AI for competitive fraud detection.

Land your dream remote job 3x faster with AI