Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Senior/Lead Application Security Engineer image - Rise Careers
Job details

Senior/Lead Application Security Engineer

At BioRender, we’re on a mission to accelerate the world’s ability to learn, discover, and communicate science — transforming how knowledge is shared and making science open, collaborative, and easily understandable by all.

We’re shaping the future of science communication and are looking for talented individuals to help bring this vision to life! 🚀

As a Senior/Lead Application Security Engineer, you will drive on-going improvements for SSDLC, bug bounty and the application stack.Your primary responsibility is to manage the on-going application security program, including application risk assessments, CI/CD integration (SAST/DAST), bug-bounty and perform code reviews (NodeJS/React). Working closely with our engineering teams, you will define and manage the processes for how secure code is shipped. You’re excited about the challenge of building security into our workflows while proactively identifying which threats matter.

What you'll be doing 

  • Build and maintain security and CI/CD tooling for automation.

  • Perform penetration testing and code reviews (NodeJS).

  • Drive identification and remediation of application security vulnerabilities (SAST/DAST/HackerOne).

  • Conduct Bug Bounty issue evaluation, reproduction, and recommendations.

  • Test application code using the OWASP methodology.

What you bring to the table 

  • Expertise in web application security and best practices.

  • Ability to perform code reviews on NodeJS, React and related application findings.

  • Knowledgeable on integrating and maintaining SAST/DAST systems.

  • Experience with Secure Software Development Life Cycles.

  • Applied knowledge of cryptography, PKI, TLS and practical implementation of the same.

  • Performed threat modeling and have experience of common code and network vulnerability types, impacts, and remediations.

Why join us?

  • We are mission-driven: we work collaboratively towards our shared vision of improving scientific communication and accelerating scientific discovery. BioRender figures have appeared in more than 54,000 publications! 

  • BioRender is loved by millions! We have a world-class NPS and a community of loyal fans and users in 200+ countries!

  • Our company is backed by top investors and accelerators like Y Combinator, and we are on a growth trajectory comparable to many top-performing SaaS companies 

  • We’re remote-first with team members across Canada and the U.S., offering you the flexibility to work from anywhere. 

BioRender is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status.

BioRender Glassdoor Company Review
3.5 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
BioRender DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of BioRender
BioRender CEO photo
Shiz Aoki
Approve of CEO

Average salary estimate

$140000 / YEARLY (est.)
min
max
$120000K
$160000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Senior/Lead Application Security Engineer, BioRender

At BioRender, we’re embarking on an exciting journey to redefine science communication, and we need a passionate Senior/Lead Application Security Engineer to join our ambitious team! Your role will be pivotal in managing and enhancing our application security program, ensuring that we deliver secure code seamlessly to our users. You’ll dive into tasks such as conducting application risk assessments, integrating CI/CD pipelines with SAST/DAST tools, and evaluating reports from our bug bounty programs. Collaborating closely with our engineering teams, you'll be the backbone of our secure development practices, helping to identify and mitigate potential threats. With your expertise in performing code reviews for NodeJS and React applications, you'll ensure robustness in our codebase and contribute to our relentless pursuit of high security standards. Beyond that, you’ll engage in vulnerability remediation, penetration testing, and the adoption of industry best practices, guiding us to maintain our stellar reputation in scientific discovery and communication. At BioRender, we prioritize a mission-driven culture, and your efforts will be instrumental in helping scientists across the globe by making knowledge more accessible. With the flexibility of a remote-first environment and a commitment to diversity, this is a unique opportunity to make an impact in a growing company that values your skills and vision.

Frequently Asked Questions (FAQs) for Senior/Lead Application Security Engineer Role at BioRender
What are the main responsibilities of a Senior/Lead Application Security Engineer at BioRender?

As a Senior/Lead Application Security Engineer at BioRender, your main responsibilities include managing the application security program, conducting risk assessments, integrating SAST/DAST tools into our CI/CD pipelines, and leading bug bounty evaluations. You will also perform code reviews primarily on NodeJS and React applications, ensuring that our code is secure and compliant with best practices.

Join Rise to see the full answer
What qualifications are required to apply for the Senior/Lead Application Security Engineer position at BioRender?

Qualified candidates for the Senior/Lead Application Security Engineer role at BioRender should have extensive expertise in web application security, especially in conducting secure code reviews on NodeJS and React. Applicants should also be knowledgeable about integrating and maintaining SAST/DAST systems, possess experience with Secure Software Development Life Cycles, and demonstrate a solid understanding of cryptography and common vulnerability types.

Join Rise to see the full answer
How does BioRender support professional growth for a Senior/Lead Application Security Engineer?

At BioRender, we believe in fostering an environment that supports professional development. As a Senior/Lead Application Security Engineer, you’ll have opportunities to engage in continuous learning, participate in industry conferences, and work alongside talented colleagues who are committed to innovation. We encourage you to pursue certifications that enhance your expertise and contribute to your career advancement.

Join Rise to see the full answer
What tools will a Senior/Lead Application Security Engineer at BioRender use?

In the role of Senior/Lead Application Security Engineer at BioRender, you’ll utilize a variety of tools including SAST and DAST systems for security testing in our CI/CD pipelines, as well as HackerOne for managing bug bounty programs. You will also leverage security and CI/CD tooling to automate processes and facilitate penetration testing and vulnerability assessments.

Join Rise to see the full answer
What makes BioRender a unique workplace for a Senior/Lead Application Security Engineer?

BioRender stands out as a unique workplace for a Senior/Lead Application Security Engineer because of its mission-driven culture that aims to revolutionize science communication. Unlike many tech companies, we prioritize inclusivity and collaboration among a diverse team, while you’ll also find the flexibility of working remotely from anywhere in Canada or the U.S. Our backing by prominent investors and consistent growth trajectory enhances the dynamic nature of our responsibilities.

Join Rise to see the full answer
Common Interview Questions for Senior/Lead Application Security Engineer
Can you explain your experience with secure software development practices?

When answering this question, showcase your experience regarding integrating security into every phase of the Software Development Life Cycle (SDLC). Talk about how you've worked with teams to ensure secure coding standards while performing regular code reviews and vulnerability assessments.

Join Rise to see the full answer
What tools do you prefer for static and dynamic application security testing?

Discuss your familiarity with a variety of tools for SAST and DAST. Mention specific tools you've used, why you chose those tools, and how they have helped improve the application's security posture within previous projects.

Join Rise to see the full answer
How do you stay current with security vulnerabilities and threats?

Share your strategies for staying informed about the latest security threats, such as subscribing to relevant security blogs, participating in webinars, and engaging within professional cybersecurity communities. This demonstrates your proactive approach to your role.

Join Rise to see the full answer
Describe a time when you identified a critical vulnerability. What steps did you take?

Use the STAR method to structure your response, outlining the situation, task, action, and result. Be specific about the vulnerability, how you identified it, the steps taken for remediation, and the outcome of your actions.

Join Rise to see the full answer
What experience do you have with performing code reviews?

Emphasize your hands-on experience with code reviews specifically for NodeJS and React applications. Discuss how you've identified vulnerabilities during these reviews and the methods you use to educate your team on best practices and secure coding.

Join Rise to see the full answer
How would you approach threat modeling for a new application?

Explain your methodical approach to threat modeling, including identifying assets, sketching the architecture, and prioritizing threats based on potential impact and likelihood. Also, mention the use of frameworks such as STRIDE or PASTA for systematic threat identification.

Join Rise to see the full answer
What role does automated testing play in your security strategy?

Describe how automated testing tools integrate into your security protocol, the types of security tests you automate, and the benefits of maintaining consistent testing standards throughout the development process.

Join Rise to see the full answer
Have you conducted any penetration testing? If so, what tools and methodologies did you use?

Share your experience with penetration testing, listing the tools (like Burp Suite, OWASP ZAP) and methodologies you employed. Provide examples of findings and how they informed improvements in security practices.

Join Rise to see the full answer
How do you handle and document security incidents when they occur?

Outline your preferred process for documenting and responding to security incidents, emphasizing communication, evaluation, and remediation steps taken. Highlight the importance of post-incident reviews for future improvements.

Join Rise to see the full answer
What is your experience with working in a remote team, particularly in security roles?

Discuss your experience collaborating with remote teams, mentioning tools and communication practices that facilitate effective teamwork, especially concerning security protocols and maintaining a high-security posture across disparate locations.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
BioRender Remote No location specified
Posted 3 days ago
Feedback Forward
Collaboration over Competition
Growth & Learning
Transparent & Candid

Join BioRender as a Go-To-Market Engineer to automate and optimize our go-to-market strategies using AI and data-driven methods.

Photo of the Rise User
Posted 11 days ago
Feedback Forward
Collaboration over Competition
Growth & Learning
Transparent & Candid

Become a key leader at BioRender, where your expertise in enterprise product management will help shape the future of science communication tools.

Daxko Remote Raipur Gali Number 1, Raipur Khadar, Sector 126, Noida, Uttar Pradesh, India
Posted 3 days ago

Join Daxko as a Senior Website Developer, where you will enhance website solutions for health and wellness organizations.

Posted 13 days ago

Launch your career as a Software Engineer Intern with CCC Intelligent Solutions, where you will contribute to ecommerce applications in the auto parts industry.

Powertalent Remote No location specified
Posted 3 days ago

As a Mobile Tech Lead at Powertalent, you will drive mobile application development and mentor a talented team of developers in a remote setting.

Photo of the Rise User
Posted 3 days ago

Lead Visa's core Payment Processing development team as a Chief Software Engineer, driving innovation and technical leadership.

Photo of the Rise User
Posted 11 days ago

Herbalife is looking for a seasoned Principal Cloud Developer to advance their cloud application development on Oracle platforms.

Photo of the Rise User
Cognizant Remote US, Missouri, Cole County, MO
Posted 11 days ago

We are looking for a Forward Deployed Software Engineer to join Cognizant and tackle complex challenges by leveraging AI and data engineering.

Photo of the Rise User

Join a mission-driven team as a Staff Software Engineer, leading backend development in a clean energy platform.

Photo of the Rise User

Join Dev.Pro as a Software Engineer and help shape a platform designed for digital creators, all while working remotely from Latin America.

BioRender is a web-based program with thousands of pre-made icons and templates to help researchers create and share scientific illustrations.

84 jobs
MATCH
Calculating your matching score...
BADGES
Badge ChangemakerBadge Family FriendlyBadge Flexible CultureBadge Global CitizenBadge InnovatorBadge Work&Life BalanceBadge Rapid Growth
CULTURE VALUES
Feedback Forward
Collaboration over Competition
Growth & Learning
Transparent & Candid
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, remote
DATE POSTED
April 15, 2025

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!
LATEST ACTIVITY
C
Someone from OH, Massillon just viewed RN Ambulatory - Outpatient Infusion Therapy at CCF
Photo of the Rise User
Someone from OH, Columbus just viewed HR Business Partner (Maternity Cover) at Marshmallow
Photo of the Rise User
Someone from OH, Columbus just viewed Community Outreach Canvasser $24/Hr at Confidential
Photo of the Rise User
Someone from OH, Cincinnati just viewed Email Marketing Coordinator at Creative Circle
Photo of the Rise User
Someone from OH, Columbus just viewed UX Researcher, Amazon Autos at Amazon
Photo of the Rise User
24 people applied to Front-end Developer at Venturenox
Photo of the Rise User
Someone from OH, Cincinnati just viewed AI training and enablement at Writer
Photo of the Rise User
Someone from OH, Cincinnati just viewed Data Analyst (Contact Center-Hybrid) at Dow Jones
Photo of the Rise User
Someone from OH, Delaware just viewed Practice Group Manager at LifeStance Health
Photo of the Rise User
Someone from OH, Youngstown just viewed Event Services Human Resources Coordinator at Allied Universal
Photo of the Rise User
Someone from OH, Columbus just viewed IP Network Engineering Intern - Summer 2025 at Bandwidth
Photo of the Rise User
Someone from OH, Cleveland just viewed Director, Education Programs & Partnerships at Encoura
Photo of the Rise User
Someone from OH, Cleveland just viewed Operations Associate (Part-Time) - Pinecrest at Alo Yoga
Photo of the Rise User
Someone from OH, Dayton just viewed Medical Receptionist at LifeStance Health
Photo of the Rise User
Someone from OH, Coldwater just viewed Engineering Design Checker Jobs at Lockheed Martin
Photo of the Rise User
Someone from OH, Loveland just viewed SEO Admin & Business Support at Outliant
Photo of the Rise User
Someone from OH, Columbus just viewed Casting: Cedar Lake - Pilot Episode at Backstage