Principal Application Security Specialist
Relay
| Company | Relay |
| Category | Engineering |
| Location | Vancouver |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 13 Jul 2026 |
| Last verified | 30 Jul 2026 |
| Source | Employer career page (greenhouse) |
Description
Who we are:
For over 25 years, Global Relay has set the standard in enterprise information archiving with industry-leading cloud archiving, surveillance, eDiscovery, and analytics solutions. We securely capture and preserve the communications data of the world’s most highly regulated firms, giving them greater visibility and control over their information and ensuring compliance with stringent regulations.
Though we offer competitive compensation and benefits and all the other perks one would expect from an established company, we are not your typical technology company. Global Relay is a career-building company. A place for big ideas. New challenges. Groundbreaking innovation. It’s a place where you can genuinely make an impact – and be recognized for it.
We believe great businesses thrive on diversity, inclusion, and the contributions of all employees. To that end, we recruit candidates from different backgrounds and foster a work environment that encourages employees to collaborate and learn from each other, completely free of barriers. Your role:
The Principal Application Security Specialist is the most senior individual contributor across Global Relay's Software & Application Security function. Combining deep application security testing mastery with DevSecOps leadership, you set the technical direction for how Global Relay tests the security of its applications and for how security is engineered into the software development lifecycle. You lead the most complex and novel assessments, define testing methodology and standards, and drive the integration of automated security controls into CI/CD pipelines. You act as the organization’s authority on application, mobile and AI/LLM security, and partner with engineering, platform and product leadership so that security is built in and aligned with business objectives.
Your responsibilities:
Testing & methodology leadership
Collaborate with the Team Lead, Application & Software Security to develop and own the application security testing methodology and standards across web, API, mobile and AI/LLM domains.
Lead the most complex, novel and high-risk security assessments, including original research and the development of new testing techniques and tooling.
Own the organization-wide triage, escalation and evidence-quality framework across all security testing and scanning functions and define how L1–L3 teams are trained and measured against it.
Support the direction for the penetration testing and offensive security program.
Own the most advanced threat modelling for critical and cross-cutting architecture.
Serve as the organization's authority and final technical escalation point for application security.
DevSecOps & secure SDLC
Drive the integration of security into the SDLC and CI/CD pipelines, championing a proactive, risk-based, “shift-left” approach.
Develop the organization-wide standards for remediation verification, retest evidence and release closure, ensuring security gating is consistently and appropriately applied across all release pipelines.
Design and deploy an automated security framework for robust tooling and processes, using scripting and open-source solutions.
Collaborate with Engineering for the selection, deployment and management of security scanning tools (SAST, DAST, SCA, container) within CI/CD pipelines, integrating them via APIs and plugins using agile delivery methods.
Serve as the liaison for DevSecOps standards and provide input into new standards and policies.
Review and analyze vulnerability data to identify risk across applications, infrastructure and network, and manage false positives.
Set the organization's standards for root-cause analysis and remediation guidance on the most complex or systemic security defects and define how remediation quality is assessed across teams.
Influence, measurement & people
Define how testing coverage, quality an
970,107 openings. Erioun finds yours.Scored against your own profile, every hour.Try the radar →