HelloFresh

ApplicationSecurityEngineer

CA$105–115k Toronto, Ontario, Canada Remote Friendly
Market Sentiment
HIGH DEMAND

Neural analysis suggests this role is
optimal for Mid+ candidates.

The Brief

“Application Security Engineer at HelloFresh. Skills: Application security, DevSecOps, Automation. Improve application security function. Harden apps against abuse”

Industry & Context.

Problems you'll solve

Go under the hood

Eligibility Requirements

Minimum 2 days in office

What They're Looking For.

Must Have

2-3 years experience in security, Proficiency in Python or Go, Exposure to Terraform, Exposure to Docker, Exposure to container mgmt. services, Exposure to CI/CD, Exposure to secrets management, Experience designing security controls, Experience implementing security controls, Knowledge of agile methodologies, Knowledge of modern collaboration tools

Nice to Have

Experience in microservices-based architectures

What You'll Do.

Improve application security function

Harden apps against abuse

Harden services against abuse

Secure CI/CD pipelines

Implement guardrails for developers

Conduct design reviews

Develop automated workflows

How You'll Work.

Team & Collaboration

Work with developers; Collaborate in office

Process & Methodology

Agile methodologies

Full Job Description

S'more about the team We’re looking for a new teammate to join us on the journey of keeping HelloFresh a trusted name - someone with a passion for security and appetite for new challenges. Security Engineers work in a variety of ways to constantly iterate and improve HelloFresh’s security posture. You will be the first port of call for responding to any of HelloFresh’s security related questions and concerns. You will also develop and deliver tools and processes to enable colleagues to achieve their goals and objectives. Lettuce share what this role will be responsible for Improve the application security function at HelloFresh to harden the apps & services against abuse and nefarious activity Secure containers, CI/CD pipelines and implement guardrails for the developers aligned with the DevSecOps principles Conduct design, RFC and code reviews. Mentor and train the devs following the shift-left approach through the Security Champion program. Develop practices and processes to help us scale further securely through automated workflows. Sound a-peeling? Here's what we're looking for Proven proficiency in one modern scripting language like Python or Go 2-3 years experience in the security domain Decent exposure to Terraform, Docker, container mgmt. services, CI/CD and secrets management in microservices-based architectures Experience in designing and implementing security controls specific to modern dev and deployment stack Strong knowledge of agile methodologies and modern collaboration tools like Jira, Slack Enthusiasm and passion for security and automation A skeptical, data driven mindset that is eager to go under the hood in the face of challenges Let’s cut to the cheese, this is why you'll love it here Box Discount - Amazing discounts on 1 box per week! 75% discount on weekly HelloFresh and Chefs Plate meal kits AND 50% off weekly Factor meal box. Health & Wellness - Health & Dental benefits from day 1, a Health Spending Account, unlimited access to the Headspac

Free ATS check

Applying for this Application Security Engineer role?

Most applicants get filtered before a human reads their resume. See if yours makes the cut.

ANONYMOUS · UNFILTERED

What do employees actually say about HelloFresh?

Real rants from real employees. Read before you apply.

Read Company Rants →