
Company Description
Workleap is a Montreal-based tech company, founded in 2006. We make simple products that actually matter to the people who use them, featuring product lines like Workleap Agent and ShareGate. More than 15,000 companies worldwide trust us.
Your role
You will build the security layer for how Workleap writes software, and then you will teach it to run itself.
Today that means the traditional stack done properly: SAST, DAST, SCA, and secret scanning wired into GitHub Actions so findings land where developers already work. Threat modeling on architectural changes and vulnerability intake/triage that closes the loop.
Where it goes next is the actual reason this role exists: moving toward agentic security review, where agents perform the first pass on every pull request, reason about change in context, and escalate what matters to a human. You will close the gap between rules engines and model hallucinations as a hands-on individual contributor.
Your impact:
- Build security guardrails for AI-assisted and agentic development so speed and safety stop being a tradeoff.
- Move security review from human bottleneck to automated first pass.
- Achieve near-zero developer friction on security signals by wiring SAST/DAST/SCA into CI/CD.
- Lead threat modeling on new features and architectural changes.
- Drive real remediation of application security vulnerabilities measured by risk retired.
- Harden Azure environments and deployment patterns alongside Infrastructure SecOps.
Your team
You will join LeapSec and report to the Director of Infrastructure and Security, partnering closely with the AI SDLC team and product engineering across the organization.
What you'll bring
- 5+ years in application security, DevSecOps, or security-focused software development.
- Deep working knowledge of web application security, OWASP Top 10, and CWE Top 25.
- Proven experience building security automation into CI/CD pipelines (GitHub Actions preferred).
- Experience building and shipping real agent tooling (MCP servers, Claude skills, subagents).
- Context engineering discipline for agentic reasoning about codebases.
- Understanding of the security model of agentic systems (prompt injection, tool permission scoping, credential handling).
- Proficiency in Python for building tooling.
- Hands-on experience with AI-assisted and agentic development workflows.
- Solid grasp of Azure services, infrastructure security, and deployment patterns.
- Ability to explain risk tradeoffs to engineers and executives.
Strong assets:
- Secure code review experience in C#/.NET
- Experience integrating SAST, DAST, SCA, and secret scanning at scale
- Familiarity with OIDC, SAML, and OAuth
- Exposure to SOC2 requirements
- Experience running vulnerability discovery and triage with a developer community
What the job comes with
- Annual bonus program and LTIP program.
- RRSP + Family health insurance + telemedicine + annual wellness budget.
- Flexible vacation policy.
- Remote work options with access to our Montreal office and biannual in-person gatherings.
- Claude access for everyone.
Timezone overlap
UTC-8β-4
Open to
Canada Β· NA
Sign in to track applications and earn points.