Application Security Specialist
CoLab Software
About CoLab
At CoLab, we want to help mechanical engineering teams bring life-changing products to market years sooner.
CoLab is a cloud based platform for engineering design review. We make it easy for subject matter experts (SMEs) across your business to access, evaluate, and comment on 2D drawings and 3D models. Our built-in AI peer checker, AutoReview, scans designs for common errors or non-compliance with your standards and guidelines. AutoReview creates markups and comments on your files, in context – just like a human checker.
With CoLab, human SMEs and AI work together to help you make better decisions and improve designs faster. We automatically capture knowledge from across your global business that would otherwise be buried in emails, spreadsheets, slide decks, and unknown locations in Sharepoint or PLM. Then, we make sure every lesson learned and every design guideline is applied exactly when it matters.
Companies like Johnson Controls, Komatsu, Schaeffler, and Polaris have launched products 40% faster, cut BOM costs by 50%, and reduced quality escapes by 15% in 1 year.
About the Role
CoLab is looking for our next Application Security Specialist. Your focus is helping us catch vulnerabilities before they reach production. You’ll be embedded in multiple product build teams (2–3 squads), attending standups, reviewing feature work, and stress-testing our application and tools for risk. Your day-to-day involves deeply understanding how our software works—and then figuring out how to break it.
Taking direction from the Director of AppSec, this role is ideal for someone early in their security career (dev, QA or pentesting exposure) who is deeply motivated to learn and ready to work hard to get better.
What You’ll Do
- Review and risk rate upcoming features based on potential security impact. Work closely with devs on high risk projects.
- Conduct manual and exploratory security testing on features before they ship.
- Actively participate in team standups for 2–3 development teams, building trust and offering guidance when needed.
- Break things. Your job is to think like an attacker and uncover issues devs may not see.
- Manage and support internal security tools (e.g., SemGrep, Datadog, Retool, etc.) and help teams use them responsibly.
- Continuously improve our security review process, tooling, and internal documentation.
- Shadow senior security team members and pursue self-guided learning to level up your skills.
You’ll Thrive in This Role If:
- You’re self-motivated and learn best by doing. You don’t need someone to tell you what to Google.
- You’re excited by difficult, often thankless work—because you know it matters.
- You’re detail-oriented and comfortable living in the weeds.
- You’re tactful and thoughtful in how you deliver feedback—even when it’s hard to hear.
- You have baseline exposure to development, QA, or pen testing and are hungry to specialize in application security.
Must-Haves
- Strong drive to learn, improve, and become an expert in application security.
- Some experience in software development, QA or penetration testing (even co-op or personal projects).
- Familiarity with modern web applications and security fundamentals.
- Clear communication skills
- Willingness to work toward a certification like OSCP or OSWA (we’ll support you).
Nice-to-Haves
- Exposure to web app security testing or bug bounty programs.
- Hands-on experience practicing offensive security techniques (CTFs, labs, or platforms such as Hack The Box) is a plus
- Experience with dev tools and CI/CD pipelines.
- Familiarity with security issues in modern JavaScript, Python, or cloud-based applications.
The Extra Details
Compensation: Full-time, permanent role with competitive compensation and stock options.
Benefits: Unlimited vacation, extended health coverage, and 5% RRSP matching.
Location: Remote-first within Canada. Our HQ is in St. John’s, NL, Canada with optional hybrid if you're local.
Equity Note
Frequently cited statistics show that people who identify with historically marginalized groups are likely to apply to jobs only if they meet 100% of the qualifications. We encourage you to help us break that statistic and apply even if you don’t meet every single qualification—your potential is what matters most to us.
