Principal Application Security Engineer (Remote, Americas)

United States
27 Oct 2021
04 Nov 2021
At Shopify, we build products that help entrepreneurs around the world start and grow their businesses. We're the world's fastest-growing commerce platform on a mission to make commerce better for everyone and we need your help.

We are currently seeking a Principal Application Security Engineer to join Shopify. We'll look to this person as a technical leader and mentor for application security, advocating for security best practices. They'll be an evangelist and leader within Shopify and externally in the ecommerce community.

We ship fast. 1000 PRs per day fast. We build products for over 1.7 million merchants in over 175 countries, with a peak RPS of 170k. Our merchants' needs are constantly growing and evolving. Application Security is responsible for the tools and training that make it possible for Shopify to ship so fast at our scale, while maintaining secure systems. From static analysis and security reviews to running one of the world's largest bug bounty programs, we do it all. Our Application Security team is split up into three main areas:
  • Proactive Security: building tools and processes for developers to catch issues before they hit production, and developing tools to track findings after-the-fact.
  • Bug Bounty: We receive several hundred security reports per month from our research partners, and they're all processed in-house by Shopify. The Bug Bounty team builds tooling to handle this volume and keep our security commitments to our merchants.
  • Ecosystem Security: thousands of companies and individuals use Shopify's API to build integrations that help power our merchant's most specific needs. We are building black-box security testing tools to help our Partners maintain our high bar of security.

If you're interested in securing products that power over 1.7 million businesses in 175 countries by working closely with development teams and creating innovative security tooling, keep reading!

  • Set the technical direction for Shopify's application security program
  • Be an advocate for security with senior leadership and other stakeholders
  • Solve the hardest security problems for over 1.7+ million merchants, 30K+ partner developers, and 2000+ internal Shopify developers
  • Look for gaps in our application security posture, prototype solutions, and build teams and products around them
  • Share knowledge with Shopify's peers in the e-commerce industry and beyond
  • Build and hire diverse, strong teams to handle new security challenges for Shopify
  • Mentor and lift up application security engineers of all levels
  • Work across all levels of abstraction: you may be building a scalable static analysis system one day, and helping with the high-level design for one of our most critical products the next


  • You're a tenured expert in the field of application security. Technology choice doesn't matter: it's the fundamental challenges of securing large systems that motivate you
  • You know patterns. You've seen, built, or driven what works at scale and what doesn't, and you can articulate why and why not
  • You understand how to motivate large groups of product developers to up their game. You are a great communicator and leader, helping teams set direction and keep on track
  • Where you don't have the right pattern or experience, you have a network of industry peers you can rely on for ideation and support
  • You are hands-on and can build tools and connect existing ones when the need arises

If you're interested in helping us shape the future of commerce at Shopify, click the "Apply Now" button to submit your application. Please submit a resume and cover letter with your application. Make sure to tell us how you think you can make an impact at Shopify, and what drew you to the role.

All your information will be kept confidential according to EEO guidelines.

Please apply before November 3rd 5:00 PM ET.

At Shopify, we are committed to building and fostering an environment where our employees feel included, valued, and heard. Our belief is that a strong commitment to diversity and inclusion enables us to truly make commerce better for everyone. We strongly encourage applications from Indigenous peoples, racialized people, people with disabilities, people from gender and sexually diverse communities and/or people with intersectional identities. Please take a look at our Sustainability Reports to learn more about Shopify's commitments to our communities, and our planet.


How we hire

At Shopify, we put a lot of care and time into who we hire. We believe that in order to build the best products, we need to build high impact teams. Our recruitment process centres around what we call the Life Story interview, a conversational-style interview where we get to learn more about you.
Learn more about our hiring process

Similar jobs

More searches like this

Similar jobs