Full-Time

Staff Security Engineer

Application Security

Homebase

Homebase

1,001-5,000 employees

Workforce management platform for hourly workers

Compensation Overview

CA$205k - CA$240k/yr

+ Stock Options + RRSP/TFSA match

Toronto, ON, Canada

Hybrid

Hybrid role; in-office Tuesdays & Wednesdays are required.

Category
IT & Security (1)
Required Skills
LLM
Python
React.js
Ruby
Threat modeling
Machine Learning
Vulnerability Analysis
AWS
DevOps
Requirements
  • 10+ years of progressive experience in Application Security or Security Engineering, with demonstrated impact at the Staff or Principal level.
  • Deep software engineering experience in production environments, you write code, build tools, and think like an engineer first.
  • A proven track record of leading architectural changes and complex cross-team initiatives that reduced security risk at scale.
  • Hands-on experience securing AI-native applications, including LLM integrations, model pipelines, or ML infrastructure.
  • Strong expertise in web application security, cloud-native security (AWS), and modern DevSecOps practices.
  • Proficiency in languages and frameworks relevant to our stack: Ruby, Python, React, and Rails.
  • Experience designing and implementing modern vulnerability management systems and embedding security tooling within CI/CD pipelines.
  • Exceptional ability to evaluate security trade-offs, make pragmatic risk-informed decisions, and communicate them clearly to technical and non-technical stakeholders.
  • Demonstrated curiosity about emerging AI capabilities, with a track record of leveraging new tools to enhance security operations and productivity.
Responsibilities
  • Define and execute Homebase’s multi-quarter Application Security roadmap, aligning security initiatives with business objectives and company Objectives and Key Results.
  • Architect secure-by-default patterns, frameworks, and paved roads that developers adopt naturally, removing entire classes of vulnerabilities before they reach production.
  • Evaluate emerging security technologies and make build-versus-buy decisions that shape the security platform.
  • Drive security and product trade-off decisions at the architectural level, balancing protection with velocity.
  • Influence company-wide engineering practices and security investments through data-driven recommendations.
  • Lead threat modeling and security architecture reviews for AI-powered features, model training pipelines, and LLM integrations.
  • Design and implement security controls specific to AI/ML systems, including prompt injection defenses, model input validation, output filtering, and data pipeline integrity.
  • Create AI-powered vulnerability detection and security automation that multiplies the team’s effectiveness.
  • Partner with AI engineering teams to establish secure development patterns for model deployment and inference infrastructure.
  • Stay ahead of the evolving AI threat landscape and translate emerging risks into practical engineering guidance.
  • Build and maintain security tooling and automation that integrates seamlessly into CI/CD pipelines, enabling continuous security validation at scale.
  • Own the vulnerability management program: design modern systems for detection, prioritization, tracking, and remediation of security debt across the product portfolio.
  • Own the bug bounty and responsible disclosure program, turning external researcher findings into systemic improvements.
  • Embed security into the full software development lifecycle through scalable guardrails, automated testing frameworks, and developer-facing documentation.
  • Partner with senior leaders across Engineering, Product, and Infrastructure to improve Homebase’s overall security posture.
  • Pioneer a security partnership program, mentoring engineers across the organization, and driving a culture of shared security ownership.
  • Provide expert guidance during security incidents and lead post-incident analysis to drive systemic improvements.
  • Curate and author security guidance, patterns, and training content that raises the security bar organization-wide.
  • Influence security decisions at the department and company level; shape how Homebase invests in security capabilities.
Desired Qualifications
  • Experience defining application security strategy and maturity roadmaps for a high-growth, product-driven company.
  • A background in building AI-powered security tools or detection systems.
  • Speaking experience at security conferences, meetups, or community events.
  • Experience with threat modeling frameworks adapted for AI/ML systems.

Homebase provides a digital workforce management platform for businesses with hourly workers. It combines time tracking, employee scheduling, payroll processing, and built-in messaging to help managers run their teams more efficiently. Time tracking turns any device into a time clock to record hours, breaks, and overtime, reducing paperwork. Scheduling lets managers plan and adjust shifts online and share the plan with the team instantly. Payroll automatically calculates pay, makes direct deposits, and handles payroll taxes. The built-in messaging keeps managers and team members connected, even when they’re not on site. The service is mainly used by small businesses with hourly workers and is priced as a software-and-services offering. The goal is to simplify and streamline day-to-day operations for hourly workforces by providing an all-in-one tool to manage time, schedules, pay, and communication in one place.

Company Size

1,001-5,000

Company Stage

Series D

Total Funding

$189M

Headquarters

San Francisco, California

Founded

2014

Simplify Jobs

Simplify's Take

What believers are saying

  • Raised $60M Series D led by L Catterton Growth for expansion.
  • Enhanced Lightspeed integration boosts omnichannel merchant experiences.
  • Doubled Canadian workforce by 104% with Toronto office in 2023.

What critics are saying

  • POS competitors like Lightspeed bundle workforce tools, eroding standalone value.
  • Payroll tax filing errors trigger IRS fines and class-action suits.
  • Free tier cannibalizes paid upgrades, capping ARPU indefinitely.

What makes Homebase unique

  • Homebase targets hourly workers in SMBs unlike desk-focused HR tools.
  • Integrates scheduling, time tracking, payroll, and messaging seamlessly.
  • Offers free core plan with POS integrations like Square and Shopify.

Help us improve and share your feedback! Did you find this helpful?

Your Connections

People at Homebase who can refer or advise you

Benefits

Stock options

Comprehensive insurance plans

401(k) with 4% company match

Remote, hybrid, and in-office work options

Top-of-the-line equipment and home office

Annual holidays and accrued PTO

Fun company activities

Growth & Insights and Company News

Headcount

6 month growth

0%

1 year growth

0%

2 year growth

8%
Business Wire
Sep 9th, 2025
Homebase Earns Spot on Fast Company's 2025 Best Workplaces for Innovators North America

From this foundation of learning, Homebase has introduced its first AI-powered Hiring Assistant and Scheduling Assistant, tools designed to transform how small businesses manage their teams.

Retail Times
May 7th, 2025
The Range expands with Homebase acquisition

CDS Superstores, parent of The Range and wilko, is expanding its new-format superstores after acquiring Homebase and up to 70 of its stores. Four new locations will open on 9th May: Santry, Woodside Park, Tiverton, and Cookstown. The Range plans to open up to 10 new superstores monthly, aiming to transform 70 Homebase locations by 2025, securing up to 1,600 jobs. The initiative includes retaining Homebase staff and relaunching the Homebase website for an enhanced shopping experience.

Worcester News
Apr 15th, 2025
B&Q officially opens in former Homebase in Blackpole

It is the second of eight stores across the UK that B&Q acquired from Homebase.

Lightspeed Commerce
Dec 10th, 2024
Lightspeed Enhances Workforce Management Integration With Homebase

Lightspeed Commerce Inc., the one-stop commerce platform empowering merchants to provide the best omnichannel experiences, today announced an enhanced integration with Homebase, the all-in-one HR and team management solution for small businesses.

TechCrunch
Apr 3rd, 2024
Team management app Homebase welcomes $60M Series D to give SMBs 'superpowers'

Team management app Homebase welcomes $60M Series D to give smbs 'superpowers'