Staff Security Engineer, Application Security (Hybrid)

Posted 52 days ago
CA$205k–240k / year
Remote
Full-Time
security-engineer

Introduction

At Homebase, you’ll join a team that’s bold, fast-moving, and obsessed with helping small businesses thrive. We build with empathy, act with urgency, and take big swings that drive real-world impact. Here, every Homie shows up to raise the bar, support one another, and celebrate wins as a team.

Your Impact Starts Here

We’re looking for a hands-on Staff Security Engineer to own and shape Homebase’s Application Security domain. This is a technical leadership role at the E5 level—you’ll define the multi-quarter strategy for how we secure our products, set architectural direction, and pioneer new capabilities that keep pace with our rapid growth. Homebase’s product suite spans scheduling, payroll, time tracking, HR, team communication, and a growing ecosystem of AI-powered features. That breadth creates fascinating security challenges, from protecting sensitive workforce and financial data to securing the AI models and pipelines that are becoming central to our product experience.

Key Responsibilities

  • **Security Strategy & Architecture**: Define and execute Homebase’s multi-quarter Application Security roadmap, aligning security initiatives with business objectives and company OKRs.
  • Architect secure-by-default patterns, frameworks, and paved roads that developers adopt naturally, removing entire classes of vulnerabilities before they reach production.
  • Evaluate emerging security technologies and make build-versus-buy decisions that shape the security platform.
  • Drive security and product trade-off decisions at the architectural level, balancing protection with velocity.
  • Influence company-wide engineering practices and security investments through data-driven recommendations.
  • **AI Security**: Lead threat modeling and security architecture reviews for AI-powered features, model training pipelines, and LLM integrations.
  • Design and implement security controls specific to AI/ML systems, including prompt injection defenses, model input validation, output filtering
Homebase
Remote
View company profile
Share this job