Hiring.Camp

Application Security Developer

AutoDesk

·

Yesterday

Location
AMER - Canada - British Columbia - Vancouver - Bentall Centre · AMER - Canada - Ontario - Toronto - University Ave
Type
Full-time
Department
IT
Closing date
Today
Source
Workday

Description

Job Requisition ID #

26WD97513

Position Overview

Our team of security experts helps Autodesk design, build, deploy and maintain secure products. We are embedding security in the full spectrum of how we build our products from inception, design, development, testing to how we are running them in the cloud as well as how we are responding to any existing or emerging threats to our products or the building blocks of our products and services. Our job is to be one step ahead of the bad guys and use expertise, technology and other resources to thwart their efforts to compromise our products and the environment in which they operate. Our team keeps a single-minded focus on protecting our customer’s data and their investment in our products by strengthening our applications, underlying services and network. 

As part of this team, you will help strengthen Autodesk's products by partnering with product and engineering teams to design, build, deploy, and operate secure applications and services. This role focuses on application security across the software development lifecycle, including secure design, threat modeling, code review, vulnerability assessment, secure coding guidance, and security testing in CI/CD pipelines.

You will work across modern cloud-native applications, APIs, services, and developer platforms to identify and mitigate risks such as injection, broken access control, and supply chain weaknesses. As Autodesk continues to adopt AI-enabled features and AI-assisted development workflows, you will also help teams understand and address emerging AI-related risks, including prompt injection, unsafe tool invocation, data exposure, and insecure use of LLM-enabled systems.

Responsibilities

  • Partner with engineering teams to embed security throughout the software development lifecycle, including design reviews, threat modeling, implementation guidance, code review, and release readiness

  • Identify, validate, and help remediate common application security vulnerabilities, including injection, broken access control, authentication and authorization flaws, data leakage, insecure deserialization, and server-side request forgery

  • Support security reviews of AI-enabled applications and AI-assisted development workflows, including risks related to LLM-integrated systems, coding assistants, prompt injection, sensitive data exposure, and unsafe model or tool interactions

  • Develop and maintain secure coding guidance, reusable security patterns, and engineering enablement materials for application, API, cloud, and data protection risks

  • Integrate and improve application security testing in CI/CD pipelines, including SAST, DAST, SCA, secrets detection, infrastructure-as-code scanning, and other automated controls

  • Provide developer education on secure coding, threat modeling, vulnerability remediation, secure use of third-party components, and safe adoption of emerging technologies

  • Track, prioritize, and report application security risks and trends to continuously improve Autodesk's product security posture

Minimum Qualifications

  • Strong understanding of application security fundamentals, including the OWASP Top 10, secure software design, common vulnerability classes, and practical mitigation techniques

  • Hands-on experience securing modern web applications, APIs, microservices, and cloud-native systems

  • Experience performing secure design reviews, threat modeling, code reviews, vulnerability assessments, or penetration testing

  • Practical knowledge of authentication, authorization, session management, data protection, input validation, output encoding, and secure API design

  • Experience identifying and mitigating vulnerabilities such as injection, broken access control, insecure deserialization, server-side request forgery, cross-site scripting, data leakage, and insecure configuration

  • Experience integrating security testing and controls into CI/CD pipelines and DevSecOps workflows

  • Familiarity with common application security tooling, such as SAST, DAST, SCA, secrets scanning, container scanning, or API security testing tools

  • Proficiency in scripting or programming, such as Python, JavaScript, Go, Java, or similar languages, for automation, testing, or prototyping

  • Ability to communicate complex security risks clearly and translate them into practical, actionable guidance for engineering teams

  • Familiarity with emerging AI/LLM security risks, such as prompt injection, data exposure, unsafe tool invocation, and secure use of AI coding assistants

Preferred Qualifications

  • Background in application security, product security, or security engineering for large-scale software products or cloud services

  • Experience building or improving secure development lifecycle programs, including developer enablement, security standards, secure design patterns, and automated security controls

  • Familiarity with cloud security concepts across AWS, Azure, or GCP.

  • Experience working with engineering teams to prioritize security findings based on exploitability, business impact, and customer risk

  • Knowledge of software supply chain security, including dependency management, SBOMs, package integrity, build pipeline security, and third-party component risk

  • Experience securing APIs, distributed systems, SaaS platforms, or multi-tenant cloud environments

  • Familiarity with AI-enabled applications, LLM-integrated systems, AI coding assistants, or security testing approaches for AI-assisted development workflows

  • Experience contributing to internal security standards, playbooks, secure coding guidance, or developer training programs

Learn More

About Autodesk

Welcome to Autodesk! Amazing things are created every day with our software – from the greenest buildings and cleanest cars to the smartest factories and biggest hit movies. We help innovators turn their ideas into reality, transforming not only how things are made, but what can be made.

We take great pride in our culture here at Autodesk – it’s at the core of everything we do. Our culture guides the way we work and treat each other, informs how we connect with customers and partners, and defines how we show up in the world.

When you’re an Autodesker, you can do meaningful work that helps build a better world designed and made for all. Ready to shape the world and your future? Join us!

Salary transparency

Salary is one part of Autodesk’s competitive compensation package. For Canada based roles, we expect a starting base salary between $80,000 and $116,600. Offers are based on the candidate’s experience and geographic location, and may exceed this range. In addition to base salaries, our compensation package may include annual cash bonuses, commissions for sales roles, stock grants, and a comprehensive benefits package.

Belonging
We take pride in cultivating a culture of belonging where everyone can thrive. Learn more here: https://www.autodesk.com/company/global-belonging

Are you an existing contractor or consultant with Autodesk?

Please search for open jobs and apply internally (not on this external site).

Skills

PythonJavaScriptJavaAWSAzureGCPCI/CDPenetration TestingMicroservicesPrototypingGo

Similar Jobs

16

Application Security Developer

Clio · Toronto, Canada +3 · Remote

2 weeks ago

Application Security Developer

AutoDesk · AMER - Canada - Ontario - Toronto - University Ave

2 months ago

Application Security Developer

Aoins · Home Office Branch, United States of America · Remote

4 months ago

Sr. Java Developer (Application Security / FTE / Hybrid)

NTT DATA · Charlotte, NC,US, US · Hybrid

2 months ago

Java Developer (Application Security) (hybrid)

NTT DATA · Charlotte, NC,US, US · Hybrid

2 months ago

Associate Software Developer – Application Security

Beghouconsulting · Hyderabad, Telangana · Hybrid

2 months ago

Sr. Java Developer (Application Security / FTE / Hybrid / USC, GC, H4/L2 EAD)

NTT DATA · Charlotte, NC,US, US · Hybrid

2 months ago

Senior Application Security Developer , AI Security

AutoDesk · AMER - Canada - Ontario - Toronto - University Ave

2 months ago

Senior Application Security Developer

atVenu · Calgary, AB

3 months ago

Mid Level Software Application Developer - Homeland Security

Team Carney · Oklahoma City, OK · Remote

3 weeks ago

Junior Level Software Application Developer - Homeland Security

Team Carney · Oklahoma City, OK · Remote

3 weeks ago

Application Security Engineer/Developer

Mmc · Toronto - Bremner, Canada · Hybrid

2 months ago

Senior Application Developer (Global Security)

Rbc · 16 YORK ST:TORONTO, Canada

3 months ago

Senior Application Developer (Global Security)

Rbc · 16 YORK ST:TORONTO, Canada

4 months ago

Senior Software Application Developer/Architect - Homeland Security

Team Carney · Oklahoma City, OK · Remote

3 weeks ago

Staff Developer / Development Manager, Application Security

atVenu · Calgary, AB

1 month ago