Clio is the global leader in legal AI technology, empowering legal professionals and law firms of every size to work smarter, faster, and more securely.
We are transforming the legal experience for all by bettering the lives of legal professionals while increasing access to justice.
Summary:What your team does:
We are currently seeking an Application Security Engineer to join our rapidly growing Security team. The Application Security team is responsible for emulating real-world adversaries to proactively discover, exploit, and help remediate critical security vulnerabilities across our applications. We provide a vital adversarial perspective, challenging our defences and partnering with development teams to eliminate flaws before they can be exploited.
This role is for someone who is passionate about building innovative solutions and being exposed to new challenges and technologies while making an impact. This role is available to candidates across Canada (excluding Quebec). If you are local to one of our hubs (Burnaby, Calgary, or Toronto), you will be expected to be in office a minimum of two days per week for our Anchor Days.
Write, review, debug, and implement tools to help developers avoid security flaws;
Build partnerships with development teams and advise on security best practices;
Contribute to collective developer education by driving security awareness and knowledge amongst the product organization;
Provide detailed guidance and support to teams in vulnerability remediation, and develop frameworks, guidelines, and systematic fixes for recurring vulnerabilities;
Resolve issues, navigate ambiguity, and maintain positive working relationships with researchers in our Bug Bounty program;
Identify and implement tools for automated application scanning, static analysis and related tools;
Perform penetration testing, and offensive campaigns against internal assets;
Perform reactive incident response and forensics when a security event occurs;
Perform proactive research to detect new attack vectors;
Elevate and educate our security culture within Clio, contributing to our cultural values;
Experience in Application or Product Security, with a focus on offensive security and penetration testing
Hands-on expertise identifying and exploiting complex vulnerabilities (e.g., SSRF, Deserialization, logic bypasses)
Proven ability to lead and conduct formal threat modeling sessions
Strong proficiency in at least one major programming language (e.g., Python, .NET, Ruby, JavaScript)
Experience securing applications in modern cloud environments (AWS, Azure, or GCP)
Expertise with common application security tools and platforms (e.g., Burp Suite, SAST, SCA)
Experience with log aggregation and SIEM technologies
Ability to identify malicious behaviour and emerging threats via log analysis
Demonstrate a keen interest in improving your craft by using AI
Security certifications such as OSCP or OSWE
Active participation in the security community (e.g., presenting at conferences, contributing to open-source tools).
Experience with Ruby on Rails, Puppet, Kubernetes, Terraform, ELK (Elastic, Logtash and Kibana)
Strong AWS security experience on EC2 and managed services
Infrastructure security (WAF, ACLs, authentication, device hardening)
What you will find here:
Compensation is one of the main components of Clio’s Total Rewards Program. We have developed a series of programs and processes to ensure we are creating fair and competitive pay practices that form the foundation of our human and high-performing culture.
Some highlights of our Total Rewards program include:
Competitive, equitable salary with top-tier health benefits, dental, and vision insurance
Hybrid work environment, with expectation for local Clions (Vancouver, Calgary, Toronto, Dublin, London, New York City and Sydney) to be in office min. twice per week.
Flexible time off policy, with an encouraged 20 days off per year.
$2000 annual counseling benefit
RRSP matching and RESP contribution
Clioversary recognition program with special acknowledgement at 3, 5, 7, and 10 years
Diversity, Inclusion, Belonging and Equity (DIBE) & Accessibility
Our team shows up as their authentic selves, and are united by our mission. We are dedicated to diversity, equity and inclusion. We pride ourselves in building and fostering an environment where our teams feel included, valued, and enabled to do the best work of their careers, wherever they choose to log in from. We believe that different perspectives, skills, backgrounds, and experiences result in higher-performing teams and better innovation. We are committed to equal employment and we encourage candidates from all backgrounds to apply.
Clio provides accessibility accommodations during the recruitment process. Should you require any accommodation, please let us know and we will work with you to meet your needs.
Learn more about our culture at clio.com/careers
We're a Human and High Performing AI company, meaning we use artificial intelligence to improve all of our operations. In recruitment, AI helps us streamline the process for greater efficiency. However, we've built our systems to ensure that a human always reviews AI-generated output, and we never make automated hiring decisions.
Disclaimer: We only communicate with candidates through official @clio.com email addresses.
Skills Required
- Experience in Application or Product Security with a focus on offensive security and penetration testing
- Hands-on expertise identifying and exploiting complex vulnerabilities (e.g., SSRF, Deserialization, logic bypasses)
- Proven ability to lead and conduct formal threat modeling sessions
- Strong proficiency in at least one major programming language (e.g., Python, .NET, Ruby, JavaScript)
- Experience securing applications in modern cloud environments (AWS, Azure, or GCP)
- Expertise with application security tools and platforms (e.g., Burp Suite, SAST, SCA)
- Experience with log aggregation and SIEM technologies
- Ability to identify malicious behaviour and emerging threats via log analysis
- Demonstrated interest in improving craft using AI
- Security certifications such as OSCP or OSWE
- Active participation in the security community (presenting, open-source contributions)
- Experience with Ruby on Rails, Puppet, Kubernetes, Terraform, ELK (Elastic/Logstash/Kibana)
- Strong AWS security experience on EC2 and managed services
- Infrastructure security experience (WAF, ACLs, authentication, device hardening)
Clio Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Clio and has not been reviewed or approved by Clio.
-
Fair & Transparent Compensation — Public salary bands on job postings and a regional pay‑transparency report signal clear ranges and equity review practices. Pay‑range transparency is described as global, with internal ranges shared company‑wide.
-
Healthcare Strength — Health, dental, and vision coverage are emphasized, with U.S. healthcare called out as strong and Canada‑based employees receiving a dedicated counseling benefit. Wellness programming and an Employee and Family Assistance Program complement core medical coverage.
-
Leave & Time Off Breadth — Flexible paid time off with a stated four‑week minimum and paid volunteering time are part of the standard package. Parental leave is offered for birthing and non‑birthing parents.
Clio Insights
What We Do
Clio is the undisputed leader in cloud-based legal technology offering practice management, CRM and client intake software. Clio enables lawyers to be more client-centered and has earned the most 5 star reviews, the approval of over 65 bar associations and law societies around the world, and a global customers base of 150,000. Clio enables law firms to deliver better client experiences through cloud-based practice management, CRM and client intake software. Clio was the first to bring cloud-based legal practice management software to market, and has been leading the industry since 2008 with the first client-centered suite of cloud-based law firm solutions, the Legal Trends Report, and the Clio Cloud Conference, which is now the most widely attended legal tech conference in the industry. Clio is more than software. Clio is the only provider truly invested in the success of you and your clients. Clio’s team of client and firm success specialists combine their expertise on the Legal Trends Report, with their knowledge of Clio’s leading cloud-based legal practice management, CRM and client intake software to help lawyers run results-driven law firms using real time insights. Founded in Vancouver, Canada, Clio employs over 500 staff across five global offices and has been named one of Canada’s Best Managed Companies, a Deloitte Fast 50 company, and one of Canada’s Most Admired Corporate Cultures.









