cover image
Aha!

Sr. Security Engineer

Remote

Canada

Full Time

01-02-2026

Share this job:

Skills

Teamwork Ruby Go Slack Burp Suite Workday Training react node.js Bootstrap Redis Kafka PostGres

Job Specifications

Aha! is the world's #1 product development software. We help more than 1 million product builders to bring their strategy to life. Our integrated tools empower teams to go from discovery to delivery. The suite includes Aha! Roadmaps, Aha! Discovery, Aha! Ideas, Aha! Whiteboards, Aha! Builder, Aha! Develop, Aha! Teamwork, and Aha! Knowledge. Product teams rely on our expertise, AI assistant, and training programs via Aha! Academy to do their best work. We are proud to be a very different type of high-growth SaaS company. The business is self-funded, profitable, and 100% remote. We are recognized as one of the best fully remote companies to work for, champion the Bootstrap Movement, and have given over $1.5M to people in need through Aha! Cares. Learn more at www.aha.io.

Our team

The Aha! engineering team is a midsized, fully remote group that is highly productive. We are centered around North American time zones so we can collaborate during the workday.

We help each other grow: We each bring unique skills to the table and want our teammates to feel valued from the start. Our onboarding program exposes new hires to the codebase and lets them contribute right away.
We move quickly: We ship code multiple times a day. We believe in getting valuable features in front of customers and iteratively improving as we learn what works and what does not.
We value product over process: We want the team to have the time and focus needed to solve complex challenges. We minimize overhead by setting clear goals and avoiding heavyweight processes and excessive meetings.
We share knowledge freely: We share our learnings with one another and with the developer community. Our engineering blog demonstrates how we tackle interesting challenges at Aha!
We enjoy: We like what we do. And we want you to love your team and your job too. Learn more about The Responsive Method, our company values, and the generous benefits we offer.

Our technology

Our web application is a single-instance, multitenant Ruby on Rails monolith supported by Postgres (database), Redis (background jobs), Kafka (event processing), and Memcached (Rails caching). We also run a Node.js webserver to support collaborative editing and real-time updates. Our application is hosted on Amazon Web Services and architected with ECS for reproducibility and scalability.

We use a growing amount of React on the front end to build rich client-side experiences, including our fully collaborative text editor and slide presentation editor. We balance the strengths of both technologies: Rails for its conventions and simplicity and React for more powerful interactive functionality.

Teammates embrace the new technologies that help us deliver a lovable product suite, but we also remain cognizant of the maintenance overhead a new library or platform brings. We solve the problems in front of us — rather than prematurely optimizing to address issues that might never materialize.

We do most of our planning and collaboration in Aha! Roadmaps and built Aha! Develop so software engineers and their teams can take advantage of those same rich features. We use Slack and Zoom for video calls. (Email? Rarely.)

Your Experience

The primary focus of this role is web application security, so you should be deeply knowledgeable about vulnerabilities and mitigations. You are familiar with securing data in multitenant architectures and have helped engineers build secure applications.

Skills

We believe that being a kind person who elevates the rest of the team is just as valuable as writing great code. You are humble, eager to learn, and always willing to help others. You want teammates who enjoy solving problems, regardless of the technologies and techniques involved. You have worked at meaningful scale before and want to do so again. You also have the following experience and skills:

Four+ years of experience working in application security
Active collaborator with engineering and product teams
Experience with security reviews or threat modeling for a full-stack web application
Experience with security tools such as CodeQL or Burp Suite
Experience with Ruby on Rails is a plus

Your work at Aha!

About

The security team works across our suite of products and provides guidance for the larger engineering team across the full stack. We are passionate about data security and helping each other. As a Senior Security Engineer, your work will include:

Identifying application security threats and mitigations early
Improving and maintaining security code scanning tools
Contributing to application security scanning or testing
Developing and sharing secure patterns internally for ongoing education

If the Sr. Security Engineer role sounds appealing, we would love to hear from you. (A real human reviews every application.)

Grow with us

Everyone deserves to reach their fullest potential. We know that when we do work that matters with people we care about in a high-growth environment, we feel engaged and

About the Company

Aha! is the world's #1 product development software. We help more than 1 million product builders go from discovery to delivery and bring their strategy to life. Our suite of tools includes Aha! Roadmaps, Aha! Discovery, Aha! Ideas, Aha! Whiteboards, Aha! Knowledge, Aha! Teamwork, and Aha! Develop. Product teams rely on our expertise, guided templates, and training programs via Aha! Academy to be their best. We are proud to be a very different type of high-growth SaaS company. The business is self-funded, profitable, and 100... Know more