Software Engineer focusing on security features for AI systems at Cohere, contributing to production security and secure coding practices.
Responsibilities
Software Development: Contributing to the core development of security features such as OIDC/OAuth flows and session management, ensuring North's AI agents are secure
Secure Coding: Writing secure code to handle OIDC tokens, user claims, and sensitive data, adhering to best practices for JWT validation and encryption
Authentication and Data Protection: Implementing authentication mechanisms including user login, token management, and authorization checks to maintain data integrity
Tool Integration: Pulling in new tools to enhance North's security capabilities
DevSecOps: Design and implement secret management within Kubernetes clusters, including encryption and RBAC
Cross-functional Collaboration: Demonstrate strong soft skills to communicate security best practices to stakeholders in a clear and concise manner
Requirements
Have 5+ years building user-facing security features in production systems
Ship production Python confidently and frequently
Understand OIDC/OAuth 2.0, JWT validation, and token lifecycle management deeply—not just conceptually
Have hands-on experience with Kubernetes in both development and production environments
Have worked across GCP, AWS, Azure, or hybrid/multi-cloud deployments
Are comfortable working across the stack
Communicate security concepts clearly to non-security engineers and stakeholders
Thrive in fast-moving environments where priorities evolve
Experience working with AI/ML systems or LLM-based applications
Benefits
An open and inclusive culture and work environment
Work closely with a team on the cutting edge of AI research
Weekly lunch stipend, in-office lunches & snacks
Full health and dental benefits, including a separate budget to take care of your mental health
100% Parental Leave top-up for up to 6 months
Personal enrichment benefits towards arts and culture, fitness and well-being, quality time, and workspace improvement
Remote-flexible, offices in Toronto, New York, San Francisco, London and Paris, as well as a co-working stipend
Enterprise Security Architect securing technology for Vancity, a member - owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk - based cybersecurity solutions.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.
Senior security advisor simulating cyber threats and strengthening defenses for Desjardins, North America's largest cooperative financial group. Leading complex initiatives, methodologies and cybersecurity risk mitigation.