Staff Security Engineer owning the security technology stack for a fintech company. Leading technical direction and mentoring engineers across security functions.
Responsibilities
Own the end-to-end architecture of Forward’s security technology stack – the platforms, tooling, data pipelines, and integrations that power AppSec, SecOps, and GRC – and make sure it works cleanly with the broader Engineering, IT, and Infrastructure ecosystem.
Set the technical direction for how we evaluate, integrate, standardize, and retire security tools, defining the reference architectures and standards the department builds on.
Act as the shared technical foundation for all three security functions: helping developers build security testing into how software ships, giving the operations team clean and reliable data to detect and investigate threats, and giving the compliance team the evidence and reporting they need to prove that controls are working.
Partner with Engineering, IT, and Infrastructure to build security into shared platforms – cloud (AWS), identity, CI/CD, endpoints, and SaaS – so security is native rather than bolted on.
Lead the evaluation, proof-of-concept, and rollout of new security technologies; consolidate overlapping tools and reduce operational toil with defensible build-versus-buy recommendations.
Use infrastructure-as-code and detection-as-code to make security configurations, platform hardening, and cloud-native controls automated, versioned, and repeatable.
Architect our centralized logging and detection data foundation (SIEM and supporting pipelines) so a single high-quality data source serves detection, investigation, and audit needs.
Architect the technical underpinnings of our identity governance and role-based access control programs, plus the automation that keeps access defensible as we grow.
Keep the security architecture aligned to frameworks like CIS Controls, ISO 27001, SOC 2, and NIST, so it stays defensible and auditable.
Provide senior technical support during major incidents, and turn lessons learned into lasting architectural improvements.
Grow the bar for the whole department – mentoring and technically guiding engineers across AppSec, SecOps, and GRC on design quality, secure defaults, and engineering practices.
Requirements
Typically 7 or more years in security engineering, security architecture, detection engineering, or security operations, including designing systems that span multiple security domains.
Demonstrated experience owning or heavily shaping the architecture of a security technology stack – how platforms, data, and controls fit together – not just operating a single tool.
Deep, hands-on cloud security expertise (AWS required; GCP or Azure a plus), including control plane monitoring, IAM, network architecture, and infrastructure log analysis.
A track record of integrating security tooling and controls into broader Engineering and IT ecosystems (CI/CD, identity, endpoints, and SaaS).
Fluency across at least two of the three domains this role serves – AppSec, SecOps, and GRC – with enough literacy in the third to design for it.
Experience with infrastructure-as-code and/or detection-as-code (e.g., Terraform and CI/CD pipelines for security configurations and detection logic).
Working knowledge of security frameworks such as CIS Controls, ISO 27001, SOC 2, and NIST, and how architecture maps to control and audit requirements.
Experience with modern programming languages such as Ruby, Python, or Go, sufficient to build automation and integrations.
Ability to communicate risk and technical direction crisply to engineers and executives alike.
Typically has a Bachelor’s Degree in Computer Science, Physics, or an equivalent technical degree, or equivalent industry experience.
Enterprise Security Architect securing technology for Vancity, a member - owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk - based cybersecurity solutions.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.
Senior security advisor simulating cyber threats and strengthening defenses for Desjardins, North America's largest cooperative financial group. Leading complex initiatives, methodologies and cybersecurity risk mitigation.