Senior Security Researcher at Geotab ensuring secure development standards across hardware and embedded development. Collaborating with software developers and security teams on various projects.
Responsibilities
Utilizing programming tools to test devices, configuration, and code, providing risk assessments for vulnerabilities, and reporting on the overall quality of current security standards
Work closely with Geotab software developers, the broader Security team, and global strategic initiative stakeholders
Leverages security expertise in Hardware and Embedded Development
Conduct device, cloud infrastructure or web application and code testing for all systems and applications, open source dependencies, and provide analysis and risk assessments for vulnerabilities discovered
Conducts focused information security research and makes recommendations on changes within department and company
Utilize code analysis and fuzzing tools to assess the quality and security of source code
Provide recommendations on tools to address any gaps in coverage as well as defining and implementing security technical and process improvements
Contribute to secure device configuration, infrastructure design and coding standards (involves developing secure coding training for current and future developers)
Conduct manual code reviews for all systems and code changes for a given device, system or application release, providing both a detailed risk analysis of the security posture of the code and technical programming solutions (secure coding standards) to the developers to mitigate insecure code from being implemented
Provide reporting on overall quality of device, infrastructure configuration or source code from a security perspective by project/team (includes trend analysis, defects found, defects remediated, and time to remediate)
Triages and handles/escalates security issues within area of expertise
Support Geotab global strategic initiatives
Participate in candidate interviews during hiring process
Requirements
8+ years of experience with security evaluation/analysis within a technical organization, including security code reviews and risk assessments
8+ years of experience performing hardware, infrastructure, or embedded development (e.g., Network protocol analysis, debugging, virtualization)
Post-Secondary Diploma/Degree in Computer Science, Information Management, Engineering, or a related field
Technical proficiency with Linux, Windows, and languages such as C, Rust, and Python
Professional certification in Information Security (e.g., CISSP, CCSP, CSSLP, CEH, OSCP, OSWE) is highly valued
Excellent verbal and written communication skills, with comfort delivering technical training and presentations
Entrepreneurial mindset with the ability to stay organized and manage multiple priorities in a flat organization.
Regional Health & Safety Manager leading health, safety, and regulatory compliance for GFL’s environmental services operations in Quebec. Conducting audits, incident management, training oversight, and regional site visits.
Information Security Student supporting vulnerability management and cloud security at Nasdaq Verafin. Assisting with remediation, security posture enforcement, and cloud environment protection.
Senior Principal Security Architect shaping enterprise security architecture for Invesco, a global investment - management firm. Leading cloud, identity, network, data - protection, and risk initiatives.
Principal Security Architect securing Menlo Security’s browser and AI - agent protection platform. Leading cryptography, cloud, vulnerability, and product security architecture.
BDC banking manager overseeing commercial loan security and disbursements across Western Canada. Coordinating due diligence, risk evaluation, lending partners and compliant loan funding.
Cybersecurity new graduate rotating through Intact’s 24 - month tech development program. Supporting threat detection, incident response, infrastructure security, and AI - enhanced security insights.