Senior Security Engineer designing and maintaining security tools and processes at Hopper. Focused on application security and integrating with developer workflows while leveraging AI.
Responsibilities
Own and evolve our vulnerability management program with a focus on application security — container images, dependencies, code analysis, and real-time detection
Design and maintain security tooling integrated directly into CI/CD pipelines and developer workflows so security happens automatically rather than acting as a blocker
Use AI extensively to code faster, automate analyses that would otherwise require manual review, and build intelligent tools that exceed what a small team could accomplish manually
Assess and improve how we leverage telemetry available in our systems
Work directly with engineering teams to influence secure development practices — not by writing policies and docs, but by delivering tools and default configurations that make the secure path the easiest
Investigate and respond to security reports as needed, but spend the majority of your time building systems that prevent and detect issues rather than chasing them manually
Move quickly and adapt to shifting priorities — our team is agile and tomorrow’s challenges may look very different from today’s
Requirements
Minimum 5 years of experience in software and/or platform engineering, with the ability to design, build, and maintain production-quality tools
Deep experience in application security and vulnerability management — you understand CVEs, dependency risks, container security, and SDLC integration, and you can distinguish what needs to be fixed vs. noise
Hands-on experience with cloud infrastructure, ideally GCP/GKE or equivalent, and the ability to adapt to our environment
Demonstrated habit of using AI tools — coding assistants, LLMs — as a central part of how you build and analyze, not as an occasional shortcut
A bias for automation — when you see a repetitive manual task, your instinct is to write a tool, not a procedures manual
Comfortable with ambiguity and ownership — you will often be the only person working on a problem and must make decisions about priorities, approach, and scope without waiting for direction
Experience influencing engineering culture around security, knowing how to get developers to care about security without slowing their velocity
Excellent written and verbal communication skills, including the ability to clearly explain our security posture to customers when needed.
Benefits
Well-funded, proven startup with big ambitions, competitive salary, and pre-IPO equity participation
Hopper covers 100% of group insurance premiums
Hopper provides life insurance and short- and long-term disability coverage
Health Spending Account (HSA) covering eligible medical and dental expenses
All employees and their dependents have access to Dialogue telemedicine services anytime, from anywhere
All employees have access to an RRSP plan with automatic pre-tax payroll contributions
Ask about our very generous parental leave—well above industry standards
Unlimited vacation
Travel allowance in Carrot Cash
Access to coworking spaces on demand via FlexDesk AND an allowance for remote work
Entrepreneurial culture where pushing boundaries and taking risks is part of the day-to-day
Open communication with management and company leaders
Security director at Intact, an insurer, protecting customer and broker digital channels and third - party risk platforms. Leading technical teams, governance, strategy, and security operations.
Information Security Advisor conducting cyber - risk assessments and contract reviews for Sun Life, a global financial - services company. Advising business and technology teams on security controls, compliance, and risk remediation.
Enterprise Security Architect securing technology for Vancity, a member - owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk - based cybersecurity solutions.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.