Product Security Engineer improving security of Lattice’s applications and services through engineering partnerships and security operations. Contributing to secure coding practices and AI/LLM security assessments.
Responsibilities
Partner with engineers to identify, triage, and remediate security issues in product features and services
Participate in security reviews and threat modeling for new features and systems
Perform security-focused code reviews and help identify common vulnerabilities
Help implement and operate security tooling (SAST, DAST, dependency scanning, etc.)
Support vulnerability management workflows, including internal findings and bug bounty reports
Assist in investigating security issues and assessing risk and impact
Collaborate with platform and infrastructure teams to improve application and cloud security posture
Contribute to improving security practices in AWS-based environments
Assist in identifying and mitigating risks in AI/LLM-powered features, including prompt injection, data leakage, and unsafe output handling
Apply emerging best practices (OWASP Top 10 for LLM Applications) to real product use cases
Contribute to security guidance, documentation, and training for engineering teams
Help improve how security is integrated into the development lifecycle.
Requirements
1–3+ years of experience in product security, application security, or software engineering
Experience writing and maintaining code in JavaScript/TypeScript (or similar languages like Python or Ruby)
Familiarity with common web and API vulnerabilities (e.g., OWASP Top 10)
Exposure to security testing tools (SAST, DAST, dependency scanning, etc.)
Experience working in or with cloud environments (AWS or similar).
Lead agentic AI cybersecurity initiatives, building automated vulnerability discovery and remediation pipelines. Requires deep expertise in offensive security, software engineering, and AI tools.
Security director at Intact, an insurer, protecting customer and broker digital channels and third - party risk platforms. Leading technical teams, governance, strategy, and security operations.
Information Security Advisor conducting cyber - risk assessments and contract reviews for Sun Life, a global financial - services company. Advising business and technology teams on security controls, compliance, and risk remediation.
Enterprise Security Architect securing technology for Vancity, a member - owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk - based cybersecurity solutions.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.