Principal Security Architect securing Menlo Security’s browser and AI-agent protection platform. Leading cryptography, cloud, vulnerability, and product security architecture.
Responsibilities
Conduct security design reviews for broad product architecture and minor changes, including AWS cloud infrastructure integrations and interactions
Conduct security code reviews
Design and document integration and deployment processes for enterprise Hardware Security Modules and Key Management
Assess third-party software and SaaS offerings
Assess designs and implementations integrating third-party software and SaaS
Oversee internal and third-party security assessments
Assess the impact of third-party and product vulnerabilities in depth
Monitor and assess product impact from emerging technologies, new web standards, and browser behavior changes
Assist compliance and sales teams with technical aspects of regulations and RFPs
Participate in technical security discussions with customers
Assist with patent writing and review
Create and review external technical materials, including blogs, white papers, and presentations
Develop novel security-focused product features
Requirements
Advanced knowledge of applied cryptography, including HSMs and TPMs
Knowledge of the Key Management Life Cycle, including key generation, storage, distribution, backup, rotation, revocation, and destruction
Deep knowledge of web and browser technologies, including Same Origin Policy, XSS, CSRF, HTTP security headers, browser architecture, and JavaScript engine internals
Thorough understanding of network and OS fundamentals, including TCP, HTTP, TLS, DNS, firewalls, WAFs, DAC/MAC, and sandboxing
AWS security experience, including IAM, Organizations, EC2, and VPC
Familiarity with static and dynamic analysis concepts and tools
Advanced knowledge of C/C++ with a focus on secure coding
Knowledge of at least one other language; Python or JavaScript preferred
Willingness to get hands-on to get things done
Minimum MSc/MEng or equivalent; PhD preferred
Benefits
Eligibility for stock-based compensation grants based on company and individual performance
Competitive total compensation and benefits package
BDC banking manager overseeing commercial loan security and disbursements across Western Canada. Coordinating due diligence, risk evaluation, lending partners and compliant loan funding.
Cybersecurity new graduate rotating through Intact’s 24 - month tech development program. Supporting threat detection, incident response, infrastructure security, and AI - enhanced security insights.
Information Security Manager leading enterprise EUC governance technology deployment and product roadmaps at TD, a global financial institution. Driving risk controls, adoption, delivery and assurance across business segments.
Principal Cloud Security Engineer securing Pax8’s cloud marketplace, infrastructure, and AI - enabled platforms. Establishing cloud, Kubernetes, identity, and software - delivery security standards across USA and Canada.
Cyber Security Engineer auditing diverse codebases, fixing vulnerabilities, and optimizing backend software. Contributing security insights and improvements to AI training datasets for a technology company.
Senior Associate designing cloud, application, and AI security solutions for PwC Canada’s consulting clients. Leading technical delivery pods and embedding DevSecOps across client environments.