Security Lead responsible for driving security function and strategy at Newton, a crypto trading platform. Ensuring CIRO and SOC 2 alignment while embedding security practices across all systems and applications.
Responsibilities
Own and drive our security function end-to-end, combining strategic direction with hands-on technical authority.
Review, challenge, and strengthen our systems.
Act as the security authority within engineering.
Define guardrails and drive remediation when risks arise.
Build the structure and standards needed as we scale.
Own the company wide security strategy and architecture.
Ensure CIRO and SOC 2 alignment.
Embed strong security practices across infrastructure, applications, and internal systems.
Requirements
Understand IAM and least privilege principles
Understand logging, monitoring, and alerting architecture
Be comfortable reviewing infrastructure-as-code (Pulumi)
Reason confidently about security architecture across infrastructure and application layers
Be willing to deepen your technical capabilities where needed
Have hands-on experience with SOC 2 or comparable audit processes
Have experience in a regulated environment (fintech, financial services, or similar), ideally CIRO-regulated
Have a strong understanding of risk management frameworks
Influence and challenge cloud architecture decisions when needed
Experience with AI tooling governance or AI-related security considerations is a strong plus
Benefits
At Newton, we celebrate our inclusive work environment and welcome members of all backgrounds and perspectives to apply. We are committed to providing reasonable accommodations and will work with you to meet your needs. If you are a person with a disability and require assistance during the application process, please don’t hesitate to reach out!
Security director at Intact, an insurer, protecting customer and broker digital channels and third - party risk platforms. Leading technical teams, governance, strategy, and security operations.
Information Security Advisor conducting cyber - risk assessments and contract reviews for Sun Life, a global financial - services company. Advising business and technology teams on security controls, compliance, and risk remediation.
Enterprise Security Architect securing technology for Vancity, a member - owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk - based cybersecurity solutions.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.