Senior Security Engineer strengthening security and compliance for Roofr’s customer-focused CRM platform. Owning cloud defense, incident response, vulnerability management, and secure engineering practices.
Responsibilities
Report to the VP of Engineering and work closely with the CTO and DevOps as part of Roofr's security guild
Design and harden security infrastructure across cloud environments, including network segmentation, firewalls, IDS/IPS, VPNs, WAF, and EDR
Lead vulnerability management end to end, including assessments, authenticated scans, triage, prioritization, and remediation SLAs
Build and tune SIEM/SOAR detection content and alerting logic against real attack techniques
Act as incident commander for security incidents; contain, eradicate, perform forensics, and write post-incident reviews
Threat-model new features and infrastructure changes before release
Own IAM hygiene and cloud security posture across production AWS accounts
Write, enforce, and maintain security policies and standards
Own Roofr's compliance program, mapping controls to NIST CSF 2.0, SOC 2, and CCPA/CPRA, running audits, closing gaps, and maintaining evidence
Run tabletop exercises and incident playbook drills
Embed secure-by-design practices into engineering workflows and the SDLC
Requirements
Bachelor's degree in computer science, IT, cybersecurity, or equivalent hands-on experience
5-8+ years in security engineering, incident response, or related infrastructure roles, including time as the primary or senior responder on real incidents
Certifications such as CISSP, OSCP, GCIH, or CEH are a strong plus
Deep network security fundamentals, including firewalls, VPNs, routing/segmentation, network boundaries, TLS, and DNS
Hands-on AWS cloud security, including IAM policy design, VPC architecture, KMS/secrets management, and CloudTrail/GuardDuty or equivalent
Real incident response experience covering triage, containment, forensics, and root cause analysis
Working knowledge of SIEM/SOAR tooling and writing detection logic with Python/Bash
Fluent in NIST CSF 2.0, SOC 2, and CCPA/CPRA compliance frameworks
Comfortable reading and writing real application code
Experience using AI/LLM tooling for threat intelligence is a plus
Familiarity with GDPR is a plus
Experience with PHP/Laravel is a plus
Comfort around Postgres is helpful
Benefits
1st week of employment is mandatory PTO
1 Friday off per month
Company-wide paid shutdown for the week between Christmas and New Year’s
Flexible time off
80% employer-paid benefits in the U.S.
100% employer-paid premiums for Extended Healthcare and Dental in Canada
RRSP/401k match
Generous Parental Leave policy
Annual company retreat with team-building activities
Principal Security Architect securing Menlo Security’s browser and AI - agent protection platform. Leading cryptography, cloud, vulnerability, and product security architecture.
BDC banking manager overseeing commercial loan security and disbursements across Western Canada. Coordinating due diligence, risk evaluation, lending partners and compliant loan funding.
Cybersecurity new graduate rotating through Intact’s 24 - month tech development program. Supporting threat detection, incident response, infrastructure security, and AI - enhanced security insights.
Information Security Manager leading enterprise EUC governance technology deployment and product roadmaps at TD, a global financial institution. Driving risk controls, adoption, delivery and assurance across business segments.
Principal Cloud Security Engineer securing Pax8’s cloud marketplace, infrastructure, and AI - enabled platforms. Establishing cloud, Kubernetes, identity, and software - delivery security standards across USA and Canada.
Cyber Security Engineer auditing diverse codebases, fixing vulnerabilities, and optimizing backend software. Contributing security insights and improvements to AI training datasets for a technology company.
Senior Associate designing cloud, application, and AI security solutions for PwC Canada’s consulting clients. Leading technical delivery pods and embedding DevSecOps across client environments.