Product Security Specialist strengthening security for Safe Software’s FME data integration platform. Supporting SDLC security, AI governance, vulnerability disclosure, and customer security engagements remotely across Canada.
Responsibilities
Strengthen security practices within the software development lifecycle
Support the AI governance program for developers
Work directly with developers, product management, customer experience teams, customers, and partners
Explain security concepts to audiences with varying technical backgrounds
Handle security questionnaires and assessments
Participate in customer- and partner-driven security meetings
Write and maintain security policies and documentation
Contribute to the risk register
Support compliance monitoring
Conduct security and compliance reviews of third-party libraries and vendor components, including licensing and known risk signals
Contribute to policies and standards for AI-assisted development
Monitor emerging AI security risks
Assist with training and awareness across the Engineering organization
Support the vulnerability disclosure process, including CVE registration and security advisory drafting
Contribute to postmortems and lessons-learned reviews
Own ongoing security coverage for non-Engineering apps and services, including websites, APIs, internal tools, IT-developed scripts, and internal AI agents
Contribute to security KPI tracking, governance dashboards, and reporting for leadership and external stakeholders
Requirements
3+ years of experience in product security, application security, or a closely related cybersecurity role
Strong technical background in cybersecurity
Solid understanding of common vulnerability classes, secure development practices, and security tooling (e.g., OWASP Top 10, SAST, DAST, SCA)
Ability to communicate security concepts clearly to stakeholders with varying technical backgrounds
Strong analytical skills and ability to interpret noisy or incomplete data
Proficiency in Python for automation, tooling, or analysis
Experience with Agentic AI
A degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent practical experience
Familiarity with compliance frameworks such as SOC 2 or ISO 27001
Security certifications such as CISSP or CISM
Familiarity with and/or experience using and supporting FME in production environments
Benefits
Bonus
Paid time off to volunteer for Safe-organized opportunities
Information Security Specialist strengthening technology controls, security governance, and risk management at TD, a major North American bank. Advising partners, assessing controls, supporting audits, and responding to incidents.
Buildings, development and security Analyst supporting fire prevention, facility safety, and building management at Desjardins. Analyzing risks, developing safety plans, and implementing physical security systems.
BMO banking associate providing bilingual credit and lending sales and service remotely in Quebec. Handling customer contacts, credit decisions, compliance, and suspicious - activity reporting.
Principal Information Security Engineer defining scalable security strategy, architecture, automation, cloud, identity, and AI controls. Helping Arctic Wolf protect organizations worldwide and end cyber risk.
Consultant cybersécurité hybride à Montréal chez I - TRACING, pure - player indépendant en sécurité informatique. Conception, déploiement et support de solutions IAM, réseau, systèmes et applications.