Senior Security Engineer focusing on Application Security and Vulnerability Management for cybersecurity firm. Collaborating with teams on security operations, incident response, and compliance initiatives.
Responsibilities
Triage and coordinate remediation of vulnerabilities across SAST, SCA, DAST, CSPM, external reconnaissance, security advisories, and bug reports
Own the SAST, DAST, and SCA technical stack end-to-end including configuration, execution, triage, and reporting across Solink's technology stack
Lead Solink's shift-left security program by embedding security guardrails, automated checks, and developer tooling into IDEs and CI/CD pipelines to identify issues early and drive adoption across teams
Leverage AI-powered security tools and modern techniques for vulnerability discovery and triage, combining them with practical experience and traditional security tooling.
Develop scalable practices, automation workflows, and documentation that raise the security bar across the organization
Participate in architecture reviews and threat modeling exercises, providing security and compliance guidance across product-engineering and corporate systems.
Conduct source code and whitebox security assessments, providing actionable recommendations to improve security posture
Support incident response activities, including investigation, containment, recovery, and post-incident reviews.
Contribute to threat hunting and red team exercises across AWS, Kubernetes, and other cloud environments.
Support compliance initiatives, evidence collection, audit readiness and the ongoing automation of compliance processes.
Help teams adopt AI tools securely by contributing to AI threat modeling, implementing appropriate controls, and addressing emerging AI-related risks.
Partner with IT Services and corporate stakeholders on endpoint security, EDR, and broader security operations initiatives.
Execute penetration tests for web, mobile, and API applications.
Requirements
8+ years of experience in security engineering, application security, cloud security, or related disciplines, with hands-on experience securing production environments
Deep expertise in application security and vulnerability management, including SAST, DAST, SCA, penetration testing, and secure code review
Experience integrating security tooling into CI/CD pipelines and DevSecOps workflows
Proficiency in at least one scripting language (Python, Go, or equivalent), with experience building and automating security tooling
Hands-on cloud security experience in AWS or GCP
Experience with SIEM platforms, detection engineering, incident investigation, and security operations
Strong understanding of IAM, including SSO, MFA, RBAC, PAM, and identity threat detection
Knowledge of OWASP Top 10, secure development practices, software supply chain security, and SBOMs
Comfortable leveraging AI-powered tools and adapting to emerging security technologies
Bachelor's degree in Information Security, Computer Science, Engineering, or equivalent practical experience.
Benefits
Fully paid health & dental (no waiting period) + $500 health spending account
Monthly reimbursement for fitness, wellness, or mental health programs
Meaningful equity: Every full-time, permanent employee has a stake in our growth
Advancement based on contribution, initiative, and the ability to raise the bar - together
Clear expectations, honest feedback, and no politics
Social connection through company events and activities
Security director at Intact, an insurer, protecting customer and broker digital channels and third - party risk platforms. Leading technical teams, governance, strategy, and security operations.
Information Security Advisor conducting cyber - risk assessments and contract reviews for Sun Life, a global financial - services company. Advising business and technology teams on security controls, compliance, and risk remediation.
Enterprise Security Architect securing technology for Vancity, a member - owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk - based cybersecurity solutions.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.