Principal Security Researcher for Spellbook, focused on securing legal AI workflows and sensitive data. Engaging in red teaming, security research, and cross-department collaboration for risk reduction.
Responsibilities
Identify security risks across the company and partner with the relevant teams to reduce them.
Lead active red teaming, application security testing, penetration testing, exploit validation, and adversarial analysis.
Conduct original security research on legal AI, LLM-enabled products, sensitive document workflows, prompt injection, data leakage, model misuse, and tool abuse.
Coordinate third-party penetration tests, red team exercises, audits, and other external security assessments.
Own external vulnerability reports — bug bounty submissions, responsible disclosure reports, researcher communications, triage, validation, prioritization, and remediation tracking.
Drive threat modelling and secure design reviews for new products, features, AI workflows, integrations, and infrastructure changes.
Partner with R&D and Engineering to surface trust boundaries, abuse cases, and data exposure risks early in development.
Support Security Operations during incident response by reproducing vulnerabilities, validating exploits, assessing impact, and recommending remediation.
Engage with frontier AI labs, external researchers, vendors, and the broader security community to stay current on AI safety and security developments.
Publish security research, advisories, technical writeups, blog posts, or conference talks where aligned with company priorities.
Define and improve repeatable processes for security research, testing, vulnerability management, and remediation across Spellbook.
Support with other responsibilities and projects as required.
Requirements
Strong experience in application security, red teaming, penetration testing, vulnerability research, product security, or offensive security.
Hands-on experience testing modern web applications, APIs, authentication flows, authorization models, cloud services, and distributed systems.
Experience developing proof-of-concept exploits or clear technical demonstrations to validate security impact.
Firm grasp of common software security risks, secure design principles, identity and access controls, data protection, and secure development practices.
Experience partnering with engineering, product, or R&D teams to triage, prioritize, and remediate vulnerabilities end-to-end.
Excellent written and verbal communication skills, with the ability to write clear technical reports, executive summaries, remediation guidance, and public-facing research, and to explain trade-offs to engineers, PMs, and leadership.
Strong judgment around responsible disclosure, customer impact, confidentiality, and coordinated communication.
Pragmatic at distinguishing theoretical risk from practical risk, with the instinct to help teams focus on what matters most.
Comfortable operating with ambiguity and moving with urgency across hands-on testing, product security, incident support, and external coordination.
Track record of driving measurable risk reduction in a fast-moving technical environment.
Benefits
Access our company-paid group benefits for you and your family, with $1,000 towards mental health support
Disconnect during our holiday closure and take advantage of our generous time off policies throughout the year
Enjoy monthly paid meals, an annual wellness allowance to support your well-being and parental leave top-ups as your family grows
Secure your stake in our success; you’ll receive competitive stock option grants as a pivotal early employee
Security director at Intact, an insurer, protecting customer and broker digital channels and third - party risk platforms. Leading technical teams, governance, strategy, and security operations.
Information Security Advisor conducting cyber - risk assessments and contract reviews for Sun Life, a global financial - services company. Advising business and technology teams on security controls, compliance, and risk remediation.
Enterprise Security Architect securing technology for Vancity, a member - owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk - based cybersecurity solutions.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.