Senior Security Engineer securing Squads’ stablecoin products, APIs, and infrastructure. Leading threat modeling, code review, vulnerability management, and secure development standards.
Responsibilities
Own product and infrastructure security across Squads
Serve as security reviewer in product and engineering calls
Lead threat modeling and security design reviews for products, features, and infrastructure changes
Perform secure code reviews across backend services, APIs, frontends, and Solana programs
Focus reviews on authentication, authorization, and access control
Own the lifecycle of findings from audits, pentests, code scanning, and bug bounty
Triage, prioritize, track remediation, and verify fixes
Set severity and SLA standards and enforce them
Run bug bounty intake and validate external reports against source
Coordinate with audit partners and scope internal assessments
Tune and extend SAST, dependency, secrets, and container scanning in CI/CD
Review IAM, network controls, encryption, and secrets management across cloud environments
Assess access of internal AI tools, MCP integrations, and agents in production
Define product security standards, review checklists, and developer guidance
Requirements
8+ years in product security, application security, or security engineering, built on a software engineering foundation
Ownership of threat modeling and architecture review for complex financial or distributed systems
Track record of finding critical, non-obvious vulnerabilities in large production codebases
Experience with TypeScript, Rust, Go, or Python
Experience with LLM and agent-based review workflows
Experience building and running a vulnerability management program or bug bounty end to end
Experience with CI/CD scanning
Deep expertise in IAM, secrets management, network controls, and container security on AWS or a comparable provider
Strong written communication and ability to work independently
Experience reviewing Solana programs (Rust/Anchor), working at an audit firm, cryptography and key management (HSMs, MPC, PKI), offensive testing across web and mobile, red teaming AI systems, or supporting SOC 2 from the product side is a plus
BMO banking associate providing bilingual credit and lending sales and service remotely in Quebec. Handling customer contacts, credit decisions, compliance, and suspicious - activity reporting.
Principal Information Security Engineer defining scalable security strategy, architecture, automation, cloud, identity, and AI controls. Helping Arctic Wolf protect organizations worldwide and end cyber risk.
Consultant cybersécurité hybride à Montréal chez I - TRACING, pure - player indépendant en sécurité informatique. Conception, déploiement et support de solutions IAM, réseau, systèmes et applications.
Desjardins property technician supporting fire prevention, building safety, management, and build - out projects. Providing technical support, process coordination, user training, and operational guidance.
Ingénieur sécurité principal protégeant l'infrastructure, les produits et les données de Shakepay, plateforme canadienne de services financiers bitcoin. Automatisation, IA, détection et réponse aux incidents.
Senior Application Security Researcher advancing AI - driven application security from prompt to production. Building detection systems and autonomous agentic penetration - testing capabilities.