Senior Security Engineer managing security initiatives for R&D and production applications. Collaborating closely with teams to enhance security practices within a cloud environment.
Responsibilities
Evolve and expand our existing security activities – threat modeling, risk mitigation, observability, incident response. Manage and execute security projects based on internal and external inputs such as our bug bounty program, pentesting, or other gap analysis.
Implement security improvements as an individual contributor as well as in collaboration with our teams. Set the standard for how new code being shipped meets our security needs.
Advocate for security. Build a culture of security ownership rooted in shared values
Managing security roadmaps from a corporate-wide perspective to meet the needs of various stakeholders including enterprise sales enablement.
Work in a predominantly AWS cloud environment with some Google Cloud Platform services. Our services are built on Django and get continuously deployed.
Requirements
5+ years of experience in application security or related fields, with a strong ability to collaborate with application development teams.
Familiar with modern security practices and technologies
You understand security in a cloud provider context (we use primarily AWS with some GCP services as well) and can help move us toward a Zero Trust architecture.
Familiar with managing infrastructure as code with automation tools such as Terraform
Proficient in threat modelling, architecture design review processes, and familiar with common attack vectors and exploitation techniques.
Strong communication skills, capable of articulating security concerns and solutions to both technical and non-technical stakeholders.
Knowledge of development security best practices for mobile and web applications.
Bachelor’s degree in Computer Science, Engineering, or a related discipline, or an equivalent combination of education and experience.
Benefits
A noble mission that creates meaningful, fulfilling work
A team that cares deeply for customers and for each other
Flexible, remote first work environment
Professional learning and development for all role levels
An awesome and welcoming Toronto HQ
Competitive health benefits that start on day one
A management team focused on performance, growth, engagement and connection
Our winning strategy and market potential
Innovative PTO policy with lots of time and space for self-care
Passionate customers that believe in us—and what we do
A chance to work with new tech like generative AI—and see the customer impact
Lead agentic AI cybersecurity initiatives, building automated vulnerability discovery and remediation pipelines. Requires deep expertise in offensive security, software engineering, and AI tools.
Security director at Intact, an insurer, protecting customer and broker digital channels and third - party risk platforms. Leading technical teams, governance, strategy, and security operations.
Information Security Advisor conducting cyber - risk assessments and contract reviews for Sun Life, a global financial - services company. Advising business and technology teams on security controls, compliance, and risk remediation.
Enterprise Security Architect securing technology for Vancity, a member - owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk - based cybersecurity solutions.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.