Lead agentic AI cybersecurity initiatives, building automated vulnerability discovery and remediation pipelines. Requires deep expertise in offensive security, software engineering, and AI tools.
Responsibilities
Architect and operationalize end-to-end agentic AI patching pipelines spanning detection, fix generation, automated testing, and release across SAST, DAST, SCA, IAST, container, and server vulnerabilities. Use frontier AI models to discover novel vulnerabilities, develop proof-of-concept exploits, and validate AI-generated fixes. Build reusable AI skills, prompts, evaluation harnesses, and tooling. Design AI-driven false positive analysis and exemption processes. Conduct hands-on penetration testing and red team exercises. Extend agentic remediation coverage across various vulnerability types. Design agent prompting, guardrails, and human-in-the-loop controls. Drive integration into CI/CD pipelines. Communicate technical design and progress to senior stakeholders.
Requirements
10+ years hands-on experience across software engineering, offensive security, and defensive security at a principal engineer level. Advanced proficiency in multiple programming languages (Java, C#, C, C++, Python, JavaScript/TypeScript, .NET, Go). Deep fluency in vulnerability classes. Extensive hands-on experience with penetration testing, red teaming, exploit development, reverse engineering, and secure code review. Extensive experience with application security testing tools (SAST, DAST, IAST, SCA). Deep technical fluency with agentic AI coding tools and frameworks (Claude, Devin, Copilot, Windsurf, Cursor, MCP). Strong architectural knowledge of CI/CD, container platforms, cloud-native deployment patterns. Nice-to-have: relevant security certifications (OSCP, OSCE, OSEP, GXPN, GWAPT, CISSP), experience in financial services, public evidence of offensive capability, experience with enterprise vulnerability tooling.
Benefits
Highly competitive compensation and benefits package, multinational organization with 57 offices in 22 countries, laptop and mobile phone, 10 days paid annual leave plus sick leave and national holidays, maternity & paternity leave plans, flexible hybrid policy, comprehensive insurance plan (medical, dental, vision, life insurance, long-/short-term disability), retirement savings plans, higher education certification policy, commuter benefits, extensive training opportunities, on-demand Udemy for Business, coaching opportunities, cutting edge projects, flat and approachable organization, diverse and global work culture.
Security director at Intact, an insurer, protecting customer and broker digital channels and third - party risk platforms. Leading technical teams, governance, strategy, and security operations.
Information Security Advisor conducting cyber - risk assessments and contract reviews for Sun Life, a global financial - services company. Advising business and technology teams on security controls, compliance, and risk remediation.
Enterprise Security Architect securing technology for Vancity, a member - owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk - based cybersecurity solutions.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.