
Security Engineer
- Canada
- Permanent
- Temps-plein
- Embed application and cloud security into our engineering lifecycle, partnering with developers at every stage
- Implement and manage automated scanning solutions (SAST, DAST, dependency, IaC) in CI/CD pipelines
- Lead triage and remediation of vulnerabilities, coordinating across engineering, product, and compliance
- Build and tune cloud security controls (IAM, monitoring, logging, container and network security)
- Provide developer-friendly security guidance and code review support
- Support compliance initiatives (SOC 2, ISO 27001, NIST CSF) with strong technical evidence
- Establish scalable detection and monitoring that ties into SIEM/SOC workflows
- Google Cloud Platform
- Kubernetes
- PostgreSQL
- Redis
- Python
- Vue.js
- 3+ years of hands-on security engineering or application security experience
- Proven ability to design, implement, and maintain automated security testing
- Strong knowledge of OWASP Top 10, CWE Top 25, and CIS Controls
- Working experience with cloud-native environments (we use GCP)
- Familiarity with compliance frameworks and audits
- Ability to read and write high-quality application code
- A builder's mindset: willing to be hands-on now, while shaping the foundation for a growing security team
- A digital-first environment, so you can do your best work anywhere in Canada
- A MacBook shipped to you and a budget for peripherals of your choice
- Flexible working hours (in coordination with your team)
- Flexibility to work abroad for up to 8 weeks at a time
- Regular social events, even while working remotely
- Annual peripheral refresh
- Competitive salary and opportunities for promotion
- High-quality health insurance, active from your first day
- HSA and Wellness Accounts
- Generous vacation and time off plan
- Employee Stock Option Plan for everyone (ESOP)
- RRSP with an employer matching component