Information Security Engineer (Vancouver)

Information Security Engineer (Vancouver)

30 Jul
|
Trupanion
|
Vancouver

30 Jul

Trupanion

Vancouver

Company Description Trupanion is a leading provider of medical insurance for cats and dogs in North America.

Our mission is to help loving, responsible pet owners budget and care for their pets.

At Trupanion, we offer a team-oriented, casual, and pet-friendly environment where everyone is encouraged to be themselves.

Job Description We are seeking an Information Security Engineer to help design,operate, and continuously improve

Trupanionssecurity controls and tooling across our Microsoft 365/Azure environment and supporting on-prem systems.

This role balances hands-on ownership of core security platformsparticularly the Microsoft Defender suite and Privileged Access Management (Cyber

Ark)with strong security engineering practices such as automation, integrations, hardening, and detection and response improvements.

The ideal candidate is proactive, detail-oriented, and comfortable partnering with IT and engineering teams to reduce risk, respond to incidents, and deliver practical, measurable security outcomes.

Candidateslocatedin the Seattle area arepreferred ,however strong remote US and CAN based employees candidatesmaybe considered.

Ifyou are basedin the Seattle area, you will have a hybrid remote/in-office schedule where you will work from our casual, pet-friendly office at least 3 days a week.

Key Responsibilities: Engineer,operate, and continuously improve the Microsoft Defender security stack (, Defender for Endpoint, Defender for Identity, Defender for Office 365, Defender for Cloud Apps, Defender Vulnerability Management) to protect endpoints, identities, email, and cloud applications.

Own and administer Privileged Access Managementtool, including onboarding/offboarding privileged accounts, policy and workflow configuration, vault health, upgrades, and integrations.

Integrate Defender and PAM signals with SIEM/SOAR and ITSM workflows to improve detection fidelity, reduce false positives, and accelerate response and remediation.

Design and implement security engineering solutions across cloud and on-prem environments (primarily Azure/M365),including baseline hardening, configuration standards, and security control automation.

Develop andmaintainsecurity tooling lifecycle management (health, licensing, capacity, performance, roadmap, and upgrades), ensuring resilient and supportable operations.

Create andmaintaindetectionengineering content: analytic rules/use cases, alert tuning, threat hunting queries, and automated response playbooks.





Perform security assessments and vulnerability management, including scanning, prioritization, remediation tracking, and validation of fixes in partnership with IT and engineering teams.

Partner with infrastructure, identity/IAM, and application teams to embed security controls into designs and delivery (secure-by-default patterns, CI/CD security checks, and least-privilege access).

Respond to security incidents as an engineering escalation pointtriage alerts,containthreats, coordinate remediation, and drive root-cause fixes and preventive controls.

Produce clear,accurate, and up-to-date runbooks, procedures, and reference architectures for security tooling and operational processes.

Support audits and regulatory exams by providing evidence, control narratives, and technical subject-matterexpertisefor implemented security controls.

Stay current with emerging threats and Microsoft security capabilities; recommend and implement pragmatic improvements to

Trupanionssecurity posture.

Qualifications: Bachelors degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent practical experience). 5+ years of hands-on security engineering experience supporting enterprise security platforms in Microsoft 365/Azure environments.

Relevant certifications (one or more preferred): Microsoft Security (, SC-200/SC-300/SC-100), AZ-500, CISSP, CISM, GIAC, or equivalent.

Skills: Deepexpertisesecuring Microsoft 365 and Azure, including identity, endpoint, email, and cloud security controls.

Demonstrated experience administering Microsoft Defender components and/or XDR/SIEM platforms, including alert tuning, detection engineering, and incident response collaboration.

Experience implementing oroperating

Privileged Access Management (Cyber

Ark preferred) and integrating PAM with identity and security monitoring systems,includingpolicy configuration, privileged session controls,onboarding/offboarding, and operational troubleshooting.

Strong hands-on experience with the Microsoft Defender stack (Defender for Endpoint, Defender for Identity,



Defender for Office 365, Defender for Cloud Apps, Defender Vulnerability Management)andassociated investigation workflows.

Experience with XDR/SIEM operations and integration (, Microsoft Sentinel or equivalent): alert triage, tuning, threat hunting, and automation/playbooks.

Strong identity and access management knowledge, including Entra ID (Azure AD), conditional access, MFA, least privilege, and role-based access control.

Security engineering fundamentals across Windows, macOS, and Linux, plus network and cloud concepts (TLS, DNS, routing, segmentation, logging).

Proficiencyin scripting and automation (Power

Shell and/or Python) to operationalize controls, integrate platforms, and improve reliability.

Experience with vulnerability management and remediation workflows, including scanning, prioritization, validation, and reporting.

Working knowledge of secure SDLC and

DevSec

Opspractices, including CI/CD security checks,secretshandling, and infrastructure-as-code security.

Familiarity with security frameworks and controls (NIST, CIS, ISO 27001) and translating requirements into implementable technical standards.

Strong communicationskills with the ability to explain security issues, tradeoffs, and remediation steps to both technical and non-technical stakeholders.

Excellent problem-solving, analytical skills, and the ability toprioritizeand deliver across multiple concurrent initiatives.

Experience developing andmaintainingrunbooks, technical documentation, security guidelines, and reference architectures.

Compensation: The base pay range for this position is $190,000 - $220,000, on a full-time schedule.

Along with base compensation, Trupanion employees are currently eligible for monthly bonuses.

We want all employees to be invested in Trupanions success, so we grant Restricted Stock Units to all new team members.

Our new hire grants vest over 4 years Additional Information Advantages and Perks: Employer-paid extended health coverage for you and your family Trupanion will partner with Wealthsimple to register your RRSP, pension, etc.

Four weeks of paid time offand 11paid float holidays (you can decide which days are most important to you!) Five weeks, paid, sabbatical after five years of employment Employer-paid medical insurance for one pet (cat or dog) Paid time off to volunteer at nonprofit organizations Open, casual, pet-friendly, and fun work environment

📌 Information Security Engineer (Vancouver)
🏢 Trupanion
📍 Vancouver

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: information security engineer (vancouver) / vancouver

Subscribe to this job alert:

Get the latest job offers by email for: information security engineer (vancouver) / vancouver