01 Aug
|
Constellation Payment Processing
|
Toronto
01 Aug
Constellation Payment Processing
Toronto
Job Description Security EngineerCompensation The expected salary range for this role is between $135,000 and $150,000, depending on experience and qualifications.Reason for Opening Net New positionCompany Constellation Payment Processing is a modern Payment Facilitator (PayFac) empowering SaaS businesses to grow revenue through seamless, embedded payments. As part of Constellation Software Inc. (TSE:CSU) — a global Canadian-based software leader at a $96B market cap and the 7th largest software company in the world — we combine the agility of a specialized payments company with the strength and stability of an established global powerhouse.Role Overview You will co‐own the DevSecOps program—driving continuous security automation, compliance automation, and penetration testing. You will design and orchestrate SAST/SCA/DAST across our services, champion remediation practices, and partner closely with our compliance team to translate control objectives into repeatable, automated evidence. Our customers are ISV vendors who embed payments by integrating with our APIs, SDKs, and webhooks. That means security and compliance aren't afterthoughts—they are product features. You will ensure our developer‐facing surface area is secure by default, establish standards for authentication and authorization (OIDC/OAuth2/JWT, mTLS/JWS for webhooks), key and secret management, request signing, idempotency, rate‐limiting/abuse controls, and secure data handling that minimizes PCI scope for ISVs (tokenization, hosted fields/iframes, PAN vault boundaries, network tokens). You will create secure integration patterns (reference apps, checklists, threat models/DFDs) so partners can implement quickly without compromising controls. Because we operate a multi‐tenant PayFac, you will harden isolation boundaries (network, identity, and data), lead supply‐chain security (SBOMs, signing/provenance, gated deployments), and build continuous evidence for PCI DSS 4.0 (and SOC 2/ISO as needed). You will collaborate with partner security and compliance teams on due‐diligence requests (SIG Lite, AOC/ROCs, shared‐responsibility matrices), and you will own pre‐launch security reviews for new ISV integrations. You will also help run incident response drills and define partner‐facing comms and SLAs for security events. Finally, you will research and implement AI‐assisted security (triage, anomaly detection, auto‐remediation PRs) with appropriate guardrails, and own KPIs that demonstrate multiplier effects—e.G., reduced MTTR, lower false‐positive rates, higher auto‐triage coverage, and faster time‐to‐evidence—so our platform's security posture continuously improves as our ISV ecosystem scales.Responsibilities Own security automation and design, implement, and run the CI/CD security toolchain: SAST, SCA, DAST, container and IaC scanning, secrets detection, SBOM generation,
and policy‐as‐code.Integrate scanners into GitHub/GitHub Actions pipelines with PR gates, auto‐ticketing to JIRA; tune noise, baselines, and break‐glass rules.Establish vulnerability management SLAs, risk acceptance workflow, and metrics dashboards (e.G., MTTR, vulnerability burn‐down).Embed security in the SDLC and create lightweight secure‐coding standards and review checklists for TypeScript/Node, Java, Ruby, React.Run threat modeling (STRIDE/PASTA) and produce DFDs (L0–L2) for new and high‐risk flows.Lead a "security champions" program with engineering squads.Platform & Cloud Security (AWS/EKS): harden EKS workloads (admission controls, pod security, image signing, runtime protection), ECR scanning, and supply‐chain security.Implement and iterate on IAM least‐privilege, KMS/CloudHSM key management, network segmentation, WAF/Shield, CloudFront, GuardDuty/Security Hub, and centralized logging.Validate service‐to‐service auth (mTLS, OIDC, JWT), secrets management (AWS Secrets Manager/SSM), and data protection at rest/in transit (FIPS‐validated crypto).Manage security certificate adoption, our own and third‐party across the company technology stack.Compliance automation: map controls and automate evidence for PCI DSS 4.0 (and SOC 2/ISO 27001 as needed): continuous monitoring, detector‐to‐control mappings, and audit‐ready artifacts.Partner with compliance on policies, risk register, third‐party/vendor assessments, and control testing cadence.Penetration testing & response: scope and coordinate internal and third‐party penetration tests (API, web, mobile, cloud); plan fix‐verification and retests; contribute to incident response playbooks, tabletop exercises, and forensics runbooks; participate in incidentresponse events and be a key contributor on improving security posture.Research & implement AI security tools: evaluate and deploy AI/ML capabilities (LLM‐assisted code reviews, AI triage for SAST/SCA/DAST, anomaly detection over logs/telemetry, drift detection) to reduce toil and increase signal quality—without leaking sensitive code or data.Own outcomes & KPIs: define baselines, instrument dashboards, and continuously tune models/policies to demonstrably improve detection efficacy, remediation speed, and compliance evidence quality.Guardrails & governance: establish safe‐use patterns (PII redaction, repository allowlists, prompt/content controls, human‐in‐the‐loop), document model/feature risks,
and keep audit trails that map to PCI DSS 4.0 controls.Automation & SOAR integration: orchestrate AI‐assisted enrichment and response (e.G., auto‐labeling, deduplication, prioritization, suggested fixes/PRs) across CI/CD, SIEM, ticketing, and chat.KPIs You Will Own MTTR for high‐severity vulns/incidents: ↓ 40–60% vs baseline within 2–3 quarters.Alert noise reduction (precision/FP rate): ≥ 50% reduction in false positives on gated scans and detections.Auto‐triage coverage: ≥ 70% of findings enriched and prioritized by AI with reviewer acceptance ≥ 90%.AI‐generated remediation PRs: ≥ 30% of low/medium issues fixed via assisted PRs passing CI policy.Time‐to‐evidence (PCI 4.0 controls): ↓ 50% for recurring audits via automated control artifacts.Signed‐off service coverage: ≥ 90% of services covered by‐backed detections and scan triage.What You Will Bring 8–10 years in application/cloud security or DevSecOps for high‐availability platforms (fintech/payments ideal).Hands‐on DevSecOps program administration experience with Veracode.Fluent in Terraform for the AWS stack.Strong CI/CD experience (GitHub Actions preferred) and automation in Python/TypeScript/Bash.Solid AWS security fundamentals: IAM, KMS, CloudTrail, Config, Security Hub, GuardDuty, VPC/LBs, WAF/Shield; Kubernetes/EKS hardening experience.Familiarity with microservices, event‐driven systems, and DDD; ability to read code inTypeScript/Java/Ruby and basic ReactJS patterns.Working knowledge of PCI DSS 4.0 control objectives (tokenization/PAN handling, key management, segmentation, logging/retention), plus SOC 2/ISO 27001 concepts.Explicit communication with engineers and non‐technical stakeholders; bias to automate and simplify.Bonus Point: Payments domain exposure: EMV/3DS, PAN vaulting, network tokenization, P2PE, dispute/chargeback flows.How We Will Measure Success 90 days: Security scans embedded in CI for core services with actionable findings; baseline metrics and SLAs defined; initial PCI 4.0 controlmappings complete.6 months: False‐positive rate 12 months: Compliance evidence automation covers priority controls; successful third‐party penetration test with timely remediation; measurable reduction inhigh‐risk vulns and misconfigurations.Team & Reporting This role sits in the CTO organization (Engineering/Platform) and partners daily with compliance, DevOps/SRE, Backend/Frontend teams, and Product.Our Stack AWS (EKS, ECR, KMS, CloudHSM, WAF/Shield, CloudFront, GuardDuty, Security Hub, CloudWatch), GitHub/GitHub Actions, Terraform, Node/TypeScript, Java, Ruby, React, Kafka, MongoDB, Postgres, Redis, Veracode, OWASP ZAP/Burp, AI Tools in Microsoft Teams, JIRA, Development IDEs (Amazon Q, Cursor, Claude Code).Seniority level Mid‐Senior levelEmployment type Full‐timeJob function Information TechnologyIndustries Software Development#J-18808-Ljbffr
📌 Security Engineer (Devsecops) - $135,000 - $150,000 A Year (Toronto)
🏢 Constellation Payment Processing
📍 Toronto