17 Aug
|
EvenUp
|
Toronto
EvenUp is on a mission to close the justice gap using technology and AI. We empower personal injury lawyers and victims to get the justice they deserve. Our products enable law firms to secure faster settlements, higher payouts, and better outcomes for victims injured through no fault of their own in vehicle collisions, accidents, natural disasters, and more.
EvenUp is backed by top VCs, including Bessemer Venture Partners, Bain Capital Ventures, SignalFire, and Lightspeed. Security at EvenUp is still early enough to shape — and detection and response is the part we're building next, from the ground up. We're looking for a hands-on Senior Security Engineer to build our detection and response program: the telemetry pipelines, the SIEM, the detection content, and the incident response muscle behind them.
The threats that matter most to us don't come out of any box: they live in our own applications and data flows, and detecting them means partnering with the engineers who build those systems. We believe security should accelerate the business, not slow it down. If you're excited about treating detection as an engineering discipline, we'd love to chat. your technical decisions become the foundation.
Detect what actually matters: focus on highest-stakes risks unique to our business, like sensitive data moving to the wrong place, misuse of internal systems, and exposure of health information, as generic detection content cannot address these.
Detection as code: detections are written, version-controlled, tested, and reviewed like software. Direct the vendors, don't answer to them: when using managed providers for 24/7 coverage, you set the requirements, escalation logic,
and quality standards.
Build Our Detection Platform: Lead SIEM evaluation and implementation, design log ingestion and routing pipelines, and make deliberate cost/retention trade-offs across hot search and long-term archive.
Engineer
High-Signal Detections: Develop and tune detection content across cloud, identity, endpoint, SaaS, and application telemetry — with an emphasis on business-logic detections built on our own products' audit events.
Define the Telemetry Contract: Partner with Engineering and DevOps to specify what our applications and infrastructure must log — the audit events that make our most important risks detectable in the first place. Build and maintain IR playbooks and runbooks, coordinate response during security events, run the annual tabletop exercise, and drive post-incident reviews that actually change things.
Detect Data Exposure: Partner with internal teams to detect sensitive data moving where it shouldn't — including PHI — across applications, endpoints, and SaaS. 5+ years in security operations, detection engineering, or incident response, including experience building (not just running) a detection and response capability at a startup or high-growth technology company. ~ Hands-on experience implementing or significantly maturing a SIEM,
including custom log sources and detection content — not just operating one that was handed to you. ~ Strong detection engineering skills: writing detections in Python, SQL, or a rules DSL, managing them in version control, and measuring their quality. ~ Experience with cloud-native telemetry (AWS/GCP/Azure control plane, identity providers, endpoint, SaaS audit logs). ~ Strong programming or automation skills (Python preferred); comfort building integrations and response automation. ~ Experience partnering directly with software engineers to instrument applications for security visibility is a strong plus. ~ Familiarity with securing or monitoring AI/LLM-powered systems is a strong plus. ~ Relevant security certifications (GIAC/GCIA/GCIH, CISSP, etc.) This is a hybrid role, with an expectation of being in our Toronto office three days per week. #Choice of medical, dental, and vision insurance plans for you and your family. ~ Flexible paid time off, sick leave, short-term and long-term disability. ~10 US observed holidays, and Canadian statutory holidays by province. ~ A home office stipend. ~Paid parental leave. ~ A local in-person meet-up program. ~ Hubs in San Francisco and Toronto. (Please note the above benefits & perks are for full time employees) Please note that EvenUp may use AI notetakers and other recording devices in the recruiting process. We are committed to diversity and inclusion in our company. We do not discriminate based on race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. #
📌 Senior AWS Security Engineer (Toronto)
🏢 EvenUp
📍 Toronto