Senior Software Security Engineer (Toronto)

Senior Software Security Engineer (Toronto)

25 Aug
|
TimePlay
|
Toronto

25 Aug

TimePlay

Toronto

Senior Software Engineer (Security)

We are looking for a Senior Security Engineer to own and mature our security function across product, infrastructure, operations, and governance. This is a senior individual contributor role for someone who is deeply technical, pragmatic, and comfortable operating with both engineering teams and executive leadership.

This person will be accountable for security risk outcomes, not just advisory input. They will define the security roadmap, lead threat modelling and risk assessment, own incident response, provide security sign-off on architecture, establish core security policies, and report clearly on the organizations security posture.

The ideal candidate is a hands-on security leader who can work closely with Engineering, DevOps, Product, IT, Legal and leadership teams to embed security into how we design, build, deploy, and operate systems.

Key Responsibilities and Duties:

- Define and maintain the company’s security strategy, roadmap, and operating model.
- Identify, assess, and prioritize security risks across product, infrastructure, cloud, data, vendors, and internal operations.
- Lead threat modelling for new products, systems, integrations, and significant architectural changes.
- Own security risk assessment processes and maintain visibility into material risks, control gaps, and remediation plans.
- Partner with Engineering and DevOps to embed secure-by-design practices into dev, deployment, and ops workflows.
- Own the incident response process, including prep, triage, containment, investigation, communication, post-incident review, and remediation tracking.
- Provide executive-level reporting on security posture, key risks, incidents, roadmap progress, control maturity, and remediation status.
- Translate technical security issues into clear business impact, trade-offs, and recommended decisions.
- Contribute hands-on where needed through tooling, automation, configuration, detection logic, documentation, and secure implementation patterns.

Knowledge, Skills and Abilities:

- Strong knowledge of application security, cloud security, infrastructure security, identity and access management, encryption, monitoring, vulnerability management, and secure software dev practices.
- Experience conducting threat modelling and technical risk assessments.
- Ability to review architecture and make sound, risk-based security decisions.
- Strong understanding of incident response processes, including detection,



triage, containment, investigation, communication, and remediation.
- Familiarity with modern cloud platforms, CI/CD pipelines, infrastructure-as-code, secrets management, container security, and DevOps practices.
- Practical knowledge of SOC 2, ISO 27001, or similar security and compliance frameworks.
- Ability to define security policies and standards that are practical, enforceable, and aligned with how teams work.
- Robust analytical judgment and ability to prioritize security work based on likelihood, impact, exploitability, exposure, and business context.
- Ability to communicate technical security risks clearly to engineering teams and business leaders.
- Strong written communication skills, including risk documentation, executive reporting, incident summaries, and policy writing.
- Ability to influence without relying on formal authority.
- Comfortable operating independently in a growing and rapidly evolving security environment.
- Balanced judgement; able to push hard on material risks while remaining pragmatic abot business needs and delivery timelines.

What We’re Looking For:

- We are looking for someone who has operated as a senior security individual contributor (IC) and has been accountable for outcomes, not just recommendations.
- The right candidate may have held titles such as Senior Security Engineer, Security Architect, Application Security Engineer, Cloud Security Engineer, Infrastructure Security Engineer, or Lead Security Engineer.
- You should be comfortable working hands-on with Engineering and DevOps teams rather than auditing from the outside. You should be able to review technical designs, challenge risky decisions, help implement better controls, lead incidents, brief executives, and build a practical roadmap for improving security maturity over time.

We are especially interested in candidates who:
- Have experience owning security risk across multiple domains.
- Can move fluidly between technical detail and executive-level communication.
- Are credible with engineering teams and can provide practical,



implementable guidance.
- Understand how to balance security, delivery speed, operational complexity, and business priorities.
- Have experience supporting SOC 2, ISO 27001, or similar frameworks.
- Can create structure, process, and visibility in an environment where the security function is still maturing.
- Are comfortable being the internal authority for security architecture, incident response, and risk prioritization.
- Prefer collaborative, embedded security work over checkbox compliance or purely advisory review.

What You’ll Gain:

- The opportunity to own and shape the security function at a meaningful level.
- A senior IC role with direct influence on architecture, engineering practices, risk management, and executive decision-making.
- The chance to build a practical, high-impact security program rather than inherit a rigid or overly bureaucratic one.
- Broad exposure across product, infrastructure, cloud, data, vendor risk, compliance, and incident response.
- Close partnership with Engineering, DevOps, Product, IT, Legal, and leadership.
- The ability to define security standards and processes that scale with the business.
- A role where security work is connected directly to business risk, customer trust, and operational resilience.
- A high-trust environment where strong judgment, ownership, and technical credibility are valued.

Working Environment:

- This role operates in a collaborative, fast-moving environment where security must be practical, risk-based, and closely connected to product and engineering delivery.
- The Senior Security Engineer will work cross-functionally with Engineering, DevOps, Product, IT, Legal, and executive leadership. The role requires comfort switching between deep technical work, risk assessment, incident coordination, policy development, and executive communication.
- This is a hands-on senior IC role. The successful candidate should expect to participate directly in technical reviews, control design, incident response, tooling decisions, vendor assessments, documentation, and roadmap execution.
- The environment is best suited to someone who is proactive, structured, collaborative, and comfortable creating clarity where processes are still evolving.

To Apply:

Please email your resume, cover letter and compensations expectations to [email protected]

Subject - Senior Software Engineer (Security)

📌 Senior Software Security Engineer (Toronto)
🏢 TimePlay
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior software security engineer (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: senior software security engineer (toronto) / toronto