- As a Senior Software Engineer on our Security team, you’ll help shape the direction of our security tooling and AppSec practices and lead high-impact security work across the company
- Your work spans offense and defense: hardening how our products are designed and built, breaking them to surface what matters, and building the tooling and AI that let engineers move quick without creating risk
- You’ll report to our Staff Software Engineer - Security and work closely with product engineers, DevOps, and Fraud
- Expect high autonomy, frequent collaboration, a fast pace, and reliance on your own initiative
- You’ll take security initiatives end-to-end, mentor other engineers, and raise the bar for security practices across engineering
- Help shape the technical direction of our security tooling and AppSec practices
- Lead secure design across major engineering projects, from threat modeling through architecture
- Design and evolve our DevSecOps architecture, deciding how security is embedded across the SDLC
- Build and extend the in-house security tooling and find current and innovative ways to identify and remediate issues
- Identify and implement new ways to use AI to automate and scale our security work
- Perform advanced offensive security work, chaining vulnerabilities and building proofs of concept that demonstrate real business impact
- Enable developers to write more secure code and ship security work faster via training and AI-powered tooling
- Mentor and develop engineers on the team, and set the bar for what good security work looks like
- Our Technology:
- Services are authored as K8s-based microservices powered by Python FastAPI backends and Typescript React front-end code
- Apps are built upon Postgres, Redis, Kafka, Elasticsearch, and Snowflake
- Our infrastructure runs on AWS and leverages hosted infrastructure technologies such as EKS, MSK, Elasticache, and RDS. We use Istio for service mesh, Helm, TF and Crossplane for IAC, and Kyverno for policy-as-code enforcement
- Vulnerabilities are managed through in-house, AI-native custom tooling that you’ll contribute to. We orchestrate open-source tools through this custom platform
- Security and application logs/metrics/events are managed through Datadog
- Our security stack is currently evolving as we select and quickly roll out recent tools. You’ll play a key role in the selection and deployment of these
- As an AI-First engineering organization, we leverage modern AI development workflows using tools such as Cursor, Claude, and internally built AI agents to accelerate implementation and iteration across our codebases. You’ll own and advance our AI infrastructure in this role
Benefits
- Competitive base salary
- Yearly learning & development allowance
- Bi-annual performance &
compensation reviews
- Generous equity options
- RRSP & 401k employee contribution plan
- Health, dental, & vision insurance on day one
- Parental leave programs
- Wellness reimbursement
- Supplemental Life Insurance
- Unlimited PTO (yes, really!)
- Recharge days throughout the year
- Office in Toronto
- Permanent remote flexibility
- Work-from-home allowance- 5+ years working in security (AppSec, DevSecOps, offensive security, or similar)
- Track record of leading security initiatives and mentoring or developing other engineers
- Experience designing and embedding security across CI/CD pipelines and the SDLC
- Experience leading threat modeling and secure design across engineering projects
- Comfortable writing and maintaining code (Python preferred)
- Professional offensive security experience, with a proven ability to find, chain, and exploit complex vulnerabilities in applications and infrastructure
- Hands-on cloud infrastructure or cloud security experience (AWS, Kubernetes)
- Strong communicator who can influence and drive security work across engineering, DevOps, and leadership
- Relevant security certifications (e.g., Burp Suite Certified Practitioner, KCSA, AWS SCS, or similar)
- Professional software development experience
- Published security research, CVEs, or conference talks
- Experience applying AI/LLMs to security or engineering workflows
- Open-source security tool development or contributions
- Mobile development or mobile security experience
📌 Senior Software Engineer (Security) (Canada)
🏢 super
📍 Canada