Cybersecurity Engineer (Waterloo)

Cybersecurity Engineer (Waterloo)

07 Oct
|
Venuiti
|
Waterloo

07 Oct

Venuiti

Waterloo

Cybersecurity Engineer

Canadian Citizenship is required for security clearance

Permanent, Full-time

100% in-person in Waterloo, ON

We are seeking a pragmatic Software Security Engineer to join our team. In this role, you will be responsible for securing our software products from the inside out - ensuring that the applications, architectures, and automated pipelines powering our business are resilient against modern, complex cyber threats.

We view software security as a core business enabler, not a compliance exercise or a "gatekeeping" function. You will not simply run automated scanners and assign tickets. Instead, you will work side-by-side with our software engineering teams to analyze attack paths, perform threat modeling early in design phases, prioritize real business risk over raw scanner severity ratings, and build practical security into our up-to-date CI/CD pipelines.

Key Responsibilities

- Architectural Threat Modeling & Design: Partner with software engineers to perform threat modeling on new features, services, and cloud architectures before code is written.
- Contextual Risk Management & Prioritization: Evaluate vulnerability findings across code, containers, cloud infrastructure, and APIs, cutting through scanner severity and noise to determine real exploitability, reachability, and business impact.
- Engineering Collaboration & Influence: Serve as a trusted security advisor to engineers: understand the design, demonstrate impact, and work through practical alternatives, compensating controls, or documented risk acceptance with an accountable owner.
- Pragmatic DevSecOps & Pipeline Integration: Design, deploy, and maintain security guardrails (SAST, SCA,



Secrets Detection, IaC scanning) within modern CI/CD pipelines.
- Attack Surface Analysis: Determine our actual attack surface across cloud and on-prem environments, from both an external/unauthenticated and an internal/identity-based perspective, including assets we don’t know we own.
- Incident Response: Support investigation and containment of compromised systems and credentials, including secrets exposure, and help drive decisions on scope, blast radius, and remediation.

Qualifications

- 5+ Years in Product Security / Application Security (AppSec): Proven hands-on experience securing modern web applications, microservices, and APIs in production software environments.
- Offensive Mindset & Exploitability Analysis: Deep understanding of how adversaries exploit software features.
- Software Engineering & Cloud Literacy: Ability to read code, review pull requests, understand modern application architectures (React, Java/Python/Go, microservices), and navigate multi-cloud (AWS and others) and on-prem environments.
- Identity & Network Architectural Knowledge: Deep understanding of identity protocols (OIDC, OAuth, SAML, MFA), network boundaries, API gateways, load balancers, and Zero Trust concepts.
- Hands-on DevSecOps Experience:



Experience integrating automated security tools into CI/CD pipelines (e.g., GitHub Actions, GitLab CI, Jenkins) with a focus on developer experience.
- Strong Business Acumen & Communication: Ability to articulate technical risk in clear business terms to engineering leads, product managers, and executive leadership.
- Knowledge of Container & Kubernetes Security.
- Incident Response Experience: Hands-on experience investigating and containing security incidents, including compromised credentials and secrets exposure, beyond following a written IR procedure.

Nice-to-Have Qualifications

- Experience with External Attack Surface Management (EASM) and asset discovery tools.
- Active experience in Red Teaming or Ethical Hacking.
- Industry certifications such as GWAPT, OSCP, CISSP, or CCSP (practical experience is valued above certifications).

Why Join Us?

Venuiti believes in universal acceptance for everyone everywhere. We promote diversity of thought, culture, and background, which connects the entire Venuiti family. As such, Venuiti is proud to be an Equal Opportunity Employer. We do not discriminate on the basis of race, color, ancestry, national origin, religion, disability, medical condition, gender identity or expression, age, marital status, military or veteran status, or any other status protected under provincial or federal law. We especially encourage applications from women, minorities, veterans, and individuals with disabilities.

Job Type: Full-time

Pay: $100,000.00-$125,000.00 per year

Education:

- Master's Degree (preferred)

Experience:

- Cybersecurity: 6 years (required)

Work Location: In person

📌 Cybersecurity Engineer (Waterloo)
🏢 Venuiti
📍 Waterloo

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cybersecurity engineer (waterloo) / waterloo

Subscribe to this job alert:

Get the latest job offers by email for: cybersecurity engineer (waterloo) / waterloo