Senior Security Engineer - Vulnerability & Data/SaaS Security
New
J
JobgetherCybersecurity
Fully remote within Ontario or British ColumbiaFull-TimeSenior
SalaryCompetitive annual base salary of CAD $136,800–$171,000. Annual bonus opportunities based on individual and overall company performance. Equity participation in a publicly traded company. Monthly stipend to support remote work. Annual professional development stipend.
Apply NowOpens the employer's application page
Job Details
- Experience
- 5+ years of professional experience in security engineering
- Required Skills
- AWSPython
Requirements
- 5+ years of professional experience in security engineering, with hands-on ownership of vulnerability management, cloud security, application security, data security, or SaaS security programs.
- Direct experience with vulnerability management and application security platforms such as Tenable, Snyk, and StackHawk, or equivalent technologies.
- Strong experience securing AWS environments and using cloud security posture management tools.
- Experience with endpoint and cloud workload detection and response platforms such as CrowdStrike Falcon.
- Hands-on experience with data security posture management and SaaS security posture management solutions such as Sentra and Reco, or comparable platforms.
- Experience with security findings aggregation or application security posture management platforms such as ArmorCode, including ticketing integrations such as Jira.
- Strong Python scripting and REST API integration skills, including building and maintaining security data pipelines across platforms.
- Experience developing security metrics, KPIs, KRIs, and executive-level dashboards from security tooling data.
- Familiarity with SIEM integrations and security automation or orchestration practices is an asset.
- Strong understanding of PCI DSS, SOX, SOC 2, and ISO 27001.
- Strong analytical and problem-solving skills, including prioritizing risks and driving remediation across teams.
- Experience establishing vulnerability, risk-exception, and SLA governance processes is highly valued.
- Experience in fintech, payments, financial services, or another highly regulated industry is an advantage.
Responsibilities
- Own the vulnerability management lifecycle, including triage, risk-based prioritization, remediation tracking, SLA enforcement, and exception management.
- Review application security and dynamic testing findings and coordinate remediation with relevant teams.
- Develop risk-prioritization models based on severity, exploitability, business criticality, regulatory requirements, and potential impact.
- Lead AWS cloud security posture management and strengthen secure baselines for IAM, networking, storage, encryption, compute, and containers.
- Manage data security posture initiatives, including sensitive-data discovery, classification, data-flow visibility, and monitoring of data replication.
- Operate SaaS security posture capabilities, including SaaS discovery, OAuth and third-party application governance, and data exposure monitoring.
- Partner with application, cloud, platform, and data engineering teams to translate security policies into technical controls and remediation actions.
- Automate findings aggregation, ticket creation, remediation workflows, ownership assignment, SLA tracking, escalations, and risk exceptions.
- Build and maintain API integrations between security platforms and ticketing, SIEM, CMDB, and data warehouse systems; develop Python automation to enrich findings and improve dashboards.
- Define security KPIs and KRIs, produce executive dashboards and recurring reports, and support alignment with PCI DSS, SOX, SOC 2, and ISO 27001.
View Full Description & ApplyYou'll be redirected to the employer's site