Senior Software Security Engineer
Toronto, Ontario, Canada · Full Time
Be the first to apply
- Experience
- Any
- Salary
- —
- Openings
- 1
- Posted
- 3 weeks ago
- Work mode
- In office
- Resume
- Required to apply
Where you'll work
Sign in to tell us what does and doesn't work for you here — it sharpens every match we show you.
Job description
About the Role
We seek an experienced Senior Software Security Engineer to lead and develop our security capabilities across product development, infrastructure, operations, and governance. This senior individual contributor position demands a technically proficient, pragmatic professional adept at working collaboratively with engineering teams and senior executives alike.
The appointed candidate will hold accountability for security risk management outcomes, shaping the security strategy, spearheading threat modeling and risk assessments, overseeing incident response, endorsing secure architectural solutions, formulating core security policies, and providing transparent reports on our security posture.
Key Responsibilities
- Develop and oversee the organization's security strategy, roadmap, and operational framework.
- Identify and prioritize security risks spanning product, infrastructure, cloud services, data, vendors, and internal processes.
- Lead threat modeling activities for new products, system integrations, and major architectural changes.
- Manage risk assessment protocols, track significant risks, control weaknesses, and remediation efforts.
- Collaborate with Engineering and DevOps to integrate secure-by-design principles within development, deployment, and operational workflows.
- Own the end-to-end incident response lifecycle including preparation, triage, containment, investigation, communication, post-incident review, and remediation tracking.
- Provide executive-level security posture reports covering risks, incidents, roadmap advancements, control maturity, and remediation updates.
- Translate complex technical security issues into clear business impact statements and actionable recommendations.
- Contribute hands-on by developing tooling, automation solutions, detection rules, documentation, and implementing secure patterns.
Knowledge, Skills, and Abilities
- Comprehensive expertise in application security, cloud and infrastructure security, identity and access management, encryption, monitoring, and vulnerability management, along with secure software development methodologies.
- Proficient in conducting threat modeling and technical risk evaluations.
- Skilled in architectural reviews to make informed, risk-based security decisions.
- Thorough understanding of incident response processes encompassing detection to remediation.
- Familiarity with contemporary cloud platforms, CI/CD pipelines, infrastructure-as-code, secrets management, container security, and DevOps practices.
- Practical experience with security and compliance frameworks such as SOC 2 or ISO 27001.
- Capability to establish practical and enforceable security policies aligned with team workflows.
- Strong analytical judgment and ability to prioritize based on risk likelihood, impact, exploitability, exposure, and business context.
- Effective communication skills to convey technical security risks to both engineering and business stakeholders.
- Advanced written skills for risk documentation, executive reports, incident summaries, and policy development.
- Influence skills without formal authority and ability to work independently within a rapidly evolving security setting.
- Balanced decision-making, focusing on material risks while considering business requirements and delivery timelines.
Ideal Candidate Profile
- Experienced as a senior individual contributor responsible for delivering security outcomes.
- Previous titles may include Senior Security Engineer, Security Architect, Application Security Engineer, Cloud Security Engineer, Infrastructure Security Engineer, or Lead Security Engineer.
- A hands-on collaborator who partners with Engineering and DevOps teams, capable of technical design reviews, risk mitigation, incident leadership, executive briefings, and security roadmap development.
- Experienced managing security risks across multiple domains and adept at balancing technical details and executive communication.
- Familiar with SOC 2, ISO 27001 or comparable compliance frameworks and able to implement scalable security processes.
- Comfortable serving as the authoritative security figure for architecture, incident handling, and risk prioritization in a maturing environment.
- Prefers integrated security efforts versus compliance checklists or pure advisory roles.
Benefits and Opportunities
- Lead and shape the organization's security function at a strategic level.
- Senior individual contributor role influencing architecture, engineering practices, risk management, and executive decision-making.
- Opportunity to build a flexible, impact-driven security program.
- Engagement across product, infrastructure, cloud, data security, vendor risk, compliance, and incident management.
- Close collaboration with cross-functional teams including Engineering, DevOps, Product, IT, Legal, and executives.
- Authority to define scalable security policies and processes aligned with business objectives.
- Role connecting security work directly with business risk, customer trust, and operational resilience.
- High-trust, autonomy-rich environment valuing judgment, ownership, and technical credibility.
Work Environment
- Dynamic, collaborative environment emphasizing practical, risk-based security integrated with product and engineering delivery.
- Cross-functional interaction encompassing technical work, risk assessments, incident management, policy creation, and executive communications.
- Hands-on senior individual contributor role including technical reviews, control design, incident leadership, tooling decisions, assessments, and execution of security initiatives.
- Suited to proactive, organized, collaborative professionals who can impose structure in evolving processes.