Remote job
Senior Security Engineer - Vulnerability & Data/SaaS Security
Job details
About this role
Role overview Own the day-to-day operation, integration, and continuous improvement of vulnerability management, cloud security posture, and data and SaaS security programs. The role sits at the center of a multi-vendor security tooling ecosystem, correlating findings across platforms, driving remediation, and translating technical risk into metrics and reporting for engineering teams and executive leadership. Remote within Ontario or British Columbia, Canada.
Responsibilities - Run the end-to-end vulnerability management lifecycle across infrastructure, applications, and containers, including triage, prioritization, remediation tracking, and SLA enforcement. - Review and act on application and code-level findings from software composition analysis, static analysis, container and IaC scanning, and dynamic application security testing, driving remediation and SLA compliance across teams. - Maintain risk-based prioritization models that weigh severity, exploitability, business criticality, and regulatory impact. - Own and mature the cloud security posture management program across AWS infrastructure, monitoring for misconfigurations, drift, and control violations against the Common Controls Framework. - Manage cloud misconfiguration findings, partnering with cloud and platform engineering to enforce secure baselines across identity, networking, storage, and encryption. - Operate the data security posture management program, including sensitive data discovery, automated classification, data flow visibility, and replication monitoring across cloud data stores.
Requirements - Senior-level experience in security engineering with a focus on vulnerability management, cloud security, or data security. - Hands-on familiarity with vulnerability scanning, CSPM, DSPM, and SaaS security tooling ecosystems. - Strong working knowledge of AWS infrastructure, including IAM, networking, storage, encryption, and containers. - Experience translating technical findings into metrics, dashboards, and executive-level reporting. - Demonstrated ability to drive cross-functional remediation across engineering, platform, and infrastructure teams. - Understanding of risk-based prioritization that balances severity, exploitability, business impact, and regulatory considerations.
Nice to have - Experience with frameworks such as the Common Controls Framework and aligning security controls to regulatory requirements. - Background operating security programs in payments, fintech, or other regulated environments.
Benefits and work setup - Full-time remote role based in Ontario or British Columbia, Canada, under a flexible-first model.