Job Closed
This listing is no longer active.
Website Operations Platform for Drupal & WordPress
Staff Security Engineer
Location
Canada
Posted
60 days ago
Salary
0
Seniority
Lead
Job Description
Staff Security Engineer
Pantheon Platform
• Design and implement security primitives across GCP including org policy hierarchies, VPC Service Controls perimeter design, Workload Identity Federation, CMEK key management strategy, and Secret Manager governance ensuring secure-by-default infrastructure across all engineering teams. • Define, document, and champion processes and practices for a secure Software Development Life Cycle (SDLC). • Be a driving force in establishing a strong security culture within platform engineering teams. • Lead Threat Modeling as a core principle for the Secure by Design strategy with particular focus on GCP-hosted, container-based, multi-tenant architectures. • Conduct Secure Code and Architecture Design Reviews, including threat modeling and technology/risk-based assessments. • Automate application security testing and controls, integrating them directly into the CI/CD pipelines. • Own the deployment, operation, and tuning of security tools (SAST, DAST, IAST, and CSPM), with a focus on platforms like CodeQL and Wiz.io including deep integration with GCP Security Command Center (SCC) and Binary Authorization for container workload protection. • Partner with engineering to effectively prioritize and remediate identified vulnerabilities. • Own the software supply chain security program, including SCA tooling, Artifact Registry vulnerability scanning, and Binary Authorization policy enforcement across GCP. Coordinate with the Security Operations team on penetration testing scope and findings remediation.
Job Requirements
- Minimum of 10+ years of overall experience, with at least 5+ years dedicated to Application Security.
- Proven, hands-on experience designing and operating security controls in Google Cloud Platform at scale including IAM and Workload Identity Federation, VPC Service Controls, CMEK and Secret Manager, Binary Authorization, GKE hardening, and Security Command Center.
- Deep, hands-on experience in Secure by Design development practices, including guiding Secure Architecture and System Design.
- A builder first demonstrated experience designing and shipping reusable security primitives (Terraform modules, policy libraries, pipeline integrations) that engineering teams adopt, not just policies that exist on paper.
- Hands-on experience writing production-grade, secure-by-default Terraform for GCP deployments including org policies, IAM bindings, VPC configurations, and GKE cluster hardening.
- Ability to build maintainable components in Go or Python.
- Hands-on experience with Jenkins, Cloud Build, or CircleCI (bonus points for experience with reusable workflows).
- Proven ability to build, select, and implement application security tools, and integrate them into CI/CD pipelines.
- Google Professional Cloud Security Engineer certification strongly preferred. CISSP, CCSP, or CKS (Certified Kubernetes Security Specialist) are a plus.
- Bachelor's degree in Computer Science or equivalent practical experience.
Benefits
- Industry competitive compensation and equity plan
- Paid Time Off (PTO), Paid Sick Leave (PSL) and 11 Paid Company Holidays
- Full medical coverage (Extended health care, dental, vision)
- Top-of-line equipment
- In-office workspace (Vancouver, BC Canada)
- Monthly allowance for wellness, reading and access to LinkedIn Learning for continued development
- Events and activities both team-based and company wide that inspire, educate and cultivate
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Research Assistant – Software Security, Program Analysis
Fraunhofer-GesellschaftAngewandte Forschung seit 75 Jahren. Technologie, Innovation, Wertschöpfung.
• Contribute to applied research projects in software security in collaboration with academic, industry, and public-sector partners • Develop and scientifically evaluate new methods for detecting, analyzing, verifying, and remediating software vulnerabilities • Conduct research on novel static and dynamic program analysis techniques, including fuzzing and the application of AI methods for vulnerability detection • Perform security analyses of real-world software systems, including: code reviews • Penetration testing and security assessments • Risk and threat analyses • Participate in publicly funded research projects and industry collaborations • Prepare project reports and scientific publications • Present research results at national and international conferences
Chef
Instasks App platformInstasks App is a Professional Concierge Service. The app provides top-tiered professionals and clients with an online platform. Our unique approach to building an App is to give the client and the provider instant bookings and an easy process of all services. Providers receive custom requests for their specialized skills. The app takes care of all invoicing between client and provider with a detailed invoice. We track providers' locations for the client's en route to any job. We created a portal platform to guide you in listing your professions. The platform provides you with schedules, invoicing and credit card processing as part of the enhanced technology. Clients will have a choice to give the providers reviews and star ratings to ensure our elite services when booking on our app. Our mission is to help all providers strive to achieve their financial and independent goals. Opportunities to providers over the age of 18 and, by law, over the age of 21 for any tasks serving liquor.
Role Description We are looking for a chef to join our team and prepare delicious meals for our customers. Chef responsibilities include: - Studying recipes, setting up menus, and preparing high-quality dishes. - Delegating tasks to kitchen staff to ensure meals are prepared in a timely manner. - Informing the wait staff about daily specials. - Ensuring an appealing plate presentation. - Supervising cooks and assisting as needed. - Slightly modifying recipes to meet customers’ needs and requests (e.g., reduce salt, remove dairy). - Monitoring food stock and placing orders. - Checking the freshness of food and discarding out-of-date items. - Experimenting with recipes and suggesting new ingredients. - Ensuring compliance with all health and safety regulations within the kitchen area. Qualifications - Proven work experience as a Chef or cooking. - Hands-on experience with various kitchen equipment (e.g., grilles and pasta makers). - Advanced knowledge of culinary, baking, and pastry techniques. - Leadership skills. - Ability to remain calm and undertake various tasks. - Excellent time management abilities. - Up-to-date knowledge of cooking techniques and recipes. - Familiarity with sanitation regulations. - Culinary school diploma preferred. Requirements - Requires working from detailed instructions and occasional independent decision-making. - Ability to read, analyze, and interpret documents such as safety rules, operating and maintenance instructions, or procedural manuals. Benefits - Build your future with a secure & safe platform. - Be your own boss by choosing the TASKS that best suit your schedules. - Build your income to help increase your revenue. - Book tasks that are within a 15-mile radius. - Health & well-being of clients and providers are our highest priorities. Company Description Instasks App is a Professional Concierge Service. The app provides top-tiered professionals and clients with an online platform. Our unique approach to building an App is to give the client and the provider instant bookings and an easy process of all services. - Providers receive custom requests for their specialized skills. - The app takes care of all invoicing between client and provider with a detailed invoice. - We track providers' locations for the client's en route to any job. - Our mission is to help all providers strive to achieve their financial and independent goals. - We created a portal platform to guide you in listing your professions. - Clients will have a choice to give the providers reviews and star ratings to ensure our elite services. - All providers must go through a third-party background check only after you are confirmed for a job. - Each provider will go through etiquette training to ensure that every provider is a friendly and well-mannered individual.
Senior Product Security Engineer
HistoSonicsHistoSonics, founded in 2009, is a medical technology company specializing in the development of the Edison Platform, a noninvasive robotic system that uses his
Title: Senior Product Security Engineer Location: Remote (contiguous United States) Job Description: Salary Range:$120,000.00 To $140,000.00 Annually HistoSonics is a commercial-stage medtech company advancing the Edison System, a novel non-invasive sonic beam therapy based on histotripsy. Since receiving FDA De Novo grant for the non-invasive destruction of liver tumors in 2023, the company has progressed beyond initial market entry into commercial expansion, reimbursement momentum, and ongoing clinical and pipeline development. In addition to its current liver tumor indication, HistoSonics is pursuing future indications across multiple applications including kidney, pancreas, prostate, neuro, women's health, and other significant underserved human health areas, to realize the broader potential histotripsy across multiple disease states and medical specialties. We offer an exciting work culture where cutting-edge science meets real-world application, and each team member's contribution is important to our success in ensuring our physicians and their patients get what they need most. Location: Remote (contiguous United States) Travel: Quarterly - 3 days on site (likely Plymouth, MN) Position Summary: (Why this role matters) The Product Security Engineer will be part of a growing team responsible for contributions to the cybersecurity stature of the HistoSonics Edison Histotripsy system. The role will require you to work cross-functionally with hardware, firmware, software, quality, and regulatory teams to drive implementation of a wide array of security controls and best practices into the Edison system. Key Responsibilities: (What you'll do) - Threat Modeling and Risk Assessment: Execute and document risk assessments of the cybersecurity stature of various subsystems and components within the Edison system, in partnership with cross-functional stakeholders and subject matter experts. - Secure Design: Guide product engineering teams to drive inherent risk remediation via documenting and implementing requirements and adoption of best practices to reduce residual risk and improve the cybersecurity stature of the Edison system. Support development and documentation of verification plans to ensure control sufficiency. Analyze and document impact due to proposed changes. - Regulatory Compliance: Support FDA premarket submissions by preparing cybersecurity documentation including risk management reports, threat model, MDS2 and cybersecurity whitepaper. - Postmarket Compliance: Support cyber lifecycle management activities including vulnerability monitoring, assessment, and documentation needs. - Maintain a positive, results-oriented work environment, building partnerships and modeling teamwork, communicating to team members in an open, balanced, and objective manner. - Create/ maintain a clean, safe, and effective work environment. Qualifications and Skills: - 8 years of combined professional experience in Information Security, Risk Management, and or/IT-centric cybersecurity roles is required. - Bachelor's degree in an engineering, science, or technical discipline preferred. - In lieu of degree requirement: relevant technical, cybersecurity, or medical device on-job experience is considered. - Expertise with cybersecurity vulnerability analysis methodologies including CVSS is required. - Expertise with cybersecurity methodologies for identifying design weakness is required: (threat modeling/STRIDE, CWE) - Familiarity with cybersecurity, information security, and medical device standards regulations is required: (HIPAA, FDA, ISO 27001) - Familiarity with methodologies for assessing cybersecurity residual risk is required: (CVE analysis, review of technical design documentation, compensating controls analysis, CVSS MD rubric) - Relevant security certifications are preferred. - In-depth, systemic technical knowledge of complex, dynamic, and varying medical device systems. - Excellent written and verbal communication skills, with the ability to participate in engineering discussions. - Strong analytical, critical thinking, and problem-solving skills with an attention to detail. Benefits: We offer a comprehensive benefits package for full-time employees. This includes health, dental, and vision insurance, life, short-term and long-term disability insurance, 401(k), paid time off, and more. We are an equal opportunity employer and value diversity at our company. We do not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, veteran status, or disability status. #LI-Remote
Oracle Security Administrator
Inova HealthWe are Inova, Northern Virginia and the Washington, D.C. metropolitan area’s leading nonprofit healthcare provider.
• Meets all defined service levels and defined performance objectives within Inova IT for Supporting our Business Customers. • Serves as a leader for modifications or enhancements to use Oracle Security Architecture. • Coordinates all security designs with various Business Units. • Analyzes and implements Oracle security requirements. • Recommends and develops security measures to protect information against unauthorized modification or loss. • Works closely with both Oracle technical and functional teams to ensure the success of the overall Oracle solution. • Collaborates with Oracle Applications and business teams to design and implement technical security solutions for Oracle and associated bolt-on applications. • Adheres to and delivers ITGC controls and procedures. • Supports audits both internal and external. • Supports additional projects and duties as assigned.


