Website Operations Platform for Drupal & WordPress
Senior Security Engineer
Location
Canada
Posted
28 days ago
Salary
$121K - $151K / year
Seniority
Senior
Job Description
Senior Security Engineer
Pantheon Platform
• Implement “Security by Design” within agile software development and cloud-native environments • Act as a Subject Matter Experts (SMEs), mentoring, coaching, and supporting all security engineering efforts across the organization • Define, organize, and implement application security policy, process, standards, and guidelines • Helping engineering teams design and build high-performing, secure applications by mitigating security issues in a risk-based manner • Define, document, and champion processes and practices for a secure Software Development Life Cycle (SDLC) • Be a driving force in establishing a strong security culture within platform engineering teams • Lead Threat Modeling as a core principle for the Secure by Design strategy • Conduct Secure Code and Architecture Design Reviews, including threat modeling and technology/risk-based assessments • Automate application security testing and controls, integrating them directly into the CI/CD pipelines • Responsible for the deployment, operation, and tuning of security tools (SAST, DAST, IAST, and CSPM) • Partner with engineering to effectively prioritize and remediate identified vulnerabilities • Manage tools for Software Composition Analysis (SCA) to ensure supply chain security
Job Requirements
- Minimum of 6+ years of overall experience
- At least 2+ years dedicated to Application Security
- Deep, hands-on experience in Secure by Design development practices
- Extensive experience securing production systems in Cloud environments (e.g., AWS, Azure, GCP)
- Ability to build maintainable components in Go or Python
- Hands-on experience with jenkins/cloud pipelines/ circleci
- Experience working with containerization (e.g., Docker, OCI), Terraform, and Kubernetes (K8s)
- Proven ability to build, select, and implement application security tools, and integrate them into CI/CD pipelines
- Bachelor's degree in Computer Science or equivalent practical experience
Benefits
- Industry competitive compensation and equity plan
- Paid Time Off (PTO), Paid Sick Leave (PSL) and 11 Paid Company Holidays
- Full medical coverage (Extended health care, dental, vision)
- Top-of-line equipment
- In-office workspace (Vancouver, BC Canada)
- Monthly allowance for wellness, reading and access to LinkedIn Learning for continued development
- Events and activities both team-based and company wide that inspire, educate and cultivate
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Software Engineer – Application Security
BackblazeBackblaze is the cloud storage innovator delivering a modern alternative to traditional cloud providers.
• Improve application security across software used to enable Backblaze B2 Cloud Storage and Computer Backup • Build security into how the product is used, how data is stored and how customers can use it • Leverage AI tools and software for building new and maintaining existing software security features • Perform security assessments and code reviews on internal and external customer-facing applications • Work closely with engineers to remediate security vulnerabilities using AI tools • Develop security automation and tooling to improve security • Support bug bounty program and vulnerability handling
Senior Product Security Engineer
MongoDBMongoDB, originally called 10gen, is a software development company. Since 2007, MongoDB has created an open-source, document-oriented database to help clients
Role Description Want to secure the future of data management and AI/ML? At MongoDB we are transforming industries and empowering developers to build amazing AI/ML-powered apps that people and enterprises use every day. We are the leading modern data platform and the first database provider to IPO in over 20 years. Overall, the worldwide data management software market is massive (IDC forecasts it to be $138 billion by 2026!). Join our team and be at the forefront of innovation and creativity. With a strong security engineering background, you’re looking for a role that gives you the freedom to increase MongoDB’s resonance with customers by strengthening our core database products. You’re passionate about solving hard security engineering problems while putting a strong emphasis on customer experience, leveraging your own significant experience. You enjoy collaborating with different teams to innovate and implement pragmatic solutions. Responsibilities - Take ownership, define strategy, and drive improvement for parts of our program such as fuzzing, threat modeling, secrets management, or container security. - Advocate for and lead complex security projects from inception through completion. - Drive architecture, patterns, and processes across Server Engineering that make security the easiest path. - Partner closely with engineering teams to design and implement security controls across our software and systems. - Research and POC new attacks against our systems. Plan and perform product security assessments including architecture review, threat modeling, code review, pen testing, and general security consulting to proactively build security controls. - Serve as a security subject matter expert for software security and architecture. - Educate the engineering org on security through CTFs, lunch-and-learns, and one-on-one mentorship. Qualifications - 7+ years of experience in application security, software security, or product security. - Proven experience in C++ programming, performing security assessments on low-level codebases, and implementing remediation strategies for memory-related security flaws such as buffer overflows and memory leaks. - Programming experience and ability to contribute code back to our environments. - A strong track record of partnering with software engineers: leading threat models, performing security design reviews, and developing an understanding of their product space to form pragmatic security recommendations and influence their prioritization. - Comfortable communicating complex technical issues in a simple manner that builds trust with a variety of audiences. - Demonstrated ownership of security initiatives, with the ability to deliver results autonomously or collaboratively. - Can work flexible hours occasionally to collaborate with US-based colleagues. Nice to Haves - Subject matter expertise in database security, or data security. - Knowledge of database engines, database internals, or applied cryptography. - Experience contributing or partnering with security researchers to identify vulnerabilities that eventually are published CVEs or administrative responsibilities of a CNA. Success in this role means - Seeing projects through from conception to completion in order to deliver new services or capabilities for the team. - Establishing yourself as a go-to person for discussing security topics. Company Description MongoDB is built for change, empowering our customers and our people to innovate at the speed of the market. We have redefined the database for the AI era, enabling innovators to create, transform, and disrupt industries with software. MongoDB’s unified database platform—the most widely available, globally distributed database on the market—helps organizations modernize legacy workloads, embrace innovation, and unleash AI. - Our cloud-native platform, MongoDB Atlas, is the only globally distributed, multi-cloud database and is available across AWS, Google Cloud, and Microsoft Azure. - With offices worldwide and nearly 60,000 customers—including 75% of the Fortune 100 and AI-native startups—relying on MongoDB for their most important applications, we’re powering the next era of software. - Our compass at MongoDB is our Leadership Commitment, guiding how and why we make decisions, show up for each other, and win. - To drive the personal growth and business impact of our employees, we’re committed to developing a supportive and enriching culture for everyone. - From employee affinity groups, to fertility assistance and a generous parental leave policy, we value our employees’ wellbeing and want to support them along every step of their professional and personal journeys.
Junior Security Questionnaire, Compliance Analyst
OpsArmyScreen top international talent, onboard, run payroll, and manage performance.
• Review and complete customer security questionnaires (e.g., SIG, CAIQ, VSA, and custom formats) with high accuracy • Assist with security-related sections of RFPs and RFIs, ensuring responses are clear, consistent, and submitted on time • Partner with Sales, Legal, Engineering, Product, and Security to gather and confirm required information • Maintain a centralized, up-to-date repository of security documentation, FAQs, and standard responses • Learn and document security controls, processes, and certifications (e.g., SOC 2, ISO 27001) • Support follow-up security reviews by tracking questions, clarifications, and approvals • Help build templates, checklists, and lightweight processes to improve future response efficiency
Security Engineer
HealthMark GroupFounded in 2006, HealthMark Group is a software-driven company that provides health information management solutions to streamline the flow of patient information, as well as the l
• Design, implement, and maintain AWS-focused cloud security architecture aligned with HIPAA, NIST, and HITRUST. • Secure AWS environments using IAM, Organizations, CloudTrail, Config, GuardDuty, Security Hub, KMS, and network security controls. • Build, review, and maintain Infrastructure-as-Code using Terraform, ensuring security controls are versioned, auditable, and enforced by default. • Develop secure Terraform modules, guardrails, and policy-as-code to prevent misconfiguration and drift. • Partner with Development and CloudOps teams to implement DevSecOps practices, including CI/CD pipeline security and IaC scanning. • Establish and manage identity and access standards across AWS and Microsoft Entra. • Support SOC 2 Type II, HITRUST, HIPAA, and PCI audits with a focus on cloud control evidence. • Monitor cloud environments, triage security events, and respond to incidents in partnership with the MSP. • Maintain documentation related to cloud security architecture, IaC standards, and incident response. • Provide security mentorship and cloud security expertise across the organization.




