All of your investing, made simple.
Security Researcher
Location
Canada
Posted
3 days ago
Salary
$151.2K - $189K / year
Seniority
Senior
Job Description
Security Researcher
Wealthsimple
• Design and build scaffolds to automate attacker/threat modeling, attack discovery and exploitation techniques at scale • Identify promising attack surfaces and scenarios across Wealthsimple’s stack. • Architect and tune agents, prompts, and toolchains that implement real attacker TTPs. • Define success metrics and evaluation criteria for automations/ai so we can select and fine tune tooling and model use • Design and iterate on multi-step agent strategies that combine observation, planning, action, and self-learning • Improve effectiveness and automation coverage and reduce unproductive actions and loops • Propose and validate new tools or environment features that enable richer or more realistic attacks. • Research and design new AI-driven attack strategies and scenarios in anticipation of what adversaries might misuse LLMs to do in future, then help design detections and defensive measures • Analyze AI behavior and results to discover systemic weaknesses and strengths and improve platform design / outputs and compensate for weaknesses. • Compare different models, prompts, and tool sets on the same scenarios. • Measure meaningful outcomes (bugs found, depth of compromise, time-to-finding, false-positive behaviour). • Benchmark AI-driven testing against our other tooling and manual test results to understand return on investment and where to invest effort and expertise to best advantage • Translate agent outputs into high-quality findings and systemic improvements. • Identify high-confidence vulnerabilities and attack paths. • Analyze findings to uncover recurring vulnerability types and control gaps, then help us fix them • Understand how agents discovered issues and what that implies for our defences. • Share learnings and help build guardrails, detections, systemic framework fixes, libraries, or new agents/experiments
Job Requirements
- 5+ years of experience in offensive security and/or vulnerability research
- Prior work blending automation with offensive security (e.g., custom tooling, fuzzer integrations).
- Strong technical skills in reading and reasoning about code, infrastructure, and designs.
- Experience building, evaluating, or using LLM- or agent-based systems in any domain.
- A strong curiosity about and openness to AI-augmented workflows:
- Comfortable iterating on prompts, tools, and agent behaviours.
- Pragmatic about what AI can and cannot do today.
- Working experience with large language models and how they work; for example, you may have written agent scaffolds
- Technical understanding of networks, endpoint, identity, cloud, encryption, data protection and application deployment stacks.
- Knowledge of standard penetration testing methodologies, including NIST SP 800-115.
- Preferred but not required:
- Published research papers on computer security, language modelling, offensive security tool benchmarking, or related topics; or given talks at Defcon, Blackhat, CCC, or other reputable venues
- Contributed to open-source projects in LLM- or security-related projects, especially those contributing to AI / LLM-specific guardrails and models
- Experience in financial services
- Data science and data pipeline development experience
- Familiarity with Ruby, React, GraphQL, AWS
- Some software or systems engineering experience
- Previous industry experience in Financial Services is preferred.
Benefits
- Top-tier health benefits and life insurance
- Long-term group savings with employer match, through Wealthsimple for Business
- 20 vacation days, 4 wellness days, and unlimited sick and mental health days per year
- 90 days away: work outside Canada for up to 90 days per year
- Employee resource groups, including Rainbow (2SLGBTQ), Women of WS, and Black at WS
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Own enterprise deals end-to-end: Source, develop, and close ARR through new logo acquisition and strategic expansion • Navigate complex buying centers: Build and execute multi-stakeholder strategies across security, data platform, compliance, legal, and procurement organizations • Run disciplined proof of concept: Lead technical evaluations with clear success criteria, tight timelines, and executive alignment to accelerate deals • Master security reviews: Guide customers through vendor risk assessments, architecture reviews, penetration tests, and compliance validation (SOC2, ISO, PCI-DSS, HIPAA) • Build compelling business cases: Quantify value across risk reduction (PCI scope reduction, breach prevention) and enablement outcomes (faster analytics, safe AI access, compliant data sharing) • Negotiate complex contracts: Navigate DPAs, security exhibits, BAAs, indemnities, and enterprise licensing terms to mutually beneficial close • Drive expansion: Develop land-and-expand strategies that grow initial deployments across lines of business, environments, and use cases • Partner strategically: Leverage cloud ecosystem relationships (AWS, Snowflake, Databricks, etc.) and GSI partnerships to accelerate deals
• You will be the operating second to the CISO and own the bank-entity scope of Mercury's 2LOD Information Security program. • Keep the program examiner-ready by maintaining coherent policy architecture and evidenced controls • Own the examiner-ready narrative and coordinate the evidence for OCC, FFIEC, FDIC, and FRB examiner inquiries. • Lead remediation of identified FFIEC IT control deficiencies to ensure charter readiness. • Manage relationships with internal audit and external assessors. • Coach and grow the GRC sub-team while running a recurring training cadence. • Ensure third-party risk evidence holds up to bank-grade scrutiny.
Senior Infrastructure Security Engineer
Dark Matter LabsAt Dark Matter, we design institutional infrastructure for a more equitable, caring and sustainable future.
• Own the security configuration of our identity and collaboration stack: identity and access policies, third-party app governance, DLP, context-aware access, and admin audit. • Build, tune, and maintain detections. Design response playbooks for high-signal alerts. • Harden our cloud footprint, Kubernetes clusters, and CI/CD pipelines. • Own the security posture of the endpoint estate, including MDM configuration and endpoint telemetry. • Lead and participate in security incident investigations end-to-end. • Run threat models and architecture reviews for new internal systems and infrastructure changes. • Work alongside Protocol Security, DevOps, IT Ops, and Product Engineering to raise risks constructively.
• Develop and work with supporting secure AI and LLM usage/integration both in products and within Security; • Develop building blocks to accept payments and move funds; • Stripes Core Products including Connect, Subscriptions, Checkout, RADAR, and Issuing; • Build/Enhance automated threat modeling tooling; • Identify and help reduce security debt across our product portfolio; • Work closely with product engineering teams to design solutions that are secure by default; • Tailor answers to security questions from non-engineers and engineers; • Lead threat modeling discussions and help teams strike the right balance between security, user experience and product advancement; • Scale security effort by empowering engineering teams with automation, security guidance, tooling, patterns and training; • Drive high impact, cross-team security initiatives; • Mentor teammates and others across the organization.




