Information Security Specialist

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 5,001-10,000H1B SponsorCompany SiteLinkedIn

Location

Canada

Posted

1 day ago

Salary

$175K - $200K / year

Seniority

Lead

Job Description

Information Security Specialist

Teladoc Health

• Champion and execute the overall corporate IT security strategy, roadmap and governance structure, partnering with internal risk/compliance, operational, clinical, technical and business teams as well as external customers and relevant third-party stakeholders • Understand business processes and information system requirements and the associated information risk in those processes • Liaise closely with internal Canadian legal/privacy team to ensure adherence and alignment with Canadian privacy, data governance and regulatory requirements, and the business’ contractual commitments • Work directly with the Canadian commercial team and client base to understand market business and functional requirements and provide compliance, security, and risk assessment support and guidance as required • Establish and execute formal vendor security assessments, including pre-onboarding due diligence and ongoing monitoring of third-party vendors and sub-processors handling sensitive information • Implement all information security, including security breaches, business continuity, and regulatory compliance programs including legal requirements, industry regulations, and best practices (e.g., ISO27001, SOC 2 Type II, etc.) • Lead end-to-end SOC 2 Type II and ISO 27001 audit cycles, including gap assessments, evidence collection via GRC tooling (e.g. Vanta) and act as the primary liaison for external auditors to support certifications • Develop information security guidelines, procedures, and responsibilities and support the development and implementation of technical and administrative security controls and related training and education • Oversee technical incident response planning and implementation and participate in incident response, root cause analysis, and remediation activities • Assess our technology environment and development methodology (SDLC) to identify and mitigate risks and gaps related to information security including potential data breaches • Design, implement, and maintain security controls across infrastructure, applications, integrations and cloud environments in collaboration with our technology team and third-party vendors including: Applications and other systems and middleware components, including operating systems, web servers, databases, and DNS services (e.g. Salesforce, Mulesoft, APIs, etc.) • Network security architecture, including firewalls, segmentation, and secure communication protocols • Logging and monitoring security needs, including SIEM platforms • Encryption standards needed for compliance • Document security configurations, processes, and controls • Digital certificate lifecycle management, including issuance, renewal, and revocation • Communicate information security and compliance risks to leadership and other technical and non-technical stakeholders for proper awareness and decision making • Other duties as assigned

Job Requirements

  • Bachelor’s degree in computer science or comparable knowledge
  • 10+ years of relevant technical work experience, with 5+ years of experience in an information security role
  • Experience in a highly regulated environment or electronic record systems, health care experience preferred
  • CISM, CISA, CISSP, ISO 27001 LA or other relevant information security certifications are strong assets
  • Essential effective oral and written communication skills with both technical and non-technical audiences in geographically dispersed locations
  • Ability to work effectively cross-functionally with technical and non-technical teams
  • Strong prioritization and time management skills
  • A deep understanding (with practical experience) of related information security technologies and concepts including access and authentication, network and application, message and transmission security as well vulnerability management best practices
  • Proven knowledge of security program frameworks and assessments, ideally SOC 2 and ISO27001
  • Understanding of cloud security concepts and experience with securing cloud environments both public and private (AWS essential and Azure preferred)
  • Hands-on experience and familiarity with: Operating systems (Linux, Windows), Web servers (e.g., Apache, Nginx), Databases (e.g., MySQL, PostgreSQL, SQL Server), Network security principles and architecture (TCP/IP, firewalls, VPNs, segmentation and secure communication protocols), SIEM tools and its integration, Application, cloud, and SaaS integrations, particularly platforms including Salesforce, Containers and/or Kubernetes, Automation tools

Benefits

  • Health insurance
  • 401(k) matching
  • Flexible work hours
  • Paid time off
  • Remote work options

Related Categories

Related Job Pages

More Security Engineer Jobs

SCAN logo

AI Security Engineer – GRC

SCAN

SCAN is a mission-driven organization that is tackling some of the biggest issues in health care for older adults.

Full TimeRemoteTeam 1,001-5,000Since 1977H1B Sponsor

• AI Vendor & Technology Evaluation • Secure AI Implementation Guidance for Development Teams • AI Risk Management & Compliance • Security Integration Reviews • Training , Awareness & Policy

United States
$125.4K - $216.0K / year
Cybit logo

Security Sales Solutions Specialist

Cybit

Cybit is the one-stop-shop for digital transformation that scales in line with your growth

Full TimeRemoteTeam 51-200Since 1993H1B No Sponsor

• Own and deliver security revenue targets across new and existing customers • Identify, qualify, and progress cybersecurity opportunities within the pipeline • Lead complex sales cycles, from discovery through to negotiation and closure • Develop and execute account-level security growth plans with Account Managers • Engage senior stakeholders (CIO, CTO, CISO) on cybersecurity strategy and risk • Conduct consultative discovery to uncover business risks, compliance needs, and technical gaps • Position tailored solutions aligned to customer outcomes (risk reduction, compliance, resilience) • Present and demonstrate cybersecurity solutions in a clear, business-relevant manner • Maintain deep knowledge of cybersecurity domains, including: Managed Security Services (SOC, MDR, SIEM), Endpoint and network security, Identity and access management, Cloud security and zero trust architectures, Governance, risk, and compliance (GRC) • Collaborate with pre-sales and technical teams to design high-quality solutions • Work closely with Account Managers to drive joint opportunities, Marketing on campaigns, events, and go-to-market initiatives, and delivery teams to ensure smooth transition from sale to implementation. • Build strong relationships with strategic security vendors • Leverage partner programmes, incentives, and technical resources • Stay current on vendor roadmaps and emerging technologies

United Kingdom
£60K / year
SD Solutions logo

Adversarial Task Writer, AI Security, RL Gyms

SD Solutions

Create exceptional products with passionate people

Full TimeRemoteTeam 201-500H1B No Sponsor

• You design prompt injection scenarios in YAML, run them against frontier models, validate success rates, and submit passing tasks. • 5 high-quality tasks per week (full-time equivalent).

Serbia
Greenlight Financial Technology logo

Staff Product Security Engineer

Greenlight Financial Technology

Greenlight Financial Technology, Inc. is a financial services company that has developed “the money app for families.” The company’s culture is based on its values of being b

Role Description We are seeking an experienced and motivated Staff Product Security Engineer to join our growing Security team. This individual will be responsible for the end-to-end security of our consumer products, digital platform, and an emerging hardware device line. The Staff Product Security Engineer will: - Drive security review, threat modeling programs, lead penetration testing, manage PSIRT operations, champion secure AI adoption, and establish security guardrails for AI-powered products and AI-assisted development workflows within a highly regulated financial services environment. - Report to the Senior Manager of Product Security. Your day-to-day: - Lead security architecture/design review and threat modeling sessions with product and engineering teams using STRIDE, PASTA, and attack tree methodologies. - Translate threats into actionable, risk-rated engineering remediations prioritized by severity. - Conduct hands-on penetration testing and security assessments across our full product stack producing actionable reports for engineering and leadership. - Red-Team our AI-powered products and development tools to test for prompt injection, data exfiltration, MCP server exploitation, and tool misuse. - Probe AI guardrails to ensure they hold. - Experience with product security tools such as Burp Suite, Metasploit, Kali Linux, Postman, etc. - Drive PSIRT Operations by triaging incoming vulnerability reports, leading technical investigations, coordinating remediation with engineering, scoring severity (CVSS), managing coordinated disclosure with external researchers and on-call incidents. - Manage zero-day findings, driving remediation, collaborating with engineering to patch or mitigate with compensating controls. - Shape the posture of our AI-assisted development environment defining and enforcing enterprise policies for Claude and Cursor. - Partner across the organization, sitting in design review with architects, advising product managers and engineering teams on security and compliance implications of new features. - Brief executives on emerging AI threats, mentor junior security engineers, and collaborate with the AI team on securing ML pipelines. - Champion Security Culture by running developer training on secure coding with AI assistants, evangelizing security by design for products, and ensuring every engineer understands that product security is an enabler and not a gate. Qualifications - 10+ years of product security experience spanning application security, cloud security, and secure SDLC. - Expert level Threat Modeling using STRIDE, PASTA or equivalent across web, mobile, cloud, embedded, and AI systems. - Hands-on penetration testing skills across applications, API, cloud infrastructure, and hardware/firmware. - PSIRT operational experience from vulnerability intake and triage. - Deep hands-on AI security expertise and expert level understanding of OWASP Top 10 for LLM, API, Web, Mobile. - Strong hands-on experience in security tools SAST, DAST, SCA, and securing AI development tools specifically Claude and Cursor. - Strong programming ability and capability to review code, build security tools, automate workflows. - Deep technical knowledge of CI/CD pipeline and relevant tools for web and mobile applications. - Strong knowledge of programming languages & frameworks (i.e. Node.js, Java/Kotlin, React, Redux, Swift, SwiftUI), cloud technologies and infrastructure (i.e. AWS, GCP, Kubernetes, Ambassador, Helm), and databases (i.e. MySQL, DynamoDB, Redis). - Ability to influence without authority, mentor without managing, and communicate complex risks in a language that resonates with engineers, product managers, legal and compliance, and executives alike. Requirements - Hardware and embedded security experience with knowledge of secure boot, firmware integrity, hardware root of trust, and IoT threat modeling experience. - Experience in the Financial industry, knowledge of PCI DSS, COPPA or demonstrated ability to learn regulated domains quickly. Benefits - Medical, dental, vision, and HSA match. - Paid life insurance, AD&D, and disability benefits. - Traditional 401k with company match. - Unlimited PTO. - Paid company holidays and pop-up bonus holidays. - Professional development stipends. - Mental health resources. - 1:1 financial planners. - Fertility healthcare. - 100% paid parental and caregiving leave, plus cleaning service and meals during your leave. - Flexible WFH, both remote and in-office opportunities. - Fully stocked kitchen, catered lunches, and occasional in-office happy hours. - Employee resource groups.

United States
$165K - $185K / year