Staff Security Engineer

Location

Canada

Posted

4 days ago

Salary

C$104.6K - C$156.9K / year

Seniority

Lead

Job Description

Staff Security Engineer

SPS Commerce

Role Description The Staff Security Engineer – IAM ensures Company development, infrastructure, and business practices have security defined, integrated, and implemented according to the SPS security policies, standards, and best practices. Together with the broader technology team, security engineers ensure that risk-based controls are implemented and monitored to protect SPS. - Devise reasonable, risk-based security controls to monitor and protect SPS and align with our business objectives - Implement the security program strategic plan that improves program maturity and compliance - Lead team through the IAM Engineering best practices (design, build, test, implement) - Partner with engineering teams to design and implement authentication flows for internally built applications — including OAuth 2.0/OIDC client and resource server implementations, token issuance and validation, session management, and secure credential storage. - Evaluate and implement modern authentication standards: passwordless/WebAuthn/FIDO2, PKCE, mTLS, and JWT-based authorization. - Advise and recommend technology solutions supporting efficient IAM business processes - Perform security review of infrastructure and applications IAM processes and integrations - Communicate results of security review findings to a broad and diverse set of stakeholders across the company - Monitor trends, tools, etc., in the IAM industry. Recommend solutions. Lead evaluation of security toolsets to mature IAM capability - Create or write automation to orchestrate security-related processes – leveraging COTS and custom code - Develop, manage, and consult on the technical architecture for enterprise security controls - Partner with business and technology operations groups to maintain the security monitoring for IAM controls Qualifications - Bachelor's degree in related business or technical area plus a minimum of 8 years of related experience; or a Master's degree with 6 years of experience; or equivalent combination of education and experience - Equivalent work experiences include: security engineering/architecture experience and designing and implementing standards, specifications, and procedures - Experience in providing technical security guidance to technical and non-technical audiences - Strong working knowledge of authentication/authorization protocols: OAuth 2.0, OpenID Connect, SAML 2.0, SCIM, and JWT. - Experience with regulatory requirements from SOX, HIPAA, and PCI-DSS - Demonstrated experience and understanding of business security and compliance requirements and ability to translate into well-engineered & integrated business solutions - Strong knowledge of development operations practices – accountable for driving the integration of security into development operations and existing continuous delivery / continuous improvement business processes Requirements - Okta Certified Professional or Okta Certified Developer certification. - Experience with Okta Identity Governance (OIG), Okta API Access Management (custom authorization servers), or Okta Workflows at scale. - Experience with WebAuthn/FIDO2, passkeys, or other passwordless authentication implementations. - System configuration and architecture experience - Strong knowledge of industry accepted information security best practices, standards, and policies such as NIST CSF, OWASP, CIS, STIG, MITRE ATT@CK, etc. - Demonstrated experience building or significantly extending authentication capabilities for a custom-developed application — not just configuring a third-party IdP. - Proven ability to manage information security service and operation through effective management of resources - Demonstrated ability to take initiative and accountability for achieving results - Driven to understand & appropriately respond to customers' business needs - Certifications & Licenses: One or more industry certification - CISSP, CISM, CISA, CCFE, GIAC, CCIE, CCSP, ABCP, MBCP, ISA, PCIP, CEH - Actively participates and contributes to the security community Benefits - The annual salary range for this role is: $104,600.00 - 156,900.00 CAD Annual. - The actual salary offered will be determined based on factors including education, relevant skills, work history, certifications, location, and more. - Eligibility to participate in an annual incentive program based on individual and/or organizational performance. - Comprehensive benefits package designed to support employees’ health, well-being, and financial security.

Related Categories

Related Job Pages

More Security Engineer Jobs

Lumen Technologies logo

Security Engineer, Vulnerability Management

Lumen Technologies

Lumen Technologies is self-described as a global company of 40,000+ professionals empowering businesses, government, and communities to “produce amazing thing

Role Description Lumen Security Advisory Services is hiring a Cloud Security & Vulnerability Management consultant to join a team that delivers customer-facing security assessments and vulnerability management engagements across cloud environments and customer premises. The primary focus is cloud security posture assessment, where the team evaluates customer environments against industry compliance frameworks, identifies vulnerabilities and misconfigurations, and helps customers understand their security posture and build practical remediation strategies. A secondary focus is vulnerability management, where the team deploys and manages scanning platforms in customer environments, configures and tunes the platform alongside customers, develops patching strategies aligned to customer needs, and guides remediation prioritization and planning. This is a hands-on consulting role on a small, fast-moving team. You'll work directly with customers, run assessments using commercial and custom-built tooling, and contribute improvements to shared platforms and codebases. Main Responsibilities - Cloud Security (Primary Focus) - Deliver cloud security posture assessments across AWS, Azure, and Microsoft 365 environments - Evaluate customer environments against CIS Benchmarks, cloud provider security frameworks and best practices, and customer-specific compliance standards - Use custom-developed assessment frameworks and cloud-native security tooling to identify misconfigurations and security gaps - Perform cloud resource inventory and exposure analysis - Prioritize findings by risk and develop clear remediation guidance - Vulnerability Management - Deploy and manage vulnerability scanning platforms in customer environments - Configure and tune scanning platforms alongside customers, including patching strategy development - Analyze scan results, prioritize findings by severity and business impact, and guide remediation planning - Understand vulnerability types, severity frameworks (e.g., CVSS, vendor-specific), and how to communicate risk to customers - Consulting & Delivery - Participate in customer-facing activities: kickoff calls, technical interviews, working sessions, and findings presentations - Contribute to assessment reports and remediation roadmaps for technical and executive audiences - Communicate technical risk clearly to non-technical stakeholders - Tooling & Platform Development - Contribute to a custom-built cloud security assessment platform (AWS native services) - Develop and maintain custom security checks and automated compliance scanning tools - Work with AWS and Azure cloud infrastructure components - Write and maintain scripts for assessment automation and reporting Qualifications - Hands-on experience with at least one major cloud platform (AWS preferred; Azure, M365 also valued) - Understanding of cloud security posture management (CSPM) concepts and the differences between platform-level tools (e.g., Wiz) and assessment-focused tooling - Familiarity with compliance frameworks such as CIS Benchmarks, SOC2, PCI-DSS, or NIST - Understanding of vulnerability management concepts: vulnerability types, severity scoring, remediation prioritization - Strong communicator able to explain technical findings to both engineers and executives - Comfortable writing Python and working in Git - Experience with AI-assisted development and automation tools such as GitHub Copilot, Microsoft Copilot Studio and agent building, Power Automate, and Claude - Willingness to learn new tools and platforms quickly Requirements - 3–5 years’ experience in cloud security, vulnerability management, security consulting, or a related technical security role Certifications - Relevant certifications (AWS, Azure, CISSP, or similar), however, demonstrated experience matters more Compensation This information reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual pay is based on skills, experience and other relevant factors. - $67,703 - $90,270 in these states: AL, AR, AZ, FL, GA, IA, ID, IN, KS, KY, LA, ME, MO, MS, MT, ND, NE, NM, OH, OK, PA, SC, SD, TN, UT, VT, WI, WV, WY - $71,088 - $94,784 in these states: CO, HI, MI, MN, NC, NH, NV, OR, RI - $74,474 - $99,297 in these states: AK, CA, CT, DC, DE, IL, MA, MD, NJ, NY, TX, VA, WA Benefits - Lumen offers a comprehensive package featuring a broad range of Health, Life, Voluntary Lifestyle benefits and other perks that enhance your physical, mental, emotional and financial wellbeing.

United States
$67.7K - $99.3K / year
Comcast logo

Comcast Cybersecurity: Cyber Security Engineer - AI & Agentic Platforms

Comcast

Headquartered in Philadelphia, Pennsylvania, Comcast was established in 1963 as a single-system cable company. Over the years, Comcast experienced tremendous gr

Full TimeRemoteTeam 10,000Since 1963

Make your mark at Comcast -- a Fortune 30 global media and technology company. From the connectivity and platforms we provide, to the content and experiences we create, we reach hundreds of millions of customers, viewers, and guests worldwide. Become part of our award-winning technology team that turns big ideas into cutting-edge products, platforms, and solutions that our customers love. We create space to innovate, and we recognize, reward, and invest in your ideas, while ensuring you can proudly bring your authentic self to the workplace. Join us. You'll do the best work of your career right here at Comcast. (In most cases, Comcast prefers to have employees on-site collaborating unless the team has been designated as virtual due to the nature of their work. If a position is listed with both office locations and virtual offerings, Comcast may be willing to consider candidates who live greater than 100 miles from the office for the remote option.) Job Summary We build and design the tools of tomorrow to stop bad actors from harming our customers and our company. Our mission is to build, maintain, and advance the next generation capabilities that power Comcast's global cybersecurity operations. This team owns the Premonition platform, which manages, deploys, and composes agentic pipelines at scale-combining large language models, high-performance data systems, and modern cloud infrastructure to give our security teams a decisive edge. We work with technologies like Python, SQL, Rust, JavaScript, LLMs (via Ollama, Bedrock, SageMaker), AWS, EKS, open table formats (Iceberg, Delta, Hudi), and embedded engines such as DuckDB and LanceDB. Our culture is supportive, caring, competitive, high ownership, and deeply technical: we help each other grow, we care about people as much as outcomes, and we push ourselves to solve hard problems at scale. If you want to apply advanced LLMs and high-performance data engineering to real-world cybersecurity threats affecting millions of customers, this is the place to do it. Job Description As Cyber Security Engineer on the Cybersecurity AI & Data Platforms team, you will develop and maintain Premonition, Comcast's internal platform for managing, deploying, and composing agentic pipelines that power global cybersecurity operations. You will split your time between: - building a robust, scalable platform for LLM and agent driven workflows, and - optimizing the high-performance data layer supporting those workflows, including storage formats, compression, latency, and query performance across large datasets. This role sits at the intersection of applied AI and big data engineering. You will work with large language models, orchestration frameworks, and cyber focused agentic pipelines, while also owning the data and infrastructure foundations that make those systems fast, reliable, and cost-effective at Comcast scale. You'll partner closely with security operations, incident response, and threat hunting teams to translate real-world workflows into secure, composable, and observable agentic systems. Key Responsibilities - Design, build, and maintain the Premonition platform for managing, deploying, and monitoring agentic pipelines. - Develop composable building blocks-agents, tools, pipelines, evaluators, and configuration-to enable rapid workflow assembly and iteration. - Implement robust APIs, orchestration, and infrastructure integrations on AWS and EKS for reliable LLM and agent driven workloads. - Engineer and optimize the high performance data layer, including Iceberg/Delta/Hudi, compression, indexing, latency, and largescale query performance. - Work with embedded engines such as DuckDB and LanceDB to enable interactive, low latency analytics. - Collaborate with cybersecurity stakeholders (SOC, IR, threat hunters, engineers) to translate workflows into secure, automated, observable pipelines. - Experiment with and productionize LLM and agent patterns (RAG, tool use, multistep agentic workflows), including evaluation, safety, and guardrails. - Own the full lifecycle of Premonition services: design, implementation, testing, deployment, observability, performance tuning, and continuous improvement. - Contribute to and enforce standards and best practices for LLM/agent usage, data management, security, and governance. - Participate in design/code reviews and foster a supportive, caring, competitive, high ownership, deeply technical culture. Required Qualifications - Strong production experience with Python. - Solid SQL skills and experience working with large datasets. - Experience designing, building, and operating production APIs or microservices, including testing, observability, CI/CD. - Experience running workloads on AWS and Kubernetes/EKS. - Experience with high performance data engineering, including: - Iceberg, Delta, or Hudi; or - optimizing storage, compression, latency, and analytical query performance. - Ability to work in a deeply technical, high ownership environment and collaborate effectively across functions. - Strong communication skills with the ability to work closely with security stakeholders and translate workflows into technical designs. Preferred Qualifications - Demonstrated experience building LLM based applications or agentic workflows (not just prompt tinkering). - Hands on experience with agentic workflows: agents, tools, orchestration, multistep pipelines. - Experience with LLM platforms: Ollama, Amazon Bedrock, SageMaker. - Familiarity with orchestration frameworks: LangChain, LlamaIndex, or equivalent internal tooling. - Production experience with Iceberg, Delta Lake, or Hudi. - Experience with DuckDB or LanceDB. - Experience with Rust and/or JavaScript/TypeScript. - Experience with workflow/orchestration tools: Airflow, Temporal, Argo. - Prior exposure to cybersecurity domains (SOC, IR, threat hunting, security engineering). - Experience in largescale enterprise or telecom environments with high security/reliability/compliance requirements. Employees at all levels are expected to: - Understand our Operating Principles; make them the guidelines for how you do your job. - Own the customer experience - think and act in ways that put our customers first, give them seamless digital options at every touchpoint, and make them promoters of our products and services. - Know your stuff - be enthusiastic learners, users and advocates of our game-changing technology, products and services, especially our digital tools and experiences. - Win as a team - make big things happen by working together and being open to new ideas. - Be an active part of the Net Promoter System - a way of working that brings more employee and customer feedback into the company - by joining huddles, making call backs and helping us elevate opportunities to do better for our customers. - Drive results and growth. - Support a culture of inclusion in how you work and lead. - Do what's right for each other, our customers, investors and our communities. Disclaimer: - This information has been designed to indicate the general nature and level of work performed by employees in this role. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications. Comcast is an equal opportunity workplace. We will consider all qualified applicants for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, veteran status, genetic information, or any other basis protected by applicable law. Comcast will consider for employment applicants with arrest or conviction records in accordance with the requirements of applicable law, including the San Francisco Fair Chance Ordinance, the Los Angeles Fair Chance Initiative for Hiring Ordinance, the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Please note that federal state, or local laws and regulations may restrict or prohibit Comcast from hiring individuals convicted of certain crimes. Additionally, an applicant's criminal history may have a direct, adverse, and negative relationship on the job duties of this position, which may result in the withdrawal of a conditional offer of employment. Skills: Amazon Web Services (AWS); Structured Query Language (SQL); Python (Programming Language); Big Data Engineering Salary: National Pay Range: $98,678.80 USD-$231,278.44 USD Illinois Pay Range: $104,846.23 USD - $203,525.03 USD Colorado Pay Range: $111,013.65 USD - $212,776.16 USD Hawaii Pay Range: $129,515.93 USD - $194,273.89 USD Washington DC Pay Range: $141,850.78 USD - $212,776.16 USD Maryland Pay Range: $117,181.08 USD - $212,776.16 USD Minnesota Pay Range: $111,013.65 USD - $194,273.89 USD New York Pay Range: $117,181.08 USD - $231,278.44 USD Washington Pay Range: $111,013.65 USD - $222,027.30 USD New Jersey Pay Range: $123,348.50 USD - $222,027.30 USD Vermont Pay Range: $117,181.08 USD - $185,022.75 USD Massachusetts Pay Range: $123,348.50 USD - $222,027.30 USD California Pay Range: $111,013.65 USD - $205,580.83 Comcast intends to offer the selected candidate base pay within this range, dependent on job-related, non-discriminatory factors such as experience. The application window is 30 days from the date job is posted, unless the number of applicants requires it to close sooner or later. The application window is 30 days from the date job is posted, unless the number of applicants requires it to close sooner or later. Base pay is one part of the Total Rewards that Comcast provides to compensate and recognize employees for their work. Most sales positions are eligible for a Commission under the terms of an applicable plan, while most non-sales positions are eligible for a Bonus. Additionally, Comcast provides best-in-class Benefits to eligible employees. We believe that benefits should connect you to the support you need when it matters most, and should help you care for those who matter most. That's why we provide an array of options, expert guidance and always-on tools, that are personalized to meet the needs of your reality - to help support you physically, financially and emotionally through the big milestones and in your everyday life. Please visit the compensation and benefits summary on our careers site for more details. Education Bachelor's Degree While possessing the stated degree is preferred, Comcast also may consider applicants who hold some combination of coursework and experience, or who have extensive related professional experience. Relevant Work Experience 7-10 Years

Pennsylvania
$98.7K - $231.3K / year

Director, IT and Security

Tonal Systems

Tonal Systems, Inc. is a technology company known for its personal training and fitness services and equipment. As an employer, the company strives to foster an

Director, IT and Security Location Austin, TX Employment Type Full time Location Type Remote Department Operations - Business Technology & PMO - Business Technology Compensation - $178K – $220K Overview Tonal is the world's most intelligent strength training system, combining hardware, software, AI, computer vision, and world-class content to help people build strength and live healthier. Tonal is now expanding into healthcare and clinical applications, connecting strength training technology with providers, employers, and payers to deliver measurable health outcomes — raising the bar for what our IT and security function needs to deliver. We're looking for a Director of IT & Security to own this function end-to-end. This role carries the highest privileges across our most sensitive systems and direct accountability for IT and security outcomes company-wide. You'll report to the VP of Business Technology and work closely with senior leadership. The ideal candidate has a start-up mentality — comfortable moving fast in a lean, resource-constrained environment, while never losing sight of the security and compliance discipline a healthcare-adjacent company requires. What You Will Do - Own end-to-end IT operations, including device lifecycle, onboarding/offboarding, SaaS administration, identity and access management, help desk, and office infrastructure across all locations. - Lead the technical controls side of Tonal's HIPAA compliance program, implementing the safeguards required by the HIPAA Security Rule and HITECH Act — encryption, SIEM, MDM/EDR, and role-based access. - Own and execute Tonal's security program: penetration testing remediation, security policy, tabletop exercises, vendor security reviews, and incident response. - Govern Tonal's AI tool ecosystem, including licensing, spend, API key governance, corporate AI policy, and DLP and prompt injection protections. Drive AI training and best practices across the organization. - Administer Tonal's SaaS portfolio, owning contract renewals, license optimization, and vendor negotiations across critical platforms. - Drive automation and identity governance maturity, including Okta Identity Governance, expanding SCIM-based provisioning, building & enforcing RBAC frameworks, and driving workflow automation and system integration. - Lead and grow the IT & Security team, managing engineers and administrators, overseeing the virtual CISO engagement, owning the budget and aligning org structure to Tonal’s needs. - Own IT documentation and process improvement, maintaining runbooks and closing gaps in onboarding, offboarding, and incident response, and driving overall automation. - Manage global physical infrastructure — networking, Wi-Fi, AV, and physical access — across a distributed, multi-office footprint. - Serve as a trusted operator on Tonal's most sensitive matters, from executive access provisioning to security incidents and legal holds. - Report regularly to senior leadership and the C-suite, translating IT & Security roadmap priorities, progress, technical risk and incident management into clear, actionable narratives. Who You Are - 10+ years in IT and security leadership, with full functional ownership and experience across identity and access management, endpoint security, SaaS administration, network infrastructure, and security program management. - Hands-on HIPAA compliance implementation experience, beyond writing policies - Track record of building a security program from the ground up: policy, penetration testing, and real incident response - Broad expertise across identity and access management, endpoint security, SaaS administration, and network infrastructure - Equally comfortable configuring technical systems and presenting security risk to executive leadership - A start-up mindset: thrives in fast-moving, resource-constrained environments without cutting corners on security - Proven ability to prioritize with a lean team and limited budget, with outcomes to show for it. - Experience managing a large SaaS portfolio, including contract renewals, vendor negotiation, and license governance - Strong people leadership skills, setting clear expectations and developing team members - High standards of trust, integrity, and discretion, given access to the company's most sensitive systems Extra Credit - HIPAA compliance roll-out and execution, owning the technical controls end-to-end. - Experience with SOC 2 Type II, NIST CSF, or HITRUST in a hands-on implementation capacity - Background in healthcare technology, digital health, or clinical-grade software environments At Tonal, we believe that the unique and varied lived experiences of our teammates contribute to our overall strength. We don’t just appreciate differences, we celebrate them, and we always seek people that represent a wide variety of backgrounds. We’re dedicated to adding new perspectives to the team and designing employee experiences that contribute to your growth as much as you do to ours. If your experience aligns with what we’re looking for (even if you don’t check every single box), send us your application. We would love to hear from you! Tonal is committed to meeting the diverse needs of people with disabilities in a timely manner that is consistent with the principles of independence, dignity, integration, and equality of opportunity. Should you have any accommodation requests, please reach out to us via our confidential email. All requests will be addressed and responded to in accordance with Tonal’s Accessibility Policy and local legislation.

Texas
$178K - $220K / year

Network Security Architect

Redolent, Inc

ERM - Rina María Cabrera / Capgemini | North América External Resource Manager Tel.: +1 888 229 2961 Email: rina.cabrera@capgemini.com

Role Description The role involves providing subject matter expertise in the analysis, design, implementation, troubleshooting, and preparation of technology solutions to meet business needs. The candidate should have expert-level hands-on and design experience in various security technologies. - Hands-on experience with Palo Alto firewall, Fortigate Firewall, ClearPass, and Zscaler (Zscaler Internet Access, Zscaler Private Access). - Experience in implementing zero trust. - Recommends components for solutions that work well across business domains. - Accountable for timely and cost-effective delivery of projects/applications/infrastructure. - Expert level knowledge in implementing PCI4.0. - Perform Root Cause Analysis for Major P1/P2 incidents following ITIL process. - Ensures project artifacts are developed and documented properly. - Facilitates the creation of communication plans among key stakeholders. - Develops complete and robust test plans, cases, and scripts. - Acts as a communication point for infrastructure, application, and data changes. - Ensures integration of assigned business areas against critical business processing. - Thorough understanding of business strategy, operations, markets, and key stakeholders. - Reviews business processes to identify capability gaps and opportunities. - Recommends innovations and simplifications in business processes/systems. - Builds close relationships with function heads and their teams. - Works as 3rd level support to resolve issues within the area of responsibility. - Maintains a high level of individual contribution and professional growth. Qualifications - Expert-level hands-on experience with security technologies. - Strong understanding of business strategy and operations. - Ability to develop communication plans and test strategies. Requirements - Proven experience with Palo Alto and Fortinet Firewalls. - Experience with HPE Aruba Clearpass and Zscaler technologies. - Knowledge of PCI4.0 implementation. - Experience in ITIL processes. Benefits - 100% Remote work opportunity. - Flexible working hours.

United States