Senior Security Engineer
- Location
- Toronto
- Track
- AI Security
- Level
- Senior
- Salary
- $260K–$310K / yr
- Posted
- September 3, 2026
- Source
- Ashby
Job description
Who are we?
As a Senior Security Engineer you will
- Serve as trusted advisor to team’s leadership and partner teams by clearly articulating business risks associated with security issues
- Lead security operation functions – including vulnerability management, SAST, DAST, detection engineering, and incident response – in CI/CD and cloud-native production environments
- Integrate security into our applications throughout the software development lifecycle
- Collaborate with product and development teams, driving the success of larger projects to ensure that software is built and deployed securely without compromising agility and speed
- Driving and supporting bug bounty program, application security reviews and threat modeling, including code review and dynamic testing
- Assess and integrate security tools to automate and scale security processes, i.e: evaluate open-source vs vendor solutions
- Gather and analyze security metrics to address security issues with cross-team dependencies
- Be a problem solver who is empathetic to developer concerns and will employ constructive and flexible approach to building innovative solutions
You may be a good fit if
- 5+ years previous experience in Application/Product Security or Security Operations with a strong focus on security tool onboarding and optimization
- You have an understanding of vulnerability management, network security, cloud security concepts, and industry best practices across many fields of security
- You are comfortable with ambiguity and are able to make informed decisions with little data
- You employ a flexible and constructive approach when solving problems
- You are able to make trade-offs between build vs. buy decisions - help build solutions and able to review what tools are available
- You understand secure engineering best practices, can articulate problem statements and propose solutions to both technically savvy and non-technical audiences
- You have a deep technical understanding of common security vulnerabilities and risks, as well as countermeasures and compensating controls
- You’re a hands-on security engineer interested in automating controls