Skip to content

Open nowPosted 56 days ago

Staff Security Engineer

Forma.ai24 open roles

Where
Toronto, Canada
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowStaff Security EngineerForma.ai · Toronto, Canada
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Forma.ai's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Forma.ai postings stay open a median of 5 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 34.1%30 days
This job: posted 56 days ago

Forma.ai median: 5 days open

The posting

About Forma.ai:

Forma.ai is a Series B startup that's revolutionizing how sales compensation is designed, managed and optimized. We handle billions in annual managed commissions for market leaders like Edmentum, Stryker, and Autodesk.

Our growth has been fuelled by our passion for fundamentally changing and shaping how companies use sales intelligence to drive business strategy.

We’re welcoming equally driven individuals who are excited about creating something big!

The Opportunity

As a Staff Security Engineer, you will be a hands-on technical leader strengthening security across Forma's application, cloud infrastructure, development lifecycle, internal systems, and incident-response practices.

Security today is shared across Engineering and DevOps. You'll work closely with both teams and have real room to shape how Forma approaches security as we grow. Depending on your interests and the needs of the business, the role could develop into a deeper individual-contributor position or help build a dedicated security team.

You'll work directly with Engineering, DevOps, IT, Product, Legal, and Privacy to identify risks, design practical controls, automate security processes, and help teams ship secure and reliable software.

What you'll do

Cloud and infrastructure security

  • Design and implement security controls across Forma's AWS environments, with a focus on IAM, least-privilege access, service identities, and account boundaries.
  • Embed security requirements into Terraform and other Infrastructure as Code, and improve secrets, certificate, encryption-key, and credential management.
  • Build automated checks for insecure configurations, excessive permissions, exposed resources, and configuration drift across Kubernetes, containers, serverless workloads, networking, and data services.

Application, data, and AI security

  • Run threat modelling and security architecture reviews for new products, services, APIs, data pipelines, and third-party integrations.
  • Strengthen tenant isolation, authorization enforcement, and fine-grained data access controls at the schema, table, row, and column level.
  • Help protect sensitive compensation, financial, customer, and employee data across databases, data warehouses, S3, analytics services, and internal tools, including logging and auditability for sensitive-data access.
  • Review AI and agentic workflows for data leakage, prompt injection, insecure tool use, and excessive permissions; ensure agents operate strictly within the calling user's permissions; and define secure patterns for approved services such as Amazon Bedrock.
  • Identify and help remediate application vulnerabilities, and build tooling and reusable libraries that make the secure path the easy one for engineers.

DevSecOps and secure delivery

  • Embed security testing into CI/CD — static analysis, dependency and container scanning, secrets detection, Infrastructure as Code scanning, and dynamic testing — without creating unnecessary friction for developers.
  • Define practical vulnerability-severity, remediation, exception, and escalation standards, and partner with developers to separate real risk from noise and fix root causes.
  • Improve software supply-chain security, including build permissions, artifact integrity, dependency governance, and GitHub administration.

Detection, monitoring, and incident response

  • Improve security visibility across cloud infrastructure, applications, identities, endpoints, and SaaS systems, and build alerts and detection logic that are worth acting on.
  • Lead investigations and coordinate containment, remediation, and root-cause analysis, supported by clear runbooks, ownership, and escalation paths.
  • Run tabletop exercises, and track and communicate security metrics and material risks to technical and business stakeholders.

Identity, governance, and enablement

  • Strengthen SSO, MFA, privileged access, and onboarding, offboarding, and access-review processes across AWS, GitHub, Microsoft 365, Entra ID, production systems, and internal SaaS — automating provisioning, entitlement reviews, and evidence collection where practical.
  • Translate security and compliance requirements into concrete technical controls, and support customer security reviews, audits, and programs such as SOC 2 and ISO 27001.
  • Evaluate third-party tools and integrations for security, privacy, and access-control risk, and help select, consolidate, and rationalize Forma's security tooling for both coverage and cost.
  • Maintain clear technical standards and provide practical guidance, training, and mentorship that raises security capability across Engineering.

What we're looking for

  • Eight or more years of experience in security engineering, cloud security, application security, DevSecOps, or infrastructure engineering.
  • Strong hands-on experience securing AWS environments, including IAM, networking, encryption, logging, and secrets management.
  • Experience with Terraform, Kubernetes, containers, and security controls in CI/CD pipelines.
  • Strong understanding of application and API security, authentication, authorization, and multi-tenant SaaS risks.
  • Experience with vulnerability management, threat modelling, incident response, and security automation.
  • Ability to write scripts using Python, Bash, PowerShell, or a similar language.
  • Strong communication, troubleshooting, and cross-functional collaboration skills.

Strongly preferred

  • Experience supporting SOC 2, ISO 27001, privacy programs, or enterprise customer security reviews.

Nice to have

  • Experience securing analytics platforms, data pipelines, or systems handling sensitive customer data, including row-level, column-level, or attribute-based access controls.
  • Experience with AWS security services, EKS, Datadog, Wiz, Snyk, CrowdStrike, or similar tools.
  • Experience securing AI applications, large language models, agents, or Amazon Bedrock workloads.
  • Experience in a B2B SaaS or high-growth technology company.
  • Relevant security or cloud certifications.

Your first 30, 60, and 90 days

First 30 days: learn and assess

  • Build an understanding of Forma's application architecture, AWS environments, deployment processes, data flows, identity systems, and security obligations.
  • Meet key partners across Engineering, DevOps, IT, Product, Legal, and Privacy, and agree on how security reviews and escalations will operate.
  • Review existing controls, open findings, incidents, access patterns, monitoring, and compliance commitments.
  • Identify immediate risks, quick wins, and areas needing deeper assessment.

By 60 days: prioritize and improve

  • Deliver a prioritized security roadmap based on risk, business impact, and engineering effort.
  • Begin addressing the highest-priority gaps in cloud access, secrets management, CI/CD security, vulnerability management, and monitoring.
  • Introduce or improve a consistent process for threat modelling and security architecture reviews, and define vulnerability-severity, ownership, remediation, and exception standards.
  • Assess the current security tool stack for coverage, overlap, and cost, with consolidation recommendations.
  • Improve incident-response runbooks, alert ownership, and escalation paths for critical systems, and recommend measurable security objectives and reporting metrics.

By 90 days: operationalize and lead

The expectation here is momentum, not completion — these should be underway and demonstrably working, not finished.

  • A first set of automated security guardrails in place across AWS, Terraform, Kubernetes, GitHub, or CI/CD, with remaining coverage planned and underway.
  • Repeatable processes running for vulnerability management, access reviews, security assessments, and incident follow-up, even if still being refined.
  • Security reviews completed for the highest-priority product, data, or AI initiatives, with required controls agreed and in progress.
  • Improved visibility into high-risk identities, infrastructure changes, and sensitive-data access.
  • Progress, key risks, and the next phase of the security roadmap presented to leadership.

Additional Info:

  • This position is for an existing vacancy

What you can expect from us

Meaningful compensation. In addition to your base salary, you’ll join our employee stock ownership plan to further recognize your contributions to Forma.ai’s success.

Healthcare coverage. We have a full benefits package that includes medical, dental, vision, disability and life insurance, and a paid parental leave program.

Learning and development. Access the resources you want to help you grow in your role by utilizing our $750 yearly training stipend.

Growth. You’ll have a huge opportunity to build a career for yourself and gain the type of experience you’re looking for, whether that’s as an individual contributor or as a people leader.

Our Values:

  • Work well, together. We’re real. We have kids and pets. Mortgages and student loans. We’re in this together, so no matter how brilliant any one of us is, we always play nice with one another – no exceptions.
  • Be precise. Be relentless. We believe complacency breeds failure, so we set new goals as quickly as we achieve them. We persist in the face of adversity, learn from our mistakes, and push each other to continuously improve. The status-quo is kryptonite.
  • Love our tech. Love our customers. Our platform solves a very complex problem in a currently underserved market. While everyone at Forma isn’t customer-facing, we’re all customer-focused. Maybe even slightly customer-obsessed. ­

Use of AI for Recruitment

Currently, Forma.ai does not use artificial intelligence as part of our recruitment process, specifically but not limited to the screening, filtering and shortlisting of applicants.

Our commitment to you:

Forma is a proud equal opportunity employer that is committed to creating a diverse and inclusive work environment. Every effort to accommodate candidates for accessibility will be made upon request. Information received related to accommodations will be addressed confidentially. We know that applying to a new role takes a lot of effort. You're encouraged to apply even if your experience doesn't precisely match the job description. There are many paths to a successful career and we’re looking forward to reading yours.

We thank all candidates for their interest however only qualified applicants will be shortlisted.

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Forma.ai's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Forma.ai's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Forma.ai's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.