Skip to content

Open nowPosted 6 hours ago

Senior Security Engineer - Vulnerability & Data/SaaS Security

Jobgether3,739 open roles

Where
Canada
Work mode
Remote
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSenior Security Engineer - Vulnerability & Data/SaaS SecurityJobgether · Canada
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on Jobgether's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.1% of postings close within 7 days. Measured by our own scanner across the market. Jobgether postings stay open a median of 6 days.

Share of postings closed within
  1. 1.7%1 day
  2. 3.6%3 days
  3. 8.1%7 days
  4. 15.1%14 days
  5. 34.0%30 days
This job: posted 6 hours ago

Jobgether median: 6 days open

The posting

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer - Vulnerability & Data/SaaS Security based in Canada.

This is a senior security engineering opportunity focused on strengthening vulnerability, cloud, data, and SaaS security programs across a complex technology environment. You will own the day-to-day operation and continuous improvement of security programs spanning infrastructure, applications, containers, cloud platforms, data stores, and SaaS applications. The role combines hands-on security engineering with automation, risk management, remediation orchestration, and executive reporting. You will work with a broad security tooling ecosystem and build integrations that make detection, prioritization, and remediation more efficient. A key part of the role is translating technical findings into meaningful business-risk insights for engineering teams, leadership, and audit stakeholders. You will collaborate closely with application, cloud, platform, data, and business teams in a highly regulated technology environment. The position is fully remote within Ontario or British Columbia, offering significant ownership and impact across enterprise security operations.

Accountabilities

  • Own the end-to-end vulnerability management lifecycle, including triage, risk-based prioritization, remediation tracking, SLA enforcement, and exception management across infrastructure, applications, and containers.
  • Review vulnerability findings from application security and dynamic testing platforms, coordinate remediation with relevant teams, and maintain compliance with established remediation timelines.
  • Develop and continuously improve risk-prioritization models that consider severity, exploitability, business criticality, regulatory requirements, and potential impact.
  • Lead the cloud security posture management program across AWS, identifying misconfigurations, configuration drift, and control violations while strengthening secure baselines for IAM, networking, storage, encryption, compute, and containers.
  • Manage data security posture initiatives, including sensitive-data discovery, automated classification, data-flow and lineage visibility, and monitoring of cross-environment data replication.
  • Operate and mature SaaS security posture management capabilities, including sanctioned and shadow SaaS discovery, OAuth and third-party application governance, and SaaS data exposure monitoring.
  • Partner with application, cloud, platform, and data engineering teams to translate security policies into effective technical controls and remediation actions.
  • Automate findings aggregation, ticket creation, remediation workflows, ownership assignment, SLA tracking, escalation, and risk-exception processes.
  • Build and maintain API integrations between security platforms and downstream systems such as ticketing platforms, SIEMs, CMDBs, and data warehouses.
  • Develop Python scripts and automation to enrich security findings with asset and ownership context, reduce manual triage, and improve the reliability of security dashboards.
  • Define and maintain security KPIs and KRIs, including MTTD, MTTR, SLA compliance, coverage, and risk-reduction trends.
  • Produce accurate executive dashboards and recurring reports that translate technical security findings into clear business-risk narratives and compliance insights.
  • Support compliance alignment across frameworks such as PCI DSS, SOX, SOC 2, and ISO 27001.
  • Continuously improve the reliability and coverage of security tooling integrations and monitoring programs.
  • 5+ years of professional experience in security engineering, with hands-on ownership of vulnerability management, cloud security, application security, data security, or SaaS security programs.
  • Direct experience with vulnerability management and application security platforms such as Tenable, Snyk, and StackHawk or equivalent technologies.
  • Strong experience securing AWS environments and working with cloud security posture management tools.
  • Experience with endpoint and cloud workload detection and response platforms such as CrowdStrike Falcon.
  • Hands-on experience with data security posture management and SaaS security posture management solutions, such as Sentra and Reco or comparable platforms.
  • Experience with security findings aggregation or application security posture management platforms such as ArmorCode, including integrations with ticketing systems such as Jira.
  • Strong Python scripting and REST API integration skills, with the ability to build and maintain security data pipelines across multiple platforms.
  • Experience developing security metrics, KPIs, KRIs, and executive-level dashboards from security tooling data.
  • Familiarity with SIEM integrations and security automation or orchestration practices is an asset.
  • Strong understanding of security and compliance frameworks relevant to regulated environments, including PCI DSS, SOX, SOC 2, and ISO 27001.
  • Excellent written and verbal communication skills, with the ability to translate complex technical risks into clear business terms for non-technical and executive stakeholders.
  • Strong analytical and problem-solving skills, with the ability to prioritize risks and drive remediation across multiple teams.
  • Experience establishing vulnerability, risk-exception, and SLA governance processes is highly valued.
  • Experience in fintech, payments, financial services, or another highly regulated industry is considered an advantage.
  • Competitive annual base salary of CAD $136,800–$171,000, calibrated according to skills, experience, and working location.
  • Annual bonus opportunities based on individual and overall company performance.
  • Multiple health insurance options.
  • Flexible vacation time plus additional floating holidays.
  • Retirement savings program with company contributions.
  • Equity participation in a publicly traded company.
  • Monthly stipend to support remote work.
  • Annual professional development stipend.
  • Family-forming benefits.
  • Up to 20 weeks of parental leave.
  • Flexible-first remote working model for employees based in Ontario or British Columbia.
  • Opportunity to work across vulnerability management, AWS security, data security, SaaS security, automation, and security analytics.
  • High-impact role with broad visibility across engineering, security, compliance, and leadership teams.
  • Collaborative environment emphasizing responsible innovation, continuous improvement, customer focus, and inclusive teamwork.

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against Jobgether's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on Jobgether's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    Jobgether's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.