About the company
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer, Platforms & AI based in Canada.
Responsibilities
- Secure and harden cloud infrastructure, applications, APIs, internal systems, and operational workflows across production environments.
- Implement and maintain security controls covering CI/CD pipelines, cloud infrastructure, internal tooling, encryption, secrets management, logging, monitoring, and access controls.
- Partner directly with engineering teams to identify vulnerabilities, coordinate remediation, validate fixes, and strengthen secure development practices.
- Design and continuously improve security architecture for cloud-native and distributed systems while building scalable security processes into engineering workflows.
- Lead vulnerability management activities, including assessment, prioritization, remediation, and validation across infrastructure, applications, APIs, and operational systems.
- Proactively identify weaknesses through vulnerability scanning, penetration testing, adversarial testing, threat modeling, and manual security reviews.
- Secure AI-driven systems and automated agents against prompt injection, adversarial inputs, unauthorized actions, unsafe outputs, and data leakage.
- Design guardrails and validation layers for AI-generated actions and ensure systems can safely process untrusted inputs from IVRs, web applications, APIs, and human interactions.
- Monitor AI behavior for anomalies, abuse attempts, and unsafe decision-making while ensuring systems remain observable, auditable, appropriately bounded, and capable of failing safely.
- Improve security monitoring, alerting, logging, detection, and incident response capabilities across the environment.
- Investigate suspicious activity and security incidents, lead or support root-cause analysis, and implement preventative measures following incidents or security discoveries.
- Help establish a culture of continuous security improvement, operational accountability, and resilient engineering practices.
Requirements
- 7+ years of hands-on experience in security engineering, infrastructure security, application security, DevSecOps, offensive security, or a closely related discipline.
- Exceptional knowledge of the AWS ecosystem and experience securing cloud-based production environments.
- Demonstrated experience identifying, prioritizing, and remediating vulnerabilities in live production systems.
- Strong understanding of security architecture, cloud infrastructure, applications, APIs, access controls, secrets management, monitoring, and secure development practices.
- Experience with vulnerability scanning, penetration testing, threat modeling, adversarial testing, or manual security assessments.
- Strong ability to investigate security events, analyze root causes, and implement effective remediation and prevention measures.
- Ability to work directly with engineering teams and translate complex security risks into practical technical solutions.
- Strong communication skills, with the ability to clearly explain technical security issues and recommendations to engineering and other stakeholders.
- Highly autonomous and proactive, with the ability to drive projects, make sound decisions, and prioritize effectively in a fast-moving environment.
- Experience securing AI/LLM-powered systems, automated agents, or other AI-driven applications is preferred.
- Familiarity with prompt injection, adversarial AI techniques, AI guardrails, behavioral anomaly detection, and responsible AI security practices is a plus.
- Experience with cloud security tooling, SIEM and observability platforms, penetration testing tools, endpoint security platforms, or infrastructure-as-code security is advantageous.
- Experience in a high-growth startup, fintech, banking, payments, or similarly regulated technology environment is preferred.
- Security certifications such as CISSP, CISM, AWS Security Specialty, or equivalent are a plus.
- Ability to work remotely from the United States; the original role also permits candidates based in Canada.
Conditions
- 100% remote-first work culture.
- Competitive salary and equity opportunities.
- Unlimited paid time off.
- Flexible working schedule and paid holidays.
- Comprehensive health, dental, and vision insurance.
- High-ownership culture emphasizing transparency, autonomy, and technical craftsmanship.
- Opportunities to own security architecture and take on significant technical leadership responsibilities.
- Opportunity to work on emerging AI security challenges and help shape security practices as the organization scales.