Senior Security Engineer - Vulnerability & Data/SaaS Security
Job description
This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Engineer - Vulnerability & Data/SaaS Security based in Canada.
This is a senior security engineering opportunity focused on strengthening vulnerability, cloud, data, and SaaS security programs across a complex technology environment.
You will own the day-to-day operation and continuous improvement of security programs spanning infrastructure, applications, containers, cloud platforms, data stores, and SaaS applications.
The role combines hands-on security engineering with automation, risk management, remediation orchestration, and executive reporting.
You will work with a broad security tooling ecosystem and build integrations that make detection, prioritization, and remediation more efficient.
A key part of the role is translating technical findings into meaningful business-risk insights for engineering teams, leadership, and audit stakeholders.
You will collaborate closely with application, cloud, platform, data, and business teams in a highly regulated technology environment.
The position is fully remote within Ontario or British Columbia, offering significant ownership and impact across enterprise security operations.
Accountabilities
- Own the end-to-end vulnerability management lifecycle, including triage, risk-based prioritization, remediation tracking, SLA enforcement, and exception management across infrastructure, applications, and containers.
- Review vulnerability findings from application security and dynamic testing platforms, coordinate remediation with relevant teams, and maintain compliance with established remediation timelines.
- Develop and continuously improve risk-prioritization models that consider severity, exploitability, business criticality, regulatory requirements, and potential impact.
- Lead the cloud security posture management program across AWS, identifying misconfigurations, configuration drift, and control violations while strengthening secure baselines for IAM, networking, storage, encryption, compute, and containers.
- Manage data security posture initiatives, including sensitive-data discovery, automated classification, data-flow and lineage visibility, and monitoring of cross-environment data replication.
- Operate and mature SaaS security posture management capabilities, including sanctioned and shadow SaaS discovery, OAuth and third-party application governance, and SaaS data exposure monitoring.
- Partner with application, cloud, platform, and data engineering teams to translate security policies into effective technical controls and remediation actions.
- Automate findings aggregation, ticket creation, remediation workflows, ownership assignment, SLA tracking, escalation, and risk-exception processes.
- Build and maintain API integrations between security platforms and downstream systems such as ticketing platforms, SIEMs, CMDBs, and data warehouses.
- Develop Python scripts and automation to enrich security findings with asset and ownership context, reduce manual triage, and improve the reliability of security dashboards.
- Define and maintain security KPIs and KRIs, including MTTD, MTTR, SLA compliance, coverage, and risk-reduction trends.
- Produce accurate executive dashboards and recurring reports that translate technical security findings into clear business-risk narratives and compliance insights.
- Support compliance alignment across frameworks such as PCI DSS, SOX, SOC 2, and ISO 27001.
- Continuously improve the reliability and coverage of security tooling integrations and monitoring programs.
- 5+ years of professional experience in security engineering, with hands-on ownership of vulnerability management, cloud security, application security, data security, or SaaS security programs.
- Direct experience with vulnerability management and application security platforms such as Tenable, Snyk, and StackHawk or equivalent technologies.
- Strong experience securing AWS environments and working with cloud security posture management tools.
- Experience with endpoint and cloud workload detection and response platforms such as CrowdStrike Falcon.
- Hands-on experience with data security posture management and SaaS security posture management solutions, such as Sentra and Reco or comparable platforms.
- Experience with security findings aggregation or application security posture management platforms such as ArmorCode, including integrations with ticketing systems such as Jira.
- Strong Python scripting and REST API integration skills, with the ability to build and maintain security data pipelines across multiple platforms.
- Experience developing security metrics, KPIs, KRIs, and executive-level dashboards from security tooling data.
- Familiarity with SIEM integrations and security automation or orchestration practices is an asset.
- Strong understanding of security and compliance frameworks relevant to regulated environments, including PCI DSS, SOX, SOC 2, and ISO 27001.
- Excellent written and verbal communication skills, with the ability to translate complex technical risks into clear business terms for non-technical and executive stakeholders.
- Strong analytical and problem-solving skills, with the ability to prioritize risks and drive remediation across multiple teams.
- Experience establishing vulnerability, risk-exception, and SLA governance processes is highly valued.
- Experience in fintech, payments, financial services, or another highly regulated industry is considered an advantage.
- Competitive annual base salary of CAD $136,800–$171,000, calibrated according to skills, experience, and working location.
- Annual bonus opportunities based on individual and overall company performance.
- Multiple health insurance options.
- Flexible vacation time plus additional floating holidays.
- Retirement savings program with company contributions.
- Equity participation in a publicly traded company.
- Monthly stipend to support remote work.
- Annual professional development stipend.
- Family-forming benefits.
- Up to 20 weeks of parental leave.
- Flexible-first remote working model for employees based in Ontario or British Columbia.
- Opportunity to work across vulnerability management, AWS security, data security, SaaS security, automation, and security analytics.
- High-impact role with broad visibility across engineering, security, compliance, and leadership teams.
- Collaborative environment emphasizing responsible innovation, continuous improvement, customer focus, and inclusive teamwork.
Requirements
Benefits
Skills mentioned

Jobgether is a Belgium-based, AI-powered remote-work job platform founded in 2020 in Brussels. It aggregates and enriches large volumes of remote and flexible job listings from many employers and matches candidates to roles; it is a job aggregator rather than the hiring employer.
Apply for this job
Use the application link supplied with this listing to apply to jobgether. Check the destination before entering personal information.
