8 hours ago
Vancouver, CanadaSenior
Responsibilities
- Design and improve security guardrails across AWS organizations, accounts, networks, and identity and access management.
- Define and implement security standards for Kubernetes, containers, secrets, credentials, and encryption.
- Own and improve Cloudflare edge security controls, including DNS, WAF, abuse prevention, and Zero Trust access.
- Secure cloud workloads, including AI services and agents, and address their access to infrastructure, data, credentials, and internal tools.
- Embed security controls into infrastructure-as-code workflows and CI/CD pipelines.
- Operate and improve the cloud security posture management platform, including triage, risk prioritization, and remediation workflows.
- Strengthen cloud logging, monitoring, threat detection, and incident response readiness.
- Identify and mitigate security risks from AI agents, including permissions, tooling access, credential exposure, and data leakage.
- Develop automation and reusable security controls for secure infrastructure operations.
- Partner with DevOps and Engineering to evaluate cloud architecture, resolve risks, and implement secure defaults.
- Help define the cloud security roadmap and communicate priorities and progress to stakeholders and leadership.
- Mentor engineers, developers, and testers and help foster continuous learning.
Requirements
- 5+ years of experience in software engineering, cloud engineering, infrastructure, DevOps, or a related technical role in a SaaS environment.
- 3+ years of experience in cloud security, infrastructure security, or a related engineering role.
- Strong hands-on experience securing production workloads in AWS, including IAM, networking, logging, and native security services.
- Experience securing Kubernetes and containerized environments.
- Experience securing edge infrastructure with Cloudflare or a similar platform, including DNS, WAF, and Zero Trust access.
- Proficiency with CloudFormation, CDK, Terraform, or similar tools, including integrating security controls into infrastructure-as-code and CI/CD workflows.
- Experience operating a CNAPP or CSPM platform such as Wiz, Prisma Cloud, or a comparable tool.
- Experience with cloud threat detection, vulnerability management, incident investigation, and remediation.
- Understanding of emerging security risks in agentic and AI-enabled systems.
- Scripting or programming experience with Python, Go, Bash, or a similar language.
- Strong communication, collaboration, learning, adaptability, and attention to detail.
- Passion for mentoring and enabling teams to deliver high-quality, secure solutions.
Benefits
- Hybrid work environment with two in-office days per week.
- Four weeks of annual vacation and paid time off for office holiday closures.
- RRSP matching.
- CAD $2,000 annual health and lifestyle spending account.
- CAD $1,000 annual education budget.
- CAD $1,000 annual charitable donation matching.
- Comprehensive extended health, critical illness, long-term disability, and life insurance benefits.
- Company-issued MacBook and home office budget.
- Anniversary rewards and complimentary Pixieset premium account.
- Team-building activities and company-wide events.
- The position offers a typical salary range of CAD $117,800-$160,650 annually.
