12 hours ago
Montréal, CanadaStaff+
Responsibilities
- Define the multi-year security engineering roadmap and build security tooling, services, automation, standards, and review practices.
- Own Cloudflare edge security, including WAF rules, rate limiting, bot management, and DDoS posture.
- Own AWS and Kubernetes security architecture and lead the Wiz cloud security program, including identity, networking, secrets, encryption, hardening, admission control, image supply chain, and runtime posture.
- Implement policy-as-code in Terraform and CI/CD security enforcement covering SAST, SCA, secrets, and container scanning.
- Own vulnerability management, including intake, exploitability-based prioritization, SLAs, automation, and reporting.
- Lead detection engineering, log source onboarding, and technical incident response for cloud and application infrastructure.
- Lead threat modeling, security design reviews, and technical escalations for complex security engineering decisions.
- Secure AI agents, agentic workflows, and developer pipelines through threat modeling, guardrails, and review standards.
- Build control automation supporting SOC 2, HIPAA, and customer assurance.
- Mentor engineers and represent the security engineering approach to customers and auditors.
Requirements
- Bachelor’s or advanced degree in Computer Science, Cybersecurity, Software Engineering, Computer Engineering, Information Technology, or a related technical field.
- Extensive hands-on experience in DevSecOps, cloud security engineering, or platform and SRE work with deep security ownership at staff or principal technical scope.
- Deep AWS security expertise, including IAM, VPC networking, KMS, and organizational controls.
- Deep production experience securing and hardening Kubernetes clusters.
- Production experience owning a WAF and edge security platform, ideally Cloudflare.
- Strong production software engineering ability in Python, Go, or a comparable language.
- Deep hands-on Terraform experience, including module design, review at scale, and policy-as-code.
- Experience designing CI/CD security enforcement that developers adopt.
- Strong application security fundamentals, including OWASP Top 10, secure design, threat modeling, and architectural secure code review.
- Detection engineering experience with a modern SIEM such as Panther or Splunk and experience leading cloud incident response.
- Experience building agents and agentic automation and evaluating their security risks.
- Ability to assess and communicate real risk to engineers, executives, and auditors.
- Ability to lead and influence across engineering without direct authority and mentor senior engineers.
- Experience in healthcare, home health, or medical devices is an asset.
- Bilingual French and English is required or expected.
Benefits
- Equity in a well-funded, scaling company.
- Comprehensive health benefits, telemedicine, and lifestyle spending accounts.
- Parental leave top-up and family support programs.
- Wellness Fridays, volunteer time off, flexible vacation, mentorship, career mobility, and promote-from-within opportunities.
- Montreal-based hybrid work model with two set in-office collaboration days per week.
- Employee-led DEIB events, summits, and social activities in person and virtually.
About AlayaCare
AlayaCare builds a cloud-based platform for home and community care providers, combining clinical documentation, scheduling, billing, client/family portals, and mobile caregiver apps. It sells its software on a SaaS basis to home health, personal care, and IDD agencies across North America and Australia. Founded in 2014 and headquartered in Montreal, the company is privately held.
