6 days ago
Toronto, CanadaMid Level
H1B Sponsor
Responsibilities
- Conduct security reviews of product features, integrations, platform changes, applications, APIs, cloud configurations, and third-party vendors.
- Participate in threat modeling and document security requirements and remediation guidance.
- Review AI-enabled features for prompt injection, excessive agency, agentic tool-use risk, and unintended member-data exposure.
- Triage, score, route, and drive remediation of security findings with owning teams.
- Configure, tune, and manage security tooling workflows.
- Automate manual reviews and embed security checks and reusable controls into the software development lifecycle.
- Create secure-coding training materials and documentation and share security knowledge with peers.
- Contribute to security standards, internal documentation, customer security assurance, and SOC 2 Type II, HITRUST, HIPAA, and PHIPA control activities.
- Communicate security risks to software engineers, infrastructure leadership, and other audiences.
- Execute access-management responsibilities and follow organizational security policies and incident-notification procedures.
Requirements
- At least 2 years of professional experience in application or product security, or software engineering with substantial security responsibility.
- Ability to identify issues scanners miss, including broken access control, tenant-isolation failures, and business-logic flaws.
- Working knowledge of OAuth 2.0, OIDC, authentication, authorization, session and token handling, and role- or attribute-based access control.
- Familiarity with CI/CD and software supply-chain security, including pipeline-integrated testing, dependency management, and secrets handling.
- Working knowledge of common application vulnerabilities such as the OWASP Top 10 and their mitigations.
- Experience with AI and LLM application security, including prompt injection, agentic tool-use risk, and retrieval-pipeline exposure.
- Exposure to cloud security and secure cloud architecture, ideally in GCP, including containerized workloads.
- Experience writing and shipping relied-upon code in Python, Go, or a comparable language.
- Some experience with threat-modeling methodologies such as STRIDE.
- Awareness of SOC 2 Type II, HITRUST, HIPAA, and PIPEDA.
- Preferred qualifications include experience with PHI or similarly sensitive regulated data, incident response exposure, and self-directed security work such as side projects, CTFs, published research, or coordinated disclosure.
Benefits
- Full-time position with a Canada base-salary range of $109,100–$136,400 CAD, exclusive of bonus, equity, and benefits.
- Remote-eligible roles may be based anywhere in Canada or the US; Toronto-area employees within 65 km of headquarters collaborate in-office Monday through Thursday.
- Toronto-area employees receive 10 or 20 Flexible Remote Days per quarter depending on distance from the office.
- Reference and background checks are conducted before joining, with additional checks potentially required for US candidates.
Tech Stack
Categories
About League
Founded in 2014, League is a platform technology company powering the next generation of healthcare consumer experiences. Payers, providers, and consumer health organizations build on League's healthcare experience platform to deliver personalized, high-engagement health experiences that close care gaps, reduce costs, and drive better outcomes. League's platform is built to meet the most stringent standards in healthcare, including HITRUST r2, SOC 2 Type II, HIPAA, PIPEDA, and GDPR compliance, with security, privacy, and AI guardrails built in by design. Millions of people use solutions powered by League to access, navigate, and manage their health every day. Learn more at league.com.