4 hours ago
Toronto, CanadaSenior
Responsibilities
- Harden AWS and Kubernetes environments against CIS Benchmarks, DISA STIGs, and FedRAMP Moderate baselines using remediation tooling, evidence, and security posture KPIs.
- Own Kubernetes and container security for EKS, Istio, RBAC, workload identity, admission control, container provenance, and runtime policy.
- Build and operate security platforms, services, and automation using Python or Go, Terraform, Kubernetes policy-as-code, and agentic tooling.
- Define and operate PKI, certificate lifecycle, encryption, TLS/mTLS, KMS-backed key management, and key rotation standards.
- Design Service Control Policy guardrails and least-privilege IAM/PAM across multiple AWS accounts and organizations.
- Author and tune SIEM detections and conduct threat hunting for container escape, lateral movement, anomalous mesh traffic, and identity or credential abuse.
- Participate in on-call rotations, triage cloud and Kubernetes alerts, act as Incident Commander, and lead containment and post-incident reviews.
- Partner with AppSec and GRC teams to align platform controls and produce audit and compliance evidence.
- Mentor teammates, contribute to roadmap and annual planning, and support external- and auditor-facing communications at the senior end of the role.
Requirements
- 5+ years of security engineering experience with deep hands-on expertise securing Kubernetes and containerized environments.
- Strong software engineering background building and operating production systems at scale, with proficiency in Python and/or Go or similar and Terraform-based Infrastructure as Code.
- Experience with EKS, Kubernetes RBAC, admission control, OPA/Gatekeeper or Kyverno, network policy, IRSA or pod identity, container runtime and image security, and Istio or another service mesh.
- Deep expertise with AWS security services and least-privilege IAM/PAM, including IAM, Organizations/SCPs, Secrets Manager, KMS, GuardDuty, CloudTrail, and Config.
- Experience automating security controls as code, informing SIEM detection strategy, threat hunting, incident response, and on-call operations.
- Experience scoping ambiguous projects, driving them to completion with high ownership, and building AI or agentic security automation.
- Preferred experience with PKI, cryptography, TLS/mTLS, HSM/KMS, CIS Benchmarks, DISA STIGs, FedRAMP, NIST CSF, SOC 2, or ISO 27001.
- Preferred experience with Wiz, CrowdStrike Falcon, Azure Entra ID, Defender for Cloud, and securing AI/ML or agentic workloads.
- Demonstrated mentoring and strong written and verbal communication skills, plus working knowledge of PagerDuty Incident Management and Process Automation products.
Benefits
- Base salary range of 156,800–206,800 CAD, with possible bonus, commission, equity, and benefits.
- Hybrid work model requiring two days per week from the Toronto, Ontario office; candidates must reside in an eligible location.
- Comprehensive benefits, flexible work arrangements, company equity, ESPP, retirement or pension plan, paid vacation, paid holidays, and sick leave.
- Dutonian Wellness Days and HibernationDuty paid days off, paid parental leave, and 20 hours of paid volunteer time annually.
- Mental wellness programs and company-wide hack weeks.
About PagerDuty
PagerDuty builds a subscription SaaS platform for incident response, on‑call management, AIOps, and workflow automation used by DevOps, IT, SRE, security, and support teams. Its cloud service centralizes alerts, orchestrates real-time response, and integrates with monitoring and ticketing tools. Founded in 2009 and headquartered in San Francisco, the public company (NYSE: PD) counts 60 of the Fortune 100 among its customers, including Netflix and Cisco.
