11 months ago
Responsibilities
- Advise leadership and partner teams on business risks associated with security issues
- Lead vulnerability management, SAST, DAST, detection engineering, and incident response functions
- Integrate security into applications throughout the software development lifecycle
- Partner with product and development teams on secure delivery for larger projects
- Drive and support the bug bounty program, application security reviews, threat modeling, code review, and dynamic testing
- Assess and integrate security tools to automate and scale security processes
- Gather and analyze security metrics to address issues involving cross-team dependencies
Requirements
- At least 5 years of experience in application/product security or security operations, with a strong focus on security tool onboarding and optimization
- Understanding of vulnerability management, network security, cloud security concepts, and security industry best practices
- Deep technical understanding of common security vulnerabilities, risks, countermeasures, and compensating controls
- Knowledge of secure engineering best practices and the ability to communicate with technical and non-technical audiences
- Ability to make informed decisions with limited data and navigate ambiguity
- Ability to evaluate build-versus-buy trade-offs and review available security tools
- Hands-on interest in automating security controls
- Flexible, constructive, and empathetic problem-solving approach
Benefits
- Weekly lunch stipend, in-office lunches and snacks
- Full health and dental benefits, including a separate mental health budget
- 100% parental leave top-up for up to 6 months
- Personal enrichment benefits for arts and culture, fitness and well-being, quality time, and workspace improvement
- Remote-flexible work with offices in Toronto, New York, San Francisco, London, and Paris
- Co-working stipend
- Six weeks of vacation, or 30 working days
Categories
About Cohere
Cohere builds large language models and an enterprise AI platform that companies use for search, summarization, and workflow automation, delivered via API or private deployments. Founded in 2019 and headquartered in Toronto, it focuses on multilingual models, data controls, and options to run across major clouds or on-premises. The business is privately held and serves security- and compliance-sensitive organizations.
