
Product Security Engineer
Posted Sep 11

Posted Sep 11
This is a fully remote position, open to applicants in Canada.
• Lead security evaluations of architecture, code, and changes that are sensitive to security.
• Assess risks associated with AI-driven products, such as prompt injection, unsafe tool usage, identity and delegation failures, excessive agency, data exposure, tenant isolation, and sandbox escapes.
• Conduct threat modeling for new features by identifying trust boundaries, abuse cases, and significant failure modes.
• Convert findings into actionable, prioritized mitigations.
• Investigate potential vulnerabilities and create proofs of concept.
• Evaluate exploitability and impact, collaborating with engineers during remediation efforts.
• Establish secure defaults, approved patterns, reusable controls, review requirements, and automated checks.
• Collaborate with engineers to document practical security guidance.
• Assist product teams in building sustainable security expertise.
• Articulate technical findings, business implications, and remediation strategies to engineers, product leaders, and executives.
• Strong foundation in software engineering with the ability to independently comprehend, test, and propose fixes to production codebases.
• Proficient in at least one programming language such as Python, Go, or TypeScript.
• Experience in leading security reviews or threat modeling for intricate production systems.
• Knowledge of injection, authorization flaws, IDOR, SSRF, unsafe deserialization, race conditions, cryptographic misuse, and software supply-chain vulnerabilities.
• Familiarity with web applications, APIs, OAuth/OIDC, cloud platforms, containers, Kubernetes, and CI/CD systems.
• Capability to reason about untrusted input, authorization, isolation, identity, delegation, and data boundaries.
• Proven experience in driving security enhancements across multiple engineering teams.
• Effective communication skills with both technical and non-technical audiences.
• Experience with SAST, DAST, SCA, custom linters, or policy-as-code is a plus.
• Background in securing multi-tenant SaaS, enterprise software, or systems that handle sensitive customer data is a plus.
• Offensive security experience through penetration testing, red teaming, or security research is a plus.
• Experience with vulnerability disclosure or bug bounty initiatives is a plus.
• Contributions to open-source security, published research, conference presentations, or credited vulnerability discoveries are a plus.
• A weekly lunch stipend of $75/£75 or its equivalent in your local currency for meals.
• Comprehensive health and dental coverage, along with a separate budget for mental health support.
• RRSP matching, 401K, and Pension Scheme.
• 100% Parental Leave top-up for up to 6 months for either parent.
• Annual enrichment benefits including arts & culture, fitness/wellness, quality time, and workspace improvement credit.
• Education and learning stipend available for conferences, courses, and coaching opportunities.
• 6 weeks of paid vacation (30 working days).
• Budget for travel to other offices for remote employees, plus an annual company offsite.
• Co-working benefit for employees not located near an office.
• $500 home office stipend.
• Daily lunch program, snacks, and regular community and social events for office-based employees.
VMD Corp
GR8 Tech
Modern Health
Accumulus Technologies
Get handpicked remote jobs straight to your inbox weekly.