
Security Engineer II
Posted 1 day ago

Posted 1 day ago
This is a fully remote position, open to applicants in Canada.
• Integrate Security by Design principles into agile software development and cloud-native settings.
• Develop and sustain security tools and automation that enhance the effectiveness of the security team.
• Serve as a Subject Matter Expert, providing mentorship and support for security engineering initiatives throughout the organization.
• Contribute to the formulation of application security policies, processes, standards, and guidelines, and create tools that enforce these measures.
• Assist engineering teams in designing and constructing high-performing, secure applications utilizing risk-based mitigation strategies.
• Create SIEM detection rules and response playbooks in Chronicle / Google SecOps using YARA-L.
• Develop and maintain security automation pipelines in Python/Go, vulnerability management tools, GHAS automation, and CI/CD security integrations.
• Oversee the identification, triage, and remediation coordination of vulnerabilities across both application and infrastructure layers.
• Implement supply chain security measures including Aikido, SLSA, and dependency pinning.
• Conduct RBAC cleanup, implement access architecture, perform user access reviews, and establish GitHub organization security policies.
• Manage CSPM findings triage, validate cloud security baselines, and implement security measures for Snowflake data warehouses.
• Define DLP policies and assess tools; execute credential and secrets hygiene programs.
• A minimum of 4+ years of overall experience, with at least 2+ years focused on Application Security or Security Engineering.
• Proven experience in developing security automation — including vulnerability management scripts, CI/CD pipeline integrations, detection rules, or similar tools utilized in production by engineering teams.
• Practical experience with Secure by Design development methodologies, including involvement in security architecture and design reviews.
• Experience in securing production systems within cloud environments (GCP preferred; AWS or Azure are also beneficial).
• Proficient in creating maintainable components using Python or Go.
• Practical knowledge of Jenkins, Cloud Build, CircleCI, or comparable platforms.
• Familiarity with containerization (e.g., Docker, OCI), Terraform, and Kubernetes (K8s).
• Experience with SAST/DAST/SCA/CSPM tools.
• Knowledge of CodeQL, Wiz, or similar platforms is an advantage.
• A Bachelor's degree in Computer Science is preferred, or equivalent practical experience.
• Excellent communication skills.
• Dedication to teamwork, professionalism, and authenticity.
• Visa Sponsorship is not available at this time.
• Competitive compensation and equity plan within the industry.
• Flexible time off, sick days, and 13 paid holidays.
• Comprehensive medical insurance including Health, Dental, and Vision coverage.
• Paid parental leave along with fertility, adoption, and other family planning benefits.
• Monthly allowance for wellness, reading materials, and access to LinkedIn Learning for ongoing development.
• Team-based and company-wide events and activities that inspire, educate, and foster community.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.