
Senior Security Developer, Vulnerability Management
Posted 16 hours ago

Posted 16 hours ago
This is a fully remote position, open to applicants in Canada.
• Take ownership and enhance Wealthsimple's tailored vulnerability management platform, which encompasses deployment, integrations, data modeling, and automation workflows.
• Develop automation solutions for triage, ticket routing, SLA monitoring, ownership resolution, and follow-up processes.
• Broaden the platform's application from a single team's workflow to encompass wider engineering practices.
• Incorporate scanner data into the vulnerability management framework.
• Sustain enrichment workflows that convert raw findings into actionable tickets.
• Create queries, dashboards, and automated reports to provide visibility into vulnerability posture.
• Remain updated on the threat landscape, including the role of AI in vulnerability research and exploitation.
• Assist in integrating the platform with the Cyber Reasoning System harness for sandbox validation and automated remediation.
• Over 4 years of practical experience in vulnerability management and/or security engineering, particularly with scanner integration, triage workflows, and remediation tracking.
• Experience with production AWS environments.
• A strong automation-oriented mindset with a track record of replacing manual processes.
• In-depth knowledge of vulnerability management tools such as Tenable, Semgrep, Rapid7, or similar scanners.
• Capability to build scanner integrations using APIs.
• Comprehensive understanding of the software development lifecycle.
• Familiarity with package and library vulnerabilities, as well as vulnerability classifications across application and infrastructure layers.
• Knowledge of scanner deployment across CI, production, and network stages.
• Practical experience with SAST/DAST/SCA tools and OWASP principles.
• Hands-on knowledge of GitHub Actions, ArgoCD, Kubernetes, AMIs, and container images like ECR.
• Understanding of attack surface and exposure management.
• Ability to translate business and partner requirements into effective solutions.
• Awareness of the interconnections between vulnerability management, CI/CD and deployment pipelines, threat intelligence, and bug bounty or responsible disclosure programs.
• Familiarity with compliance frameworks and vulnerability management controls.
• Active engagement with AI-assisted development workflows such as Claude Code, Cursor, Copilot, or similar tools.
• Legally eligible to work in Canada.
• Comprehensive health benefits and life insurance.
• Long-term group savings plan with employer matching, available through Wealthsimple for Business.
• 20 vacation days per year.
• 4 wellness days annually.
• Unlimited sick leave and mental health days each year.
• Opportunity to work outside Canada for up to 90 days per year.
• Access to employee resource groups, including Rainbow (2SLGBTQ), Women of WS, and Black at WS.
• Equity compensation for permanent employees.
Trail of Bits
Newxel
Xcelerate Solutions
Catholic Relief Services
Get handpicked remote jobs straight to your inbox weekly.