
Senior Security Engineer
Posted 6 days ago

Posted 6 days ago
This is a fully remote position, open to applicants in Canada.
• Report directly to the VP of Engineering and collaborate closely with the CTO and DevOps as a member of Roofr's security guild.
• Design and enhance security infrastructure across cloud environments, which includes network segmentation, firewalls, IDS/IPS, VPNs, WAF, and EDR.
• Manage vulnerability assessments end to end, encompassing evaluations, authenticated scans, triage, prioritization, and remediation SLAs.
• Develop and refine SIEM/SOAR detection content and alerting logic based on actual attack techniques.
• Serve as the incident commander during security incidents; responsible for containment, eradication, conducting forensics, and drafting post-incident reviews.
• Conduct threat modeling for new features and infrastructure modifications prior to their release.
• Oversee IAM hygiene and maintain cloud security posture within production AWS accounts.
• Draft, implement, and uphold security policies and standards.
• Manage Roofr's compliance program by mapping controls to NIST CSF 2.0, SOC 2, and CCPA/CPRA, executing audits, addressing gaps, and maintaining evidence.
• Facilitate tabletop exercises and incident playbook drills.
• Integrate secure-by-design practices into engineering workflows and the software development lifecycle (SDLC).
• A Bachelor's degree in computer science, IT, cybersecurity, or equivalent practical experience.
• 5-8+ years of experience in security engineering, incident response, or similar infrastructure roles, including time served as the lead or senior responder on actual incidents.
• Relevant certifications such as CISSP, OSCP, GCIH, or CEH are highly advantageous.
• Strong understanding of network security fundamentals, including firewalls, VPNs, routing/segmentation, network boundaries, TLS, and DNS.
• Practical experience with AWS cloud security, including IAM policy design, VPC architecture, KMS/secrets management, and CloudTrail/GuardDuty or equivalent tools.
• Real-world incident response experience involving triage, containment, forensics, and root cause analysis.
• Familiarity with SIEM/SOAR tools and writing detection logic in Python/Bash.
• Proficient in NIST CSF 2.0, SOC 2, and CCPA/CPRA compliance frameworks.
• Comfortable reading and writing actual application code.
• Experience utilizing AI/LLM tools for threat intelligence is a plus.
• Familiarity with GDPR is advantageous.
• Experience with PHP/Laravel is beneficial.
• Comfort with Postgres is helpful.
• The first week of employment is mandatory paid time off (PTO).
• One Friday off each month.
• Company-wide paid shutdown during the week between Christmas and New Year’s.
• Flexible time off policy.
• 80% employer-covered benefits in the U.S.
• 100% employer-paid premiums for Extended Healthcare and Dental in Canada.
• RRSP/401k matching program.
• Generous Parental Leave policy.
• Annual company retreat featuring team-building activities.
• Opportunities for learning and development.
• Stipend for home office setup.
• Internet and phone allowance.
• Emphasis on a remote-first culture.
• Weekly paydays on Fridays.
• Equity participation.
• Significant opportunities for professional growth.
Robots & Pencils
Latitude IT Solutions | SDVOSB
Latitude IT Solutions | SDVOSB
11:11 SYSTEMS
Get handpicked remote jobs straight to your inbox weekly.