
Staff Security Engineer
Posted Jul 28

Posted Jul 28
This is a fully remote position, open to applicants in Canada.
• Take ownership of the complete architecture of Forward’s security technology stack, including the platforms, tools, data pipelines, and integrations that support AppSec, SecOps, and GRC, ensuring seamless functionality within the wider Engineering, IT, and Infrastructure ecosystem.
• Establish the technical guidelines for evaluating, integrating, standardizing, and decommissioning security tools, while defining the reference architectures and standards that the department adheres to.
• Serve as the foundational technical resource for all three security functions: assisting developers in embedding security testing into software delivery, providing the operations team with reliable data for threat detection and investigation, and equipping the compliance team with the necessary evidence and reporting to demonstrate effective controls.
• Collaborate with Engineering, IT, and Infrastructure to embed security into shared platforms such as cloud (AWS), identity, CI/CD, endpoints, and SaaS, ensuring that security is an intrinsic part rather than an afterthought.
• Lead the evaluation, proof-of-concept, and implementation of new security technologies; streamline overlapping tools and minimize operational complexity through well-justified build-versus-buy recommendations.
• Employ infrastructure-as-code and detection-as-code methodologies to automate, version, and repeat security configurations, platform hardening, and cloud-native controls.
• Design our centralized logging and detection data infrastructure (SIEM and supporting pipelines) to create a single, high-quality data source that meets the needs of detection, investigation, and auditing.
• Architect the foundational elements of our identity governance and role-based access control programs, including the automation that maintains defensible access as we scale.
• Ensure the security architecture is aligned with frameworks such as CIS Controls, ISO 27001, SOC 2, and NIST, maintaining its defensibility and auditability.
• Provide senior technical assistance during major incidents, using lessons learned to drive enduring architectural enhancements.
• Elevate the standards for the entire department by mentoring and technically guiding engineers across AppSec, SecOps, and GRC on design quality, secure defaults, and engineering best practices.
• Typically possess 7 or more years of experience in security engineering, security architecture, detection engineering, or security operations, including the design of systems that span multiple security domains.
• Proven experience in owning or significantly influencing the architecture of a security technology stack, focusing on how platforms, data, and controls interconnect rather than merely operating a single tool.
• Extensive hands-on expertise in cloud security (AWS required; GCP or Azure is a plus), including control plane monitoring, IAM, network architecture, and infrastructure log analysis.
• A history of integrating security tools and controls into broader Engineering and IT ecosystems, including CI/CD, identity management, endpoints, and SaaS.
• Proficient in at least two of the three domains relevant to this role – AppSec, SecOps, and GRC – with sufficient understanding of the third domain to facilitate design considerations.
• Experience with infrastructure-as-code and/or detection-as-code (e.g., Terraform and CI/CD pipelines for security configurations and detection logic).
• Familiarity with security frameworks such as CIS Controls, ISO 27001, SOC 2, and NIST, and understanding how architecture aligns with control and audit requirements.
• Experience with modern programming languages such as Ruby, Python, or Go, adequate for building automation and integrations.
• Capability to articulate risk and technical direction clearly to both engineers and executives.
• Typically holds a Bachelor’s Degree in Computer Science, Physics, or a related technical field, or possesses equivalent industry experience.
• Medical
• Dental
• Vision
• Flexible time-off policy
• Paid parental leave
• RRSP match
• Wellness reimbursement
• Volunteering days
• Annual professional development budget
• Charitable donation match
ASG Technologies
CrowdStrike
Culmen International
Threatscape
Get handpicked remote jobs straight to your inbox weekly.