Staff Security Engineer
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
TL;DR
Staff Security Engineer (Cybersecurity): Perform security assessments of third-party integrations and connected apps with an accent on mitigating API-related security risks and ensuring secure-by-design principles. Focus on threat modeling, operationalizing AI for security reviews, and developing repeatable workflows for enterprise integrations like Salesforce and Slack.
Toronto, Ontario, Canada (#LI-HYBRID)
$141,000 — $193,000 CAD
Company
is The World’s Identity Company providing secure access, authentication, and automation via Platform and Auth0 Platform.
What you will do
- Lead technical security reviews and threat modeling for complex enterprise applications and third-party integrations.
- Operationalize AI for security use cases like integration security reviews to automate and scale operations.
- Analyze and document API permissions and risk levels for major integrations (e.g., Salesforce, Slack, Google).
- Design and implement repeatable security review workflows in collaboration with stakeholders.
- Identify vulnerabilities and security control gaps in connected apps and recommend mitigation strategies.
- Maintain metrics and dashboards demonstrating overall security posture for leadership.
Requirements
- Proven experience in information security, specifically application and enterprise security.
- Strong background in assessing and mitigating risks for third-party APIs and connected apps.
- Understanding of secure-by-design principles and least privilege model.
- Hands-on experience with threat modeling, attack vectors, and risk assessments.
- Experience with security platforms for application permissions and interest in AI for security tasks.
- Bachelor's degree in Computer Science, information security, or related field.
Culture & Benefits
- Health, dental, and vision insurance, RRSP with match, healthcare spending, telemedicine.
- Paid leave including PTO and parental leave.
- Equity and bonus where applicable.
- Immersive in-person onboarding and global community across 20+ offices.
- Focus on well-being, social impact, talent development, and fostering connections.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →