Назад
Company hidden
2 дня назад

Lead Incident Security Responder (Cybersecurity)

100 000 - 150 000CAD
Формат работы
remote (только Canada)
Тип работы
fulltime
Грейд
lead
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/

TL;DR

Lead Incident Security Responder (Cybersecurity): Driving applied product security across the portfolio with an accent on threat modeling, vulnerability triage, and secure SDLC integration. Focus on coordinating complex security projects, managing customer-facing security inquiries, and enhancing incident response capabilities within a DevSecOps environment.

Location: Must be based in Canada (Remote)

Salary: $100,000 – $150,000 CAD

Company

A pioneer in application security providing SAST, SCA, and DAST solutions to help organizations build secure software throughout the development lifecycle.

What you will do

  • Partner with engineering teams on architecture reviews, threat models, and security design feedback.
  • Triage internally discovered and externally reported product vulnerabilities and drive resolution.
  • Coordinate customer-facing security communications, questionnaires, and audit requests.
  • Maintain and tune detection content in SIEM platforms and contribute to SOAR automations.
  • Lead discrete security workstreams and mentor less experienced team members.
  • Support incident response activities with a focus on product-related security risks.

Requirements

  • Must be based in Canada.
  • 7–8+ years of experience in product security, application security, or security engineering.
  • Hands-on depth in at least two areas: secure SDLC, threat modeling, secure code review, vulnerability management, or incident response.
  • Working knowledge of application security tooling (SCA, SAST, DAST) and cloud platforms (AWS, Azure, or GCP).
  • Experience contributing to a Product Security Incident Response Team (PSIRT) or equivalent process.
  • Strong communication skills for explaining technical security topics to diverse stakeholders.

Nice to have

  • Industry certifications such as CISSP, CSSLP, GWAPT, GPEN, OSCP, or OSWE.
  • Experience supporting RFPs and third-party risk assessments.
  • Familiarity with AI and LLM security risks (OWASP Top 10 for LLM).

Culture & Benefits

  • Opportunity to work with industry-leading application security tools.
  • Collaborative environment partnering with engineering and security operations.
  • Focus on professional growth through mentorship and complex project leadership.
  • Commitment to equal opportunity and inclusive employment practices.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →