Назад
Company hidden
8 часов назад

Senior Security Engineer (Cybersecurity)

Формат работы
onsite
Тип работы
fulltime
Грейд
senior
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Senior Security Engineer (Cybersecurity): Building and operating a greenfield security platform across identity, endpoints, detection, automation, and compliance with an accent on phishing-resistant authentication, infrastructure-as-code, and Canadian data sovereignty. Focus on designing detection-as-code and SOAR workflows, integrating security tooling and GenAI/LLM models, and translating NIST, CPCSC, and ITSP.10.171 controls into automated engineering.

Location: On-site in Ottawa or Toronto, Canada

Company

hirify.global builds defence capability for the Canadian Armed Forces and its allies, with systems already deployed in the field.

What you will do

  • Design and operate the security platform across identity, endpoints, detection, automation, and compliance.
  • Build a Terraform-managed identity platform with SSO, SCIM, WebAuthn/FIDO2 authentication, and device-trust enforcement.
  • Deploy and tune EDR and maintain secure MDM baselines for managed macOS endpoints.
  • Integrate HRIS and IT asset-management systems to automate joiner, mover, leaver, and asset-lifecycle workflows.
  • Build SIEM log-ingestion pipelines, detection-as-code capabilities, and CI/CD-deployed detections.
  • Design SOAR automation integrating identity, secrets management, collaboration tools, security platforms, and GenAI/LLM models.

Requirements

  • 5+ years of experience in security engineering, infrastructure security, or a closely related discipline.
  • Hands-on experience with identity and access management, modern IdPs, SSO/SCIM, phishing-resistant MFA, and device trust.
  • Strong Terraform and security-tooling infrastructure-as-code experience.
  • Expertise in EDR, MDM, SIEM, log pipelines, detection-as-code, security automation, SOAR, APIs, and Python or similar scripting.
  • Working knowledge of NIST SP 800-171, CMMC/CPCSC, and ITSP.10.171, including translating controls into engineering work.
  • Must work on-site in Ottawa or Toronto, Canada. Canadian data-residency requirements apply, and eligibility to obtain a Canadian Reliability or Secret security clearance is an asset.

Nice to have

  • Experience in defence, government, critical infrastructure, or other regulated environments.
  • Experience securing GenAI/LLM systems and building AI-driven security automation.
  • Exposure to OT, embedded, robotics, or autonomous-systems security.
  • OSCP, GIAC, or other relevant certifications.
  • Defence background is not required.

Culture & Benefits

  • High-ownership role with direct access to leadership and short feedback loops.
  • Opportunity to build defence capability for the Canadian Armed Forces and allies.
  • Competitive base salary and company equity.
  • Comprehensive health benefits.
  • Additional equity based on impact; equity is available to full-time employees.

Hiring process

  • AI tools may support screening and response review.
  • Final hiring decisions are made by people in accordance with Canadian privacy and employment laws.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →