Security Engineer (AI)
Мэтч & Сопровод
Для мэтча с этой вакансией нужен Plus
Описание вакансии
Location: Toronto, Ontario, Canada. Toronto-area employees living within 65 km of the downtown headquarters collaborate in-office Monday through Thursday; remote-eligible roles may be based anywhere in Canada or the US, but this posting is based in Toronto.
Salary: CAD 109,100–136,400 annual base salary for Canadian applicants, excluding bonus, equity, and benefits.
Company
is a Canadian healthcare experience platform serving health plans, health systems, providers, and more than 70 million people.
What you will do
- Conduct security reviews of product features, integrations, platform changes, applications, APIs, cloud configurations, and third-party vendors.
- Participate in threat modeling and document security requirements and actionable remediation guidance.
- Review AI-enabled features for prompt injection, excessive agency, agentic tool-use risks, and unintended exposure of member data.
- Configure, tune, and triage security tooling while automating manual reviews and embedding security checks into the software development lifecycle.
- Build reusable security controls, secure coding training, and internal security documentation.
- Support SOC 2 Type II, HITRUST, HIPAA, and PHIPA control design, testing, evidence gathering, and customer security assurance requests.
Requirements
- 2+ years of professional experience in application or product security, or software engineering with substantial security responsibility.
- Ability to identify broken access control, tenant isolation failures, business logic flaws, and vulnerabilities missed by scanners.
- Working knowledge of OAuth 2.0, OIDC, session and token handling, role- or attribute-based access control, and common application vulnerabilities such as the OWASP Top 10.
- Familiarity with CI/CD, software supply chain security, pipeline-integrated testing, dependency management, and secrets handling.
- Experience with AI and LLM application security, plus exposure to cloud security and secure cloud architecture, ideally on GCP with containerized workloads.
- Experience writing and shipping code in Python, Go, or a comparable language, along with exposure to threat modeling methodologies such as STRIDE.
Nice to have
- Experience handling PHI or similarly sensitive data in a regulated environment.
- Exposure to incident response.
- Self-directed security work, including side projects, CTFs, published research, or coordinated disclosure.
Culture & Benefits
- Security is treated as a shared responsibility, with a security-by-design and paved-road approach.
- Employees are expected to use AI tools thoughtfully in daily work while reviewing outputs for accuracy, bias, quality, and data responsibility.
- Flexible remote days are available each quarter depending on distance from the Toronto office.
- supports equal employment opportunity and provides assistance during the recruitment process when needed.
Hiring process
- A recruiter reviews applications and contacts aligned candidates to discuss goals and the team-specific interview process.
- Reference and background checks are conducted before joining; additional checks may apply to US candidates.
Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →