Назад
Company hidden
9 часов назад

Security Engineer (AI)

109 100 - 136 400CAD
Формат работы
hybrid
Тип работы
fulltime
Грейд
middle
Английский
b2
Страна
Canada
Вакансия из списка Hirify.GlobalВакансия из Hirify Global, списка международных tech-компаний
Для мэтча и отклика нужен Plus

Мэтч & Сопровод

Для мэтча с этой вакансией нужен Plus

Описание вакансии

Текст:
/
TL;DR
Security Engineer (AI) (Application and Cloud Security): Scaling security across the software development lifecycle through security reviews, threat modeling, vendor assessments, and integrated tooling with an accent on AI-enabled product security, access control, and regulated healthcare data. Focus on building automated security controls, assessing applications and cloud configurations, and driving remediation for complex vulnerabilities across product and infrastructure teams.

Location: Toronto, Ontario, Canada. Toronto-area employees living within 65 km of the downtown headquarters collaborate in-office Monday through Thursday; remote-eligible roles may be based anywhere in Canada or the US, but this posting is based in Toronto.

Salary: CAD 109,100–136,400 annual base salary for Canadian applicants, excluding bonus, equity, and benefits.

Company

hirify.global is a Canadian healthcare experience platform serving health plans, health systems, providers, and more than 70 million people.

What you will do

  • Conduct security reviews of product features, integrations, platform changes, applications, APIs, cloud configurations, and third-party vendors.
  • Participate in threat modeling and document security requirements and actionable remediation guidance.
  • Review AI-enabled features for prompt injection, excessive agency, agentic tool-use risks, and unintended exposure of member data.
  • Configure, tune, and triage security tooling while automating manual reviews and embedding security checks into the software development lifecycle.
  • Build reusable security controls, secure coding training, and internal security documentation.
  • Support SOC 2 Type II, HITRUST, HIPAA, and PHIPA control design, testing, evidence gathering, and customer security assurance requests.

Requirements

  • 2+ years of professional experience in application or product security, or software engineering with substantial security responsibility.
  • Ability to identify broken access control, tenant isolation failures, business logic flaws, and vulnerabilities missed by scanners.
  • Working knowledge of OAuth 2.0, OIDC, session and token handling, role- or attribute-based access control, and common application vulnerabilities such as the OWASP Top 10.
  • Familiarity with CI/CD, software supply chain security, pipeline-integrated testing, dependency management, and secrets handling.
  • Experience with AI and LLM application security, plus exposure to cloud security and secure cloud architecture, ideally on GCP with containerized workloads.
  • Experience writing and shipping code in Python, Go, or a comparable language, along with exposure to threat modeling methodologies such as STRIDE.

Nice to have

  • Experience handling PHI or similarly sensitive data in a regulated environment.
  • Exposure to incident response.
  • Self-directed security work, including side projects, CTFs, published research, or coordinated disclosure.

Culture & Benefits

  • Security is treated as a shared responsibility, with a security-by-design and paved-road approach.
  • Employees are expected to use AI tools thoughtfully in daily work while reviewing outputs for accuracy, bias, quality, and data responsibility.
  • Flexible remote days are available each quarter depending on distance from the Toronto office.
  • hirify.global supports equal employment opportunity and provides assistance during the recruitment process when needed.

Hiring process

  • A recruiter reviews applications and contacts aligned candidates to discuss goals and the team-specific interview process.
  • Reference and background checks are conducted before joining; additional checks may apply to US candidates.

Будьте осторожны: если работодатель просит войти в их систему, используя iCloud/Google, прислать код/пароль, запустить код/ПО, не делайте этого - это мошенники. Обязательно жмите "Пожаловаться" или пишите в поддержку. Подробнее в гайде →