Principal Consultant - Cybersecurity & Agentic AI

Synechron

Toronto

Hybrid

CAD 180,000 - 280,000

Full time

5 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Paid annual leave
Personal leave
Comprehensive insurance plan (medical,
Dental
Vision
Long-term disability
RRSP with employer’s contribution
Udemy for Business
Coaching opportunities
Global projects

Job summary

Synechron, a global consulting firm, seeks a Principal Consultant, Agentic AI Cybersecurity Engineer to lead hands-on offensive and defensive security work, building agentic AI systems to find and remediate vulnerabilities across production code and infrastructure.

You will craft AI prompts, guardrails, and evaluation frameworks, perform penetration testing and red team exercises on critical applications, and integrate remediation into enterprise CI/CD pipelines while communicating risk to

Qualifications

  • 10+ years hands-on experience across software engineering, offensive security, and defensive security at a principal engineer level.
  • Deep fluency in vulnerability classes including memory safety, injection authentication and authorization flaws, cryptographic misuse, deserialization, race conditions, and supply chain attacks.
  • Extensive hands-on experience with penetration testing, red teaming, exploit development, reverse engineering, and secure code review against OWASP Top 10 and SANS 25, combined with defensive engineering experience.
  • Extensive hands-on experience with application security testing tools (SAST, DAST, IAST, SCA), including tuning, false positive analysis, exemption workflow design, and enterprise vulnerability management at scale.
  • Deep technical fluency with agentic AI coding tools and frameworks (Claude, Devin, Copilot, Windsurf, Cursor, MCP_, including prompt engineering, agent orchestration, reusable skill and tool design, guardrail design, and evaluation.
  • Strong architectural knowledge of modern CI.CD, container platforms (Docker, Kubernetes), cloud-native deployment patterns, and integration of security automation into developer workflows.

Responsibilities

  • Architect and operationalize the end-to-end agentic AI patching pipeline spanning detection, fix generation, automated testing, and release across SAST, DAST, SCA, IAST, container, and server vulnerabilities.
  • Use frontier AI models to discover novel vulnerabilities in production application and infrastructure code, develop proof-of-concept exploits, and validate that AI-generated fixes close the underlying root cause.
  • Build and maintain the library of reusable AI skills, prompts, evaluation harness, and tooling that power agentic vulnerability discovery, triage, remediation, false positive analysis, and exemption workflows at scale.
  • Design and operationalize AI-driven false positive analysis and exemption processes to reduce manual triage burden and surface only actionable findings to development teams.
  • Conduct hands-on penetration testing and red team exercise against critical applications and infrastructure to validate defensive controls and agent-generated remediations.
  • Extend agentic remediation coverage across SAST, SCA, DAST, IAST, container, and server vulnerabilities, including the data and tooling needed to connect findings back to source.
  • Design agent prompting, guardrails, evaluation frameworks, and appropriate human-in-the-loop controls to ensure safe autonomous code changes, testing, and deployment.
  • Drive integration of agentic remediation into enterprise CI/CD pipelines (Github, Jenkins, etc.) across the deployment landscape.
  • Communicate technical design, risk trade-offs, and delivery progress clearly to senior stakeholders including CIO, CISO, 2LOD, and Audit functions.

Skills

Penetration testing
Red team
Exploit development
Reverse engineering
Secure code review
AI tooling

Tools

Tenable
Aqua
Snyk
BrightSec

Job description

At Synechron, we believe in the power of digital to transform businesses for the better. Our global consulting firm combines creativity and innovative technology to deliver industry-leading digital solutions. Synechron’s progressive technologies and optimization strategies span end-to-end Artificial Intelligence, Consulting, Digital, Cloud & DevOps, Data, and Software Engineering, servicing an array of noteworthy financial services and technology firms. Through research and development initiatives in our FinLabs we develop solutions for modernization, from Artificial Intelligence and Blockchain to Data Science models, Digital Underwriting, mobile-first applications and more. Over the last 20+ years, our company has been honored with multiple employer awards, recognizing our commitment to our talented teams. With top clients to boast about, Synechron has a global workforce of 14500+, and has 55 offices in 20 countries within key global markets.

As “Principal Consultant, Agentic AI Cybersecurity Engineer” Candidate will work hands-on alongside our cybersecurity engineering and application security teams to build, operate, and advance the agentic AI systems that find, exploit, and remediate vulnerabilities end-to-end across our application and infrastructure estate. Operating at a principal engineer level, candidate will personally direct frontier AI models do discover vulnerabilities in production code, develop proof-of-concept exploits, generate and validate fixes, and integrate them into CI/CD pipelines with safe human-in-the-loop controls. Candidate will also build reusable AI skills, prompts, and tooling that make agentic vulnerability management efficient and scalable across the estate. Candidate will bring deep dual expertise across offensive and defensive security, penetration testing, and software engineering, and apply that fluency to push the boundaries of what is possible with agentic AI in a regulated enterprise environment.

The Role
Responsibilities:
  • Architect and operationalize the end-to-end agentic AI patching pipeline spanning detection, fix generation, automated testing, and release across SAST, DAST, SCA, IAST, container, and server vulnerabilities.
  • Use frontier AI models to discover novel vulnerabilities in production application and infrastructure code, develop proof-of-concept exploits, and validate that AI-generated fixes close the underlying root cause.
  • Build and maintain the library of reusable AI skills, prompts, evaluation harness, and tooling that power agentic vulnerability discovery, triage, remediation, false positive analysis, and exemption workflows at scale.
  • Design and operationalize AI-driven false positive analysis and exemption processes to reduce manual triage burden and surface only actionable findings to development teams.
  • Conduct hands-on penetration testing and red team exercise against critical applications and infrastructure to validate defensive controls and agent-generated remediations.
  • Extend agentic remediation coverage across SAST, SCA, DAST, IAST, container, and server vulnerabilities, including the data and tooling needed to connect findings back to source.
  • Design agent prompting, guardrails, evaluation frameworks, and appropriate human-in-the-loop controls to ensure safe autonomous code changes, testing, and deployment.
  • Drive integration of agentic remediation into enterprise CI/CD pipelines (Github, Jenkins, etc.) across the deployment landscape.
  • Communicate technical design, risk trade-offs, and delivery progress clearly to senior stakeholders including CIO, CISO, 2LOD, and Audit functions.
Requirements:
  • 10+ years hands-on experience across software engineering, offensive security, and defensive security at a principal engineer level, with demonstrated personal contributions to production codebases and published vulnerability research or penetration testing engagements.
  • Deep fluency in vulnerability classes including memory safety, injection authentication and authorization flaws, cryptographic misuse, deserialization, race conditions, and supply chain attacks, with hands-on experience finding and exploiting each.
  • Extensive hands-on experience with penetration testing, red teaming, exploit development, reverse engineering, and secure code review against OWASP Top 10 and SANS 25, combined with defensive engineering experience building detection and remediation capabilities.
  • Extensive hands-on experience with application security testing tools (SAST, DAST, IAST, SCA), including tuning, false positive analysis, exemption workflow design, and enterprise vulnerability management at scale.
  • Deep technical fluency with agentic AI coding tools and frameworks (Claude, Devin, Copilot, Windsurf, Cursor, MCP_, including prompt engineering, agent orchestration, reusable skill and tool design, guardrail design, and evaluation.
  • Strong architectural knowledge of modern CI.CD, container platforms (Docker, Kubernetes), cloud-native deployment patterns, and integration of security automation into developer workflows.
Preferred, but not required:
  • Relevant security certifications (OSCP, OSCE, OSEP, GXPN, GWAPT, CISSP, or equivalent).
  • Experience in financial services or highly regulated industries with exposure to SOX, SOC1, and regulatory audit.
  • Public evidence of offensive capability: published CVEs, bug bounty track record, conference talks (DEFCON, Black Hat, Offensive Con, Recon), CTF placements, or open-source security tooling contributions.
  • Hands-on experience with enterprise vulnerability tooling (Tenable, Aqua, Snyk, BrightSec) and remediation at scale.
  • Demonstrated ability to advise senior technology leaders and deliver within complex, multi-stakeholder enterprise environments.
We offer:
  • A multinational organization with 60 offices in 20 countries and the possibility to work abroad.
  • 15 days (3 weeks) of paid annual leave plus an additional 10 days of personal leave (floating days and sick days).
  • A comprehensive insurance plan including medical, dental, vision, life insurance, and long-term disability.
  • Flexible hybrid policy.
  • RRSP with employer’s contribution up to 4%.
  • A higher education certification policy.
  • On-demand Udemy for Business for all Synechron employees with free access to more than 5000 curated courses.
  • Coaching opportunities with experienced colleagues from our Financial Innovation Labs (FinLabs) and Center of Excellences (CoE) groups.
  • Cutting edge projects at the world’s leading tier-one banks, financial institutions and insurance firms.
  • A truly diverse, fun-loving and global work culture.
SYNECHRON’S DIVERSITY & INCLUSION STATEMENT

Diversity & Inclusion are fundamental to our culture, and Synechron is proud to be an equal opportunity workplace and is an affirmative action employer. Our Diversity, Equity, and Inclusion (DEI) initiative ‘Same Difference’ is committed to fostering an inclusive culture – promoting equality, diversity and an environment that is respectful to all. We strongly believe that a diverse workforce helps build stronger, successful businesses as a global company. We encourage applicants from across diverse backgrounds, race, ethnicities, religion, age, marital status, gender, sexual orientations, or disabilities to apply. We empower our global workforce by offering flexible workplace arrangements, mentoring, internal mobility, learning and development programs, and more. All employment decisions at Synechron are based on business needs, job requirements and individual qualifications, without regard to the applicant’s gender, gender identity, sexual orientation, race, ethnicity, disabled or veteran status, or any other characteristic protected by law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Offensive Security Engineer- Principal Consultant
Offensive Security Engineer- Principal Consultant

Synechron • Toronto

Hybrid
CAD 130,000 - 140,000
Global offices
Paid annual leave + personal leave
Comprehensive insurance plan
+6
Senior GEN AI Engineer
Senior GEN AI Engineer

Synechron • Toronto

Hybrid
CAD 120,000 - 130,000
15 days of paid annual leave
Comprehensive insurance plan
Flexible hybrid policy
+3
Senior Developer (Java / Python / AWS / DevOps)
Senior Developer (Java / Python / AWS / DevOps)

Synechron • Mississauga

Hybrid
CAD 110,000 - 115,000
Laptop and mobile phone
Sr. GenAI Engineer
Sr. GenAI Engineer

Synechron • Toronto

Hybrid
CAD 130,000 - 145,000
Hybrid work policy
RRSP with employer’s contribution
paid annual leave + personal days
+1
AI Platform Engineer – DevOps
AI Platform Engineer – DevOps

Calitii • Halifax

Hybrid
CAD 90,000 - 100,000
Hybrid policy
RRSP with employer contribution
Udemy for Business
+1
Senior AI/ML Engineer
Senior AI/ML Engineer

Synechron • Montreal (administrative region)

Hybrid
CAD 110,000 - 190,000
Paid annual leave
Personal leave
Insurance plan
+1
Senior Quality Assurance Specialist
Senior Quality Assurance Specialist

Synechron • Toronto

On-site
CAD 85,000 - 120,000
Competitive compensation package
Global footprint with 60 offices
Paid annual leave
+8
AI Platform Engineer – DevOps
AI Platform Engineer – DevOps

Synechron • Halifax

Hybrid
CAD 90,000 - 100,000
Paid annual leave (15 days)
Personal leave (10 days)
Comprehensive health insurance
+3
Senior Automation QA Engineer
Senior Automation QA Engineer

Synechron • Calgary

Hybrid
CAD 100,000 - 120,000
15 days of paid annual leave
Comprehensive insurance plan
RRSP with employer contribution
+2
AI Architect
AI Architect

Synechron • Toronto

Hybrid
CAD 125,000 - 140,000
15 days paid annual leave
Comprehensive insurance plan
Access to over 5000 Udemy courses