Product Security Engineer

Movable Ink

Toronto

On-site

CAD 133,000 - 173,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Full range of medical benefits
Financial benefits
Bonus eligibility

Job summary

Movable Ink is seeking a Product Security Engineer based in Toronto, Ontario, to enhance the security of their codebases and CI/CD practices. The role involves maintaining security testing, managing vulnerabilities, and collaborating with engineering teams. Ideal candidates should have over 2 years of experience in application security or related fields. A competitive salary range of $133,000-$173,000 CAD per year is offered along with comprehensive benefits including bonuses.

Qualifications

  • 2+ years of experience in application security, DevSecOps, or a security-focused software engineering role.
  • Hands-on experience with SAST, SCA, or secrets scanning tools (Semgrep, Dependabot, Snyk, or similar).
  • Familiarity with CI/CD pipelines and GitHub Actions.
  • Understanding of common web application vulnerabilities (OWASP Top 10) and how to detect/prevent them.
  • Experience reading and reviewing code in at least one language (Ruby, Python, JavaScript, or Go preferred).
  • Comfortable navigating codebases and working with engineering teams to explain and prioritize security findings.
  • Strong written communication skills for documentation and customer-facing security responses.
  • Self-motivated and able to manage competing priorities in a fast-paced environment.

Responsibilities

  • Implement and maintain static application security testing (SAST) using Semgrep across our repositories.
  • Configure and improve software composition analysis (SCA) tooling (Dependabot) to identify vulnerable dependencies.
  • Manage secrets detection scanning (Trufflehog) and respond to findings.
  • Integrate security scanning into CI/CD pipelines (GitHub Actions) to catch issues before code is merged.
  • Triage and prioritize vulnerability findings, working with engineering teams to drive remediation.
  • Support dynamic application security testing (DAST) efforts using tools like ZAP.
  • Contribute to our Application Security Posture Management (ASPM) platform to centralize findings and track remediation.
  • Set up and configure automation scripts to support our vulnerability management practices.
  • Document secure coding guidelines and help educate developers on security best practices.
  • Evaluate and recommend new security tools as the landscape evolves.

Job description

Movable Ink scales content personalization for marketers through data-activated content generation and AI decisioning. The world’s most innovative brands rely on Movable Ink to maximize revenue, simplify workflow and boost marketing agility. Headquartered in New York City with close to 600 employees, Movable Ink serves its global client base with operations throughout North America, Central America, Europe, Australia, and Japan.

Movable Ink is hiring a Product Security Engineer to help secure our codebases, CI/CD pipelines, and development practices. To succeed in this role, you'll balance a security-first mindset with a practical understanding of how engineering teams ship software: finding ways to reduce risk without slowing down delivery. This is a hands‑on opportunity to build and improve the automation that keeps our code and infrastructure safe, working closely with both the Security and Engineering teams. As AI coding tools and supply chain attacks increase risk across the industry, this role is critical to staying ahead of vulnerabilities before they reach production.

Responsibilities
  • Implement and maintain static application security testing (SAST) using Semgrep across our repositories
  • Configure and improve software composition analysis (SCA) tooling (Dependabot) to identify vulnerable dependencies
  • Manage secrets detection scanning (Trufflehog) and respond to findings
  • Integrate security scanning into CI/CD pipelines (GitHub Actions) to catch issues before code is merged
  • Triage and prioritize vulnerability findings, working with engineering teams to drive remediation
  • Support dynamic application security testing (DAST) efforts using tools like ZAP
  • Contribute to our Application Security Posture Management (ASPM) platform to centralize findings and track remediation
  • Set up and configure automation scripts to support our vulnerability management practices
  • Document secure coding guidelines and help educate developers on security best practices
  • Evaluate and recommend new security tools as the landscape evolves
Qualifications
  • 2+ years of experience in application security, DevSecOps, or a security-focused software engineering role
  • Hands‑on experience with SAST, SCA, or secrets scanning tools (Semgrep, Dependabot, Snyk, or similar)
  • Familiarity with CI/CD pipelines and GitHub Actions
  • Understanding of common web application vulnerabilities (OWASP Top 10) and how to detect/prevent them
  • Experience reading and reviewing code in at least one language (Ruby, Python, JavaScript, or Go preferred)
  • Comfortable navigating codebases and working with engineering teams to explain and prioritize security findings
  • Strong written communication skills for documentation and customer-facing security responses
  • Self‑motivated and able to manage competing priorities in a fast‑paced environment

The base pay range for this position is $133,000-$173,000 CAD/year, which can include additional bonus depending on the position ultimately offered, in addition to a full range of medical, financial, and/or other benefits. The base pay offered may vary depending on job-related knowledge, skills, and experience.

Studies have shown that women, communities of color, and historically underrepresented people are less likely to apply to jobs unless they meet every single qualification. We are committed to building a diverse and inclusive culture where all Inkers can thrive. If you’re excited about the role but don’t meet all of the abovementioned qualifications, we encourage you to apply. Our differences bring a breadth of knowledge and perspectives that makes us collectively stronger.

We welcome and employ people regardless of race, color, gender identity or expression, religion, genetic information, parental or pregnancy status, national origin, sexual orientation, age, citizenship, marital status, ethnicity, family or marital status, physical and mental ability, political affiliation, disability, Veteran status, or other protected characteristics. We are proud to be an equal opportunity employer.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Backend Engineer, Behavioural Team
Senior Backend Engineer, Behavioural Team

Movable Ink • Toronto

On-site
CAD 140,000 - 180,000
Full range of medical benefits
Financial benefits
Additional bonuses
Senior Full Stack Engineer, Designer Team
Senior Full Stack Engineer, Designer Team

Movable Ink • Toronto

On-site
CAD 180,000 - 253,000
Senior Backend Engineer, Analytics
Senior Backend Engineer, Analytics

Movable Ink • Toronto

On-site
CAD 140,000 - 180,000
Medical benefits
Financial benefits
Bonus potential
Senior Machine Learning Engineer
Senior Machine Learning Engineer

Doist • Toronto

Hybrid
CAD 140,000 - 180,000
Lead Backend Developer
Lead Backend Developer

Movable Ink • Toronto

On-site
CAD 207,000 - 271,000
Senior Backend Developer, Campaigns Team
Senior Backend Developer, Campaigns Team

Doist • Toronto

On-site
CAD 197,000 - 254,000
Software Developer Specialist - Security Product
Software Developer Specialist - Security Product

Intact • Toronto

Hybrid
CAD 118,000 - 146,000
Annual bonus target up to 15%
Employee Share Purchase Plan
Pension plan with guaranteed income
+1
Staff Product Marketing Manager – Security
Staff Product Marketing Manager – Security

United States Digital Space LLC • Denver

Hybrid
CAD 231,000 - 326,000
Medical insurance
Dental insurance
Vision insurance
+1
Staff Software Engineer - Device Identity
Staff Software Engineer - Device Identity

United States Digital Space LLC • Toronto

On-site
CAD 160,000 - 220,000
Health insurance
Dental insurance
Vision insurance
+3
Staff, Security Engineer
Staff, Security Engineer

Fullscript • Toronto

Remote
CAD 150,000 - 210,000
Remote-first flexibility
North America location preference
Competitive pay
+4