
Enable job alerts via email!
Generate a tailored resume in minutes
Land an interview and earn more. Learn more
A leading enterprise management software provider in Canada is seeking a Security Engineer to co-own the DevSecOps program, ensuring robust security measures. This role involves leading security automation, managing compliance with PCI DSS, and implementing cloud security strategies on AWS. The ideal candidate will have 8–10 years of experience in application/cloud security, with a strong emphasis on DevSecOps practices. Applicants should be familiar with Veracode and Terraform for AWS systems. Competitive salary and benefits offered.
Security Engineer
Compensation: The expected salary range for this role is between $135,000 and $150,000, depending on experience and qualifications.
Reason for Opening: Net New position
AI is not used to screen, assess, or select applicants for this role.
Constellation Payment Processing is a modern Payment Facilitator (PayFac) empowering SaaS businesses to grow revenue through seamless, embedded payments. As part of Constellation Software Inc. (TSE:CSU) — a global Canadian-based software leader at a $96B market cap and the 7th largest software company in the world — we combine the agility of a specialized payments company with the strength and stability of an established global powerhouse.
We are building a cloud-native PayFac platform on AWS: microservices (DDD) across TypeScript/JavaScript, Java, and Ruby, with a ReactJS front end. As our Security Engineer, you will co‑own the DevSecOps program—driving continuous security automation, compliance automation, and penetration testing. You will design and orchestrate SAST/SCA/DAST across our services, champion remediation practices, and partner closely with our compliance team to translate control objectives into repeatable, automated evidence.
Our customers are ISV vendors who embed payments by integrating with our APIs, SDKs, and webhooks. That means security and compliance aren’t afterthoughts—they are product features. You will ensure our developer‑facing surface area is secure by default: establishing standards for authentication and authorization (OIDC/OAuth2/JWT, mTLS/JWS for webhooks), key and secret management, request signing, idempotency, rate‑limiting/abuse controls, and secure data handling that minimizes PCI scope for ISVs (tokenization, hosted fields/iframes, PAN vault boundaries, network tokens).
You will create secure integration patterns (reference apps, checklists, threat models/DFDs) so partners can implement quickly without compromising controls. Because we operate a multi‑tenant PayFac, you will harden isolation boundaries (network, identity, and data), lead supply‑chain security (SBOMs, signing/provenance, gated deployments), and build continuous evidence for PCI DSS 4.0 (and SOC 2/ISO as needed).
You will collaborate with partner security and compliance teams on due‑diligence requests (SIG Lite, AOC/ROCs, shared‑responsibility matrices), and you will own pre‑launch security reviews for new ISV integrations. You will also help run incident response drills and define partner‑facing comms and SLAs for security events.
Finally, you will research and implement AI‑assisted security (triage, anomaly detection, auto‑remediation PRs) with appropriate guardrails, and own KPIs that demonstrate multiplier effects—e.g., reduced MTTR, lower false‑positive rates, higher auto‑triage coverage, and faster time‑to‑evidence—so our platform’s security posture continuously improves as our ISV ecosystem scales.
This role sits in the CTO organization (Engineering/Platform) and partners daily with compliance, DevOps/SRE, Backend/Frontend teams, and Product.
AWS (EKS, ECR, KMS, CloudHSM, WAF/Shield, CloudFront, GuardDuty, Security Hub, CloudWatch), GitHub/GitHub Actions, Terraform, Node/TypeScript, Java, Ruby, React, Kafka, MongoDB, Postgres, Redis, Veracode, OWASP ZAP/Burp, AI Tools in Microsoft Teams, JIRA, Development IDEs (Amazon Q, Cursor, Claude Code)
Jonas Software is the leading provider of enterprise management software solutions to the Country and Golf Clubs, Foodservice, Construction, Fitness & Sports, Attractions, Salon & Spa, Education, Radiology/Laboratory Information Systems, and Product Licensing industries. Within these vertical markets, Jonas is made up of over 65 distinct brands, which are respected and leaders within their own domain.
Jonas’ vision is to be the branded global leader across the aforementioned vertical markets and to be recognized by customers and respective industry stakeholders as the trusted provider of ‘Software for Life’ and as an ambassador for technology, product innovation, quality, and customer service.
Jonas Software is the valued technology partner of over 60,000 customers worldwide in more than 30 countries. Jonas employs over 2,000 skilled individuals consisting of a cross‑section of industry experts and technology professionals. Jonas is headquartered in Canada and also operates offices throughout North America, the United Kingdom, Europe, Australia New Zealand and Africa. Jonas is a 100% owned subsidiary of Constellation Software Inc., headquartered in Toronto and traded on the S&P/TSX 60.