Senior Cloud & App Security Engineer

FORMA.AI

Toronto

On-site

CAD 160,000 - 190,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Forma.ai is seeking a Senior Security Engineer in Toronto or remote Canada to strengthen security across the cloud, applications, and data. You’ll work with Engineering, DevOps, IT, and Legal to design controls, automate security processes, and ship secure software.

The role offers growth into senior IC or security leadership, with strong emphasis on threat modelling, IAM, and secure SDLC practices. Competitive salary and benefits. This position is a full-time role in a fast-growing startup.

Qualifications

  • Six or more years of experience in security engineering, cloud security, application security, DevSecOps, or infrastructure engineering.
  • Strong hands-on experience securing AWS environments, including IAM, networking, encryption, logging, and secrets management.
  • Experience with Terraform, Kubernetes, containers, and security controls in CI/CD pipelines.
  • Strong understanding of application and API security, authentication, authorization, and multi-tenant SaaS risks.
  • Experience with vulnerability management, threat modelling, incident response, and security automation.
  • Ability to write scripts using Python, Bash, PowerShell, or a similar language.
  • Strong communication, troubleshooting, and cross-functional collaboration skills.

Responsibilities

  • Design and implement security controls across Forma's AWS environments, with a focus on IAM, least-privilege access, service identities, and account boundaries.
  • Embed security requirements into Terraform and other Infrastructure as Code, and improve secrets, certificate, encryption-key, and credential management.
  • Build automated checks for insecure configurations, excessive permissions, exposed resources, and configuration drift across Kubernetes, containers, serverless workloads, networking, and data services.
  • Run threat modelling and security architecture reviews for new products, services, APIs, data pipelines, and third-party integrations.
  • Strengthen tenant isolation, authorization enforcement, and fine-grained data access controls at the schema, table, row, and column level.
  • Help protect sensitive compensation, financial, customer, and employee data across databases, data warehouses, S3, analytics services, and internal tools, including logging and auditability for sensitive-data access.
  • Review AI and agentic workflows for data leakage, prompt injection, insecure tool use, and excessive permissions; ensure agents operate strictly within the calling user's permissions; and define secure patterns for approved services such as Amazon Bedrock.
  • Identify and help remediate application vulnerabilities, and build tooling and reusable libraries that make the secure path the easy one for engineers.
  • Embed security testing into CI/CD — static analysis, dependency and container scanning, secrets detection, Infrastructure as Code scanning, and dynamic testing — without creating unnecessary friction for developers.
  • Define practical vulnerability-severity, remediation, exception, and escalation standards, and partner with developers to separate real risk from noise and fix root causes.
  • Improve software supply-chain security, including build permissions, artifact integrity, dependency governance, and GitHub administration.
  • Improve security visibility across cloud infrastructure, applications, identities, endpoints, and SaaS systems, and build alerts and detection logic that are worth acting on.
  • Lead investigations and coordinate containment, remediation, and root-cause analysis, supported by clear runbooks, ownership, and escalation paths.
  • Run tabletop exercises, and track and communicate security metrics and material risks to technical and business stakeholders.
  • Strengthen SSO, MFA, privileged access, and onboarding, offboarding, and access-review processes across AWS, GitHub, Microsoft 365, Entra ID, production systems, and internal SaaS — automating provisioning, entitlement reviews, and evidence collection where practical.
  • Translate security and compliance requirements into concrete technical controls, and support customer security reviews, audits, and programs such as SOC 2 and ISO 27001.
  • Evaluate third-party tools and integrations for security, privacy, and access-control risk, and help select, consolidate, and rationalize Forma's security tooling for both coverage and cost.
  • Maintain clear technical standards and provide practical guidance, training, and mentorship that raises security capability across Engineering.

Skills

Security engineering
Cloud security
Application security
DevSecOps
Infrastructure engineering

Tools

Terraform
Kubernetes
CI/CD pipelines

Job description

Forma.ai is seeking a Senior Security Engineer in Toronto or remote Canada to strengthen security across the cloud, applications, and data. You’ll work with Engineering, DevOps, IT, and Legal to design controls, automate security processes, and ship secure software.

The role offers growth into senior IC or security leadership, with strong emphasis on threat modelling, IAM, and secure SDLC practices. Competitive salary and benefits. This position is a full-time role in a fast-growing startup.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer — Secure SaaS Growth
Senior Cloud Security Engineer — Secure SaaS Growth

Forma AI Inc. • Toronto

On-site
CAD 160,000 - 190,000
Stock options (employee equity)
Healthcare coverage
$750 yearly training stipend
+1
Senior Security Engineer
Senior Security Engineer

Socket.dev • Toronto

On-site
CAD 110,000 - 150,000
Senior Security Engineer — Cloud & App Security (Canada)
Senior Security Engineer — Cloud & App Security (Canada)

Magnet Forensics • Canada

On-site
CAD 111,000 - 191,000
Senior Cloud & App Security Architect
Senior Cloud & App Security Architect

Triwill Group • Canada

On-site
CAD 120,000 - 180,000
Senior Security Engineer - AI-Driven Cloud Defense
Senior Security Engineer - AI-Driven Cloud Defense

Docebo • Toronto

Hybrid
CAD 100,000 - 130,000
Senior Security Engineer Toronto, Canada
Senior Security Engineer Toronto, Canada

Forma AI Inc. • Toronto

On-site
CAD 160,000 - 190,000
Stock options (employee equity)
Healthcare coverage
$750 yearly training stipend
+1
Cloud Security Solution Architect for AI & Multi-Cloud
Cloud Security Solution Architect for AI & Multi-Cloud

Fortinet • Toronto

On-site
CAD 247,000 - 304,000
Senior Software Engineer, AI Security & DevSecOps
Senior Software Engineer, AI Security & DevSecOps

Cohere • Toronto

Hybrid
CAD 100,000 - 130,000
Open and inclusive culture
Weekly lunch stipend
Full health and dental benefits
+4
Senior DevSecOps Security Engineer
Senior DevSecOps Security Engineer

Compunnel, Inc. • Toronto

On-site
CAD 90,000 - 120,000
Cloud Security Engineer – DevSecOps & AWS Expertise
Cloud Security Engineer – DevSecOps & AWS Expertise

Aquanow • Toronto

On-site
CAD 100,000 - 130,000