Senior Product Security Engineer

BeyondTrust, Inc.

Ottawa

On-site

CAD 120,000 - 180,000

Full time

2 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

BeyondTrust, Inc. is seeking a Senior Product Security Engineer to build and operate the modern security tooling pipeline supporting our Product Security team.

You will automate reviews with AI-powered tooling (Claude Code Security, Codex Security, GitHub Advanced Security) and integrate them into CI/CD, providing fast, reliable security feedback at every commit, PR, and release. You’ll partner with engineers, security testers, architects, and TPMs to design scalable processes and assist

Qualifications

  • 4+ years in Application Security, Product Security, DevSecOps, or Security Engineering with hands-on experience building and operating security tooling in CI/CD pipelines.
  • Hands-on experience with AI-powered security tooling such as Claude Code Security, Codex Security, or similar LLM-based code analysis platforms.
  • Experience implementing and tuning SAST, DAST, SCA, and secret scanning tools in GitHub-integrated environments (GitHub Advanced Security, CodeQL, Dependabot, or equivalent).
  • Automation-first mindset. You default to building repeatable, scalable workflows and reach for manual processes only when automation genuinely falls short.
  • Strong understanding of CI/CD pipeline architecture and how security controls integrate without disrupting developer velocity.
  • Experience building automation workflows: scripting, pipeline configuration, policy-as-code, webhook integrations, and workflow orchestration.
  • Familiarity with container security scanning tools (Wiz CLI, Trivy, Snyk Container, or equivalent) and cloud security fundamentals (AWS preferred).
  • Strong collaboration skills. You’ll work across Security Testers, Architects, TPM, and engineering teams daily and need to communicate effectively with all of them.
  • Experience with GitHub Advanced Security at scale: CodeQL custom queries, secret scanning custom patterns, and organization-wide rollout.
  • Experience supporting product incident response or security incident investigation.
  • Background operating Wiz CLI or similar cloud/container security scanning integrated into CI/CD
  • Background in securing endpoint technologies, identity systems, or enterprise security platforms
  • Familiarity with policy-as-code frameworks (OPA/Rego, Kyverno, or similar)
  • Experience building developer enablement programs, security documentation, or self-service security tooling
  • Cloud security experience across AWS, Azure, or Kubernetes environments

Responsibilities

  • Build and maintain the product security tooling pipeline integrated across the software development lifecycle.
  • Implement and tune Claude Code Security, Codex Security, GitHub Advanced Security (code scanning, secret scanning, Dependabot) and Wiz CLI across repositories and CI/CD pipelines.
  • Own the configuration, policy enforcement, and continuous improvement of these tools so engineering teams get accurate, actionable security feedback at the speed of development.
  • Design automated product security reviews with human-in-the-loop checkpoints, escalating to senior engineers for tougher judgments.
  • Ensure security tooling integrates cleanly into engineering workflows: PRs, CI/CD, IDE plugins, and developer dashboards.
  • Reduce false positives, tune rulesets to the product’s risk profile, and build feedback loops for continual improvement.
  • Be the go-to person for engineering teams on security tooling questions, configuration, and troubleshooting.
  • Collaborate with Security Testers, Architects, TPM, and engineering teams across the portfolio; support incident response when needed.

Skills

Automation-first mindset
Collaboration across teams
Security tooling expertise
CI/CD pipeline experience
LLM/AI-powered tooling

Tools

Claude Code Security
Codex Security
GitHub Advanced Security
Wiz CLI
CodeQL
Dependabot
Trivy
Snyk Container

Job description

  • We’re hiring a Senior Product Security Engineer to build and operate the modern security tooling pipeline that underpins everything our Product Security team does
  • You’ll establish and maintain the SDLC security infrastructure using Claude Code Security, Codex Security, GitHub Advanced Security, Wiz CLI, and integrated tooling that gives engineering teams fast, reliable security feedback on every commit, every PR, and every release
  • You bring an automation-first mindset
  • When you see a manual security review process, your instinct is to build a workflow that handles the repeatable parts and surfaces only the decisions that need a human
  • You’ll design and operate product security reviews with human-in-the-loop checkpoints, ensuring coverage scales with the engineering organization without becoming a bottleneck
  • You’ll be a trusted partner to engineers
  • That means your tooling works reliably, your findings are accurate, your integrations respect their workflow, and when something breaks or creates noise, you fix it fast
  • You’ll partner closely with Security Testers, Architects, the TPM, and engineering teams across the product portfolio
  • You’ll also support product incident response when security issues arise, working alongside the broader Product Security team to investigate, scope, and remediate
  • SDLC Security Pipeline: Build and maintain the product security tooling pipeline integrated across the software development lifecycle. Implement and tune Claude Code Security, Codex Security, GitHub Advanced Security (code scanning, secret scanning, Dependabot), and Wiz CLI across repositories and CI/CD pipelines. Own the configuration, policy enforcement, and continuous improvement of these tools so engineering teams get accurate, actionable security feedback at the speed of development
  • Automated Security Reviews Design: and operate automated product security review workflows with human-in-the-loop checkpoints. Use Claude and LLM platforms to automate initial review triage, risk classification, and recommendation generation, escalating to Security Architects or senior engineers for decisions that require judgment. The goal is every change gets appropriate security review coverage without manual review becoming the bottleneck
  • Tooling Integration & Engineering Experience: Ensure security tooling integrates cleanly into engineering workflows: GitHub PRs, CI/CD pipelines, IDE plugins, and developer dashboards. Reduce false positives, tune rulesets to the product’s actual risk profile, and build feedback loops so findings improve over time. You own the engineering experience of security tooling. When a developer interacts with a security gate, it should be clear, fast, and useful
  • AI-First Automation: Leverage Claude Code Security, Codex Security, and LLM platforms to build automation that scales security engineering. This includes automated code review triage, vulnerability pattern detection, fix suggestion generation, policy-as-code enforcement, and security review summarization. Contribute reusable prompts, skills, and plugins back to the Product Security team’s shared library
  • Product Incident Response Support: Support product incident response alongside the Product Security team. Help investigate security incidents affecting products, scope impact, coordinate with engineering on emergency fixes, and contribute to root cause analysis and post-incident improvements
  • Cross-Team Partnership: Work closely with Security Testers to ensure scanning and automated tooling feed validated findings into their workflow. Partner with Architects on translating secure design standards into enforceable pipeline policies. Coordinate with the TPM on tracking and reporting for tooling-generated findings. Be the go-to person for engineering teams on security tooling questions, configuration, and troubleshooting
  • How We’ll Measure Success:
  • Security tooling coverage across repositories and pipelines is comprehensive and consistently maintained
  • Automated security review workflows handle the majority of reviews with human-in-the-loop escalation for high-risk changes
  • False positive rates decrease over time through tuning and feedback loops you build
  • Engineering teams experience security tooling as fast, accurate, and integrated into their existing workflow
  • Reusable automation, prompts, and plugins you build are adopted across the Product Security team
  • You’re the person engineering teams reach out to for security tooling support because they trust your responsiveness and expertise
  • 4+ years in Application Security, Product Security, DevSecOps, or Security Engineering with hands-on experience building and operating security tooling in CI/CD pipelines
  • Hands-on experience with AI-powered security tooling such as Claude Code Security, Codex Security, or similar LLM-based code analysis platforms
  • You understand common vulnerability classes well enough to tune tooling, triage findings, and have credible conversations with engineers about severity and remediation
  • Automation-first mindset. You default to building repeatable, scalable workflows and reach for manual processes only when automation genuinely falls short
  • Experience implementing and tuning SAST, DAST, SCA, and secret scanning tools in GitHub-integrated environments (GitHub Advanced Security, CodeQL, Dependabot, or equivalent)
  • Strong understanding of CI/CD pipeline architecture and how security controls integrate without disrupting developer velocity
  • Experience building automation workflows: scripting, pipeline configuration, policy-as-code, webhook integrations, and workflow orchestration
  • Familiarity with container security scanning tools (Wiz CLI, Trivy, Snyk Container, or equivalent) and cloud security fundamentals (AWS preferred)
  • Strong collaboration skills. You’ll work across Security Testers, Architects, TPM, and engineering teams daily and need to communicate effectively with all of them
  • Experience with GitHub Advanced Security at scale: CodeQL custom queries, secret scanning custom patterns, and organization-wide rollout
  • Experience supporting product incident response or security incident investigation
  • Background operating Wiz CLI or similar cloud/container security scanning integrated into CI/CD
  • Background in securing endpoint technologies, identity systems, or enterprise security platforms
  • Familiarity with policy-as-code frameworks (OPA/Rego, Kyverno, or similar)
  • Experience building developer enablement programs, security documentation, or self-service security tooling
  • Cloud security experience across AWS, Azure, or Kubernetes environments
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Senior Software Engineer (Security)
Senior Software Engineer (Security)

Super • Toronto

On-site
CAD 90,000 - 120,000
Competitive salary
Learning & development allowance
Generous equity options
+2
Security Architect
Security Architect

Ateko, backed by Bell Canada • Montreal (administrative region)

On-site
CAD 120,000 - 160,000
Senior Software Security Engineer
Senior Software Security Engineer

TimePlay • Toronto

On-site
CAD 120,000 - 180,000
Staff Security Engineer (Enterprise AI)
Staff Security Engineer (Enterprise AI)

Affirm • Ottawa

Remote
CAD 120,000 - 180,000
Remote-first pay
Spending wallets
Supportive communities
+7
Product Security Manager
Product Security Manager

The Token Playbook • Canada

On-site
CAD 120,000 - 180,000
Application Security Engineer
Application Security Engineer

Segment (Twilio) • Toronto

On-site
CAD 100,000 - 130,000
Developer
Developer

CoFoMo Inc. • Lévis

On-site
CAD 120,000 - 150,000
Senior Security Operations Engineer (1 Yr Fixed Term)
Senior Security Operations Engineer (1 Yr Fixed Term)

League • Toronto

On-site
CAD 120,000 - 160,000
Senior Security Engineer
Senior Security Engineer

Metrics Recruitment • Vancouver

On-site
CAD 90,000 - 130,000
Security Engineer
Security Engineer

Relay • Toronto

Hybrid
CAD 70,000 - 120,000
Equity
Social events
Mentorship
+7