Enable job alerts via email!

Senior Product Security Engineer

Wave

Toronto

On-site

CAD 70,000 - 110,000

Full time

30+ days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking a Product Security Engineer to enhance the security of its innovative financial management solutions. In this pivotal role, you will conduct risk assessments, implement secure development practices, and collaborate with cross-functional teams to embed security throughout the product lifecycle. Your expertise will help protect software, hardware, and firmware from vulnerabilities while ensuring compliance with industry standards. Join a company that values diversity, fosters growth, and invests in your health and wellness. If you're passionate about securing products and making a meaningful impact, this is the perfect opportunity for you.

Benefits

Diverse learning experiences
Educational allowances
Health & wellness investments
Flexible work location
Fair compensation
Office perks
Supportive company culture

Qualifications

  • 3+ years of experience in a Product Security role.
  • Strong understanding of security frameworks and compliance standards.
  • Experience with manual source code review and security integration.

Responsibilities

  • Perform threat modeling and vulnerability assessments to identify risks.
  • Implement security tooling and best practices in the SDLC.
  • Monitor security incidents and manage incident response.

Skills

Threat modelling methodologies
Security best practices
Incident response
AWS Services
Python
React
Django Rest Framework
Communication skills
Organizational skills
Time-management abilities

Education

Bachelor’s degree in Computer Science
Bachelor’s degree in Cybersecurity
Related field degree

Tools

Ansible
Terraform
SAST/DAST tools
CI/CD pipeline tools

Job description

We believe small businesses are at the heart of our communities, and championing them is worth fighting for. We empower small business owners to manage their finances fearlessly, by offering the simplest, all-in-one financial management solution they can't live without.

Product Security Engineer is responsible for ensuring the security of an organization’s products throughout their lifecycle. This role focuses on protecting software, hardware, and firmware from vulnerabilities and cyber threats, aligning with business goals and compliance standards. This role also consults with security adjacent stakeholders and business units to provide suggestions, education, guidance and feedback from a security perspective.

Here’s How You Make an Impact:
  • Risk Assessment and Mitigation: Perform threat modelling application design solutions and vulnerability assessments to identify relevant risks, security gaps or risks in product design and development.
  • Secure Development Practices: Implement security tooling and automation to scale the Product Security team’s practices. Advocate for and integrate security best practices in the Software Development Lifecycle (SDLC). Conduct code reviews, penetration testing, and static/dynamic analysis. Ensure compliance with industry standards (e.g., AICPA SOC2, HIPAA, PCI DSS, SOX ISO 27001, NIST CSF).
  • Incident Response and Management: Monitor and address security incidents impacting Wave products. Implement and manage SOAR solutions to improve incident response times and efficiency.
  • Security Architecture and Development: Working with product and engineering teams to design, program development, software development and implement security controls and protections within the product via automation. This task ensures the product is built with security in mind from the ground up. Integrate security tools and technologies into the CI/CD pipeline (e.g., static and dynamic application security testing (SAST/DAST), software composition analysis (SCA), and infrastructure-as-code (IaC) scanning).
  • Planning, Collaboration and Training: Product roadmap planning with key stakeholders, collaboration with cross functional teams to develop mitigation strategies. Working closely and mentor Product, Engineering, and IT teams for security best practices. Provide security training and awareness for developers and stakeholders.
  • Compliance and Reporting: Maintain documentation of security controls and processes. Prepare reports on security risks and mitigation efforts for management and regulatory bodies. Audit source code and perform code review for critical application changes.
You Thrive Here By Possessing the Following:
  • 3+ years of experience in a Product Security role.
  • Bachelor’s degree in Computer Science, Cybersecurity, or a related field.
  • Experience leading architectural changes or complex cross team efforts to mitigate security vulnerabilities.
  • Strong understanding of Threat modelling methodologies such as MITRE ATT&CK, STRIDE, and PASTA;
  • Amazon AWS Services, MS Azure and their capabilities; Securing web applications; Orchestration tools (ex. Ansible, Terraform).
  • Experience with frameworks such as OWASP Top 10, SAST/DAST tools, and CI/CD pipelines.
  • Fluency in Python, React, and Django Rest Framework.
  • Experience with manual source code review, and embedding security to code in production environments.
  • Experience with deploying application security tools in the CI/CD pipeline.
  • Experience with securing software development lifecycle including building programs that eliminate full classes of vulnerabilities.
  • Excellent communication and interpersonal skills.
  • Ability to work independently and within a team.
  • Strong organizational and time-management abilities.
Preferred Qualifications:
  • Certifications such as CISSP, CSSLP, CEH, or equivalent.
  • Experience in IoT, embedded systems, or mobile app security.
  • Knowledge of regulatory and compliance standards (e.g., AICPA SOC2, NIST CSF, GDPR, HIPAA).

At Wave, you’re treated like the incredible human being you are.

Work From Where You Work Best: We will always have a welcoming, energizing, and world-class office (in Toronto) with a space for you. Or, if you’re more comfortable working from home, the choice is yours.

We Care About Future You: You will stretch yourself and you will grow at Wave. You will also be supported on this journey with diverse learning experiences, educational allowances, mentorship, and so much more.

We Support the Full You: We make a serious investment in your health & wellness. When we think about benefits we think about body, mind, & soul and we take this stuff very seriously.

We Take Care of the Fundamentals: Fair compensation, all the office perks you’d want, and the various goodies you’d expect from a growing tech company. This is the obvious stuff, but we don’t want you to think we forgot!

We believe that a diverse and inclusive culture creates the best workplace. We embrace our differences, value individuality, and the broad spectrum of every Waver's skills and abilities. We challenge each other from a place of respect and pursuit of continuous growth. We trust each other and encourage everyone to bring their authentic selves to work, every day. As Wavers, our voices matter, our opinions are met with an open mind. The best ideas win, no matter whose they are. Contributing to an inclusive culture is a part of all of our job descriptions.

We’ve been continuously recognized as one of Canada's Top Ten Most Admired Corporate Cultures and one of Canada’s Great Places to Work in categories including Technology, Millennials, Mental Health, Inclusion and Women.

Are you ready to be a Waver? Join us!

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Network Security Engineer

Carrier Refrigeration

Greater Toronto Area

Remote

CAD 80,000 - 120,000

4 days ago
Be an early applicant

Senior Network Security Engineer

Carrier

Ontario

Remote

CAD 80,000 - 120,000

4 days ago
Be an early applicant

Senior Network Security Engineer

Carrier

Ontario

Remote

CAD 80,000 - 120,000

6 days ago
Be an early applicant

Senior Software Security Engineer

Cohere

Toronto

Remote

CAD 80,000 - 130,000

30+ days ago

Cloud Security Engineer, Deloitte Global Technology

Deloitte Canada

Toronto

Remote

CAD 69,000 - 114,000

14 days ago

Senior Security Engineer

Shakepay

Remote

CAD 80,000 - 120,000

8 days ago

Senior Security Engineer, Detection & Response

Docker, Inc

Remote

CAD 80,000 - 120,000

9 days ago

Senior Security Engineer, Detection & Response (Canada, Mexico, United States)

Jobgether

Remote

CAD 80,000 - 120,000

8 days ago

Senior Security Engineer

Fundserv Inc.

Toronto

Hybrid

CAD 80,000 - 120,000

2 days ago
Be an early applicant