Senior Security Developer, Vulnerability Management

Wealthsimple Technologies

Toronto

Hybrid

CAD 120,000 - 180,000

Full time

3 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Health benefits
Hybrid work model
20 vacation days per year

Job summary

Wealthsimple is seeking an experienced vulnerability management engineer to design automations and integrations across our VM platform. You will own deployment, data modeling, and end-to-end automation, enabling triage, remediation, and reporting with minimal manual intervention.

You will work with AWS, CI/CD pipelines, and popular scanners to streamline findings and drive secure software delivery in our hybrid engineering environment.

Qualifications

  • Has 4+ years of hands-on vulnerability management and/or security engineering experience, including scanner integration, triage workflows, and remediation tracking.
  • Has production AWS experience.
  • Has deep familiarity with VM tooling (Tenable, Semgrep, Rapid7, or comparable scanners) and knows how to build integrations on top of them via API.
  • Understands the difference between package and library vulnerabilities and can discuss real-world fixes with developers.
  • Has hands-on familiarity with GitHub Actions, ArgoCD, Kubernetes, AMIs, and container images (ECR or comparable).
  • Is familiar with vulnerability management controls and different compliance programs.

Responsibilities

  • Own and evolve Wealthsimple's VM platform, including deployment, integrations, data model, and automation workflows.
  • Build automation across the VM lifecycle: triage, ticket routing, SLA tracking, ownership resolution, and follow-up.
  • Integrate scanner data into the VM pipeline and maintain enrichment workflows for actionable tickets.
  • Build queries, dashboards, and automated reports for visibility into vulnerability posture.
  • Stay current on the threat landscape and AI's role in vulnerability research and exploitation.
  • Help evolve the workflow so a validated finding can be tested and patched with minimal manual work.

Skills

Automation-first
AWS experience
VM tooling
API integrations
GitHub Actions
ArgoCD
Kubernetes
CI/CD
Vulnerability management

Tools

Tenable
Semgrep
Rapid7
GitHub Actions
ArgoCD
Kubernetes
ECR
AMIs

Job description

Build something people love

Wealthsimple is Canada’s leading financial innovator. The company offers a full suite of simple, sophisticated financial products across managed investing, do-it-yourself trading, cryptocurrency, tax filing, spending and saving. Wealthsimple currently serves more than 4 million Canadians and holds over $155 billion in assets under administration. The company was founded in 2014 by a team of financial experts and technology entrepreneurs, and is headquartered in Toronto, Canada.

We're proud of what we've built — and we're just getting started. Read our Culture Manual and learn more about how we work.

About the Role

Most vulnerability management programs are still built around people manually triaging tickets and chasing down owners. We're taking a different approach: a platform that uses AI-assisted tooling to do a lot of that work for us, and this role is where that gets built. We want you to design the automations, integrations, and workflows that take those fundamentals further: less manual ticket routing, more systems that carry a finding through triage, ownership, and remediation on their own.

The skill set we're after, automation-first thinking, developer-level reasoning, and the ability to build integrations across systems, is what turns a program from manual and reactive into something that runs on its own. That's the job: build the automation and integrations that let our VM tooling handle the load without a person in the loop at every step. We're also building deeper integration with our CRS (Cyber Reasoning System) harness, so a finding can move from triage through automated sandbox validation to a generated fix with less manual handling at each stage.

We use AI-assisted development tools heavily and expect you to use them too.

In this role, you will have the opportunity to:
  • Own and evolve our custom VM platform, working on deployment, integrations, data model, and automation workflows. This is a greenfield opportunity to shape how the platform grows.

  • Build automation across the full VM lifecycle: triage, ticket routing, SLA tracking, ownership resolution, and follow-up. We use Claude Code and Tracecat, and you'll be expected to use and extend both meaningfully.

  • Take a platform built around one team's workflow to one that fits how the rest of engineering actually works. Get it in front of people, bake it into their existing processes, and make it something teams reach for.

  • Integrate scanner data into our VM pipeline and maintain the enrichment workflows that turn raw findings into actionable tickets.

  • Build the queries, dashboards, and automated reports that give the team and leadership clear visibility into vulnerability posture.

  • Stay current on the threat landscape, especially the growing role of AI in vulnerability research and exploitation, and factor that into how we build and prioritize.

  • Help build toward a future where a validated finding gets tested and patched by CRS in a sandbox, and comes back out as a PR, closing the loop with minimal manual work.

We are looking for someone who:
  • Is familiar with the software development lifecycle end to end, well enough to recognize where a vulnerability was actually introduced in the process and to tell when an AI tool is hallucinating a finding instead of catching a real one.

  • Has 4+ years of hands‑on vulnerability management and/or security engineering experience, including scanner integration, triage workflows, and remediation tracking. If vulnerability management isn't explicitly on your resume, you should be able to explain clearly why you understand it anyway.

  • Has production AWS experience.

  • Has a strong automation‑first mindset. You've built things that replace manual processes.

  • Has deep familiarity with VM tooling (Tenable, Semgrep, Rapid7, or comparable scanners) and knows how to build integrations on top of them via API.

  • Understands the difference between package and library vulnerabilities well enough to know where a fix actually belongs, and understands vulnerability classes across application and infrastructure layers (XSS vs. CSRF, code vs. container issues) well enough to have a real conversation with a developer who disagrees with a finding. Knows which scanners belong at which stage of the pipeline (CI, production, network) and how a vulnerability actually ends up running in production, including in containers. Hands‑on exposure to SAST/DAST/SCA tooling and OWASP fundamentals helps here.

  • Has hands‑on familiarity with GitHub Actions, ArgoCD, Kubernetes, AMIs, and container images (ECR or comparable). You'll need this to help maintain our VM platform, and because each of these carries its own patch management burden since they all run code.

  • Understands attack surface and exposure management, including how a basic web app's architecture and traffic flow map to real risk. You'll be making risk acceptance calls, and that requires seeing the actual exposure, not just a CVE score.

  • Can translate business and partner needs into solutions. You'll spend real time with developers who don't understand a finding, disagree with it, or say a fix didn't work, and you need to work through that without losing the thread.

  • Has a strong understanding of the programs vulnerability management connects to: CI/CD and deployment pipelines, threat intelligence, and bug bounty or responsible disclosure programs. VM doesn't operate in a vacuum, and we want someone who understands the connections that exist today and the ones that should exist but don't yet.

  • Is familiar with different compliance programs and vulnerability management controls.

  • Is actively using AI-assisted development workflows (Claude Code, Cursor, Copilot, or similar) and treats them as a force multiplier, not a novelty.

Nice to have:
  • Experience with security orchestration platforms (Tracecat, Tines, XSOAR, or comparable).

  • Experience with bug bounty or responsible disclosure programs like HackerOne.

  • Familiarity with vulnerability scoring and prioritization frameworks (CVSS, EPSS, SSVC). This is quick to pick up on the job, so it's weighted lower than the items above.

  • Experience in a fintech or regulated‑industry environment.

  • Open‑source security tooling contributions.

Why Wealthsimple?

Top-tier health benefits and life insurance

Long-term group savings with employer match, through Wealthsimple for Business

20 vacation days, 4 wellness days, and unlimited sick and mental health days per year

90 days away: work outside Canada for up to 90 days per year

Employee resource groups, including Rainbow (2SLGBTQ), Women of WS, and Black at WS

We are a hybrid team with over 1,500 employees across North America. The people are one of the best parts of working here: you'll collaborate with incredibly talented, curious, and driven teammates who are deeply committed to doing great work.

ICYMI

Technology & Innovation at Wealthsimple: We move quickly and build thoughtfully. That means we're always looking for better ways to work — whether that's new tools, AI, or rethinking how we approach a problem. We don't expect you to have all the answers, but we do expect curiosity and a willingness to evolve alongside the products we're building.

Inclusion Statement: We're building products for a diverse world, and we need a diverse team to do it well. We strongly encourage applications from everyone, regardless of race, religion, colour, national origin, gender, sexual orientation, age, marital status, or disability status.

Accessibility Statement: We're committed to an accessible hiring experience. If you need any accommodations throughout the interview process, please let us know — we'll work with you to make sure you have what you need. We also welcome any feedback on how we can better accommodate candidates with accessibility needs.

AI in Hiring: We may use artificial intelligence (AI) tools to support parts of our hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our team but don't replace human judgment – all final hiring decisions are made by people. If you have questions about how your data is used, reach out to us.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Frontier AI Security Threat Hunter
Frontier AI Security Threat Hunter

Wealthsimple • Canada

On-site
CAD 151,000 - 189,000
Top-tier health benefits and life insurance
20 vacation days and wellness days
90 days work outside Canada per year
Senior Software Developer
Senior Software Developer

Wealthsimple Inc. • Toronto

Hybrid
CAD 120,000 - 190,000
Top-tier health benefits
Unlimited vacation days
Hybrid team with North America reach
Manager, Software Development - Financial Risk
Manager, Software Development - Financial Risk

Portage Ventures GP Inc. • Toronto

Hybrid
CAD 120,000 - 180,000
Health benefits
Employer match for savings
Vacation days
+2
Manager, Software Development - Financial Risk
Manager, Software Development - Financial Risk

Wealthsimple • Toronto

Hybrid
CAD 150,000 - 210,000
Health benefits and life insurance
Employer match savings (Wealthsimple)
Vacation days and wellness time
+3
Senior Software Developer, Delivery Platform
Senior Software Developer, Delivery Platform

Wealthsimple • Toronto

Hybrid
CAD 120,000 - 170,000
Top-tier health benefits
Group savings plan with employer match
Paid vacation days and wellness days
+1
Third Party Security Risk Management Specialist
Third Party Security Risk Management Specialist

Socket.dev • Toronto

Hybrid
CAD 85,000 - 125,000
Health benefits
Life insurance
Employer match savings
+5
Staff Software Engineer, Observability Platform
Staff Software Engineer, Observability Platform

Wealthsimple Technologies • Toronto

Hybrid
CAD 140,000 - 210,000
Health benefits + life insurance
Employer matched savings plan
Vacation & wellness days
+1
Lead, WFM Platform & Automation
Lead, WFM Platform & Automation

Wealthsimple • Toronto

Hybrid
CAD 110,000 - 170,000
Health benefits
Life insurance
Vacation and wellness days
+2
Lead, People Operations - Process Design
Lead, People Operations - Process Design

Wealthsimple Inc. • Canada

Hybrid
CAD 100,000 - 160,000
Health benefits & life insurance
RRSP matching
Vacation + wellness days
+2
Manager Software Development, Observability Platform
Manager Software Development, Observability Platform

Wealthsimple Inc. • Canada

Hybrid
CAD 180,000 - 210,000
Health benefits
Life insurance
Vacation days
+1