Senior Security Engineer New Remote - Canada

Roofr

Canada

Hybrid

CAD 120,000 - 180,000

Full time

3 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Benefits offered by this job

1st week PTO
Friday off per month
Company shutdown for holidays
Flexible time off
Benefits in US & Canada
Parental Leave
Learning & development
Home office stipend
Internet & phone allowance
Remote first culture
Weekly paydays

Job summary

Roofr is seeking a Senior Security Engineer to fortify security posture as the company scales. You will own detection, response, and secure-by-design practices across cloud environments and collaborate with leaders to drive secure outcomes.

You’ll lead vulnerability management, incident response, and compliance efforts while shaping security policies and living controls. This is a hands-on, critical role in a security guild with broad impact.

Qualifications

  • Bachelor’s degree in computer science, IT, cybersecurity, or equivalent hands-on experience.
  • 5-8+ years in security engineering, incident response, or related infrastructure roles, including time as the primary or senior responder on real incidents.
  • Certifications are a strong plus — CISSP, OSCP, GCIH, or CEH.

Responsibilities

  • Own design and hardening of security infrastructure across cloud environments — network segmentation, firewalls, IDS/IPS, VPNs, WAF, and EDR.
  • Lead vulnerability management end to end: run assessments, triage by exploitability, and drive remediation SLAs with engineering.
  • Build and tune detection content (SIEM/SOAR rules, alerting logic) against real attack techniques.
  • Act as incident commander for security incidents: contain, eradicate, forensics, and post-incident reviews.
  • Threat-model new features and infrastructure changes before they ship; catch design-level risk.

Skills

Incident response
Threat modeling
Cloud security
Security engineering
Communication
IAM security

Education

Bachelor’s degree in CS/IT/cybersecurity

Tools

SIEM/SOAR
Python/Bash
AWS IAM/VPC/KMS
CloudTrail/GuardDuty

Job description

At Roofr, we’re obsessed with our customers. We constantly gather feedback to shape, prioritize, and launch the products they truly need. That’s what makes Roofr’s CRM special. We started by building essential sales tools like aerial roof measurements and digital sales proposals. But when our customers asked for a simple, affordable way to manage and scale their entire businesses, we listened. So, we created a CRM that connects these solutions—along with payments, material ordering, and more—into a seamless, powerful platform. With a clear roadmap ahead, we’re excited to continue expanding and leading the market with innovative products.

We have an amazing culture, strong financials, and best-in-class company metrics. It’s an exciting time to be part of an extraordinary startup that is already successful, yet still early enough to offer its team significant growth, equity, and the opportunity to make a real impact.

This position is for an existing vacancy.

As Senior Security Engineer, you'll report to the VP of Engineering and work closely with the CTO and DevOps as part of Roofr's security guild. You'll contribute directly to improving Roofr's security posture — sharpening what's already in place and driving it forward as the company scales. You'll own the tools and processes that detect and stop threats, partner with engineering on secure-by-design practices, and act as the front-line responder when something goes wrong.

What You’ll Get to Do
  • Own design and hardening of security infrastructure across cloud environments - network segmentation, firewalls, IDS/IPS, VPNs, WAF, and endpoint detection and response (EDR)
  • Lead vulnerability management end to end: run assessments and authenticated scans, triage and prioritize by exploitability and blast radius, and drive remediation SLAs with engineering
  • Build and tune detection content (SIEM/SOAR rules, alerting logic) against real attack techniques - not just default vendor signatures
  • Act as incident commander for security incidents: contain, eradicate, run forensics, and write the post-incident review
  • Threat-model new features and infrastructure changes before they ship - catch design-level risk, not just implementation bugs
  • Own IAM hygiene and cloud security posture (least privilege, key/secret management, network boundaries) across production AWS accounts
  • Write, enforce, and maintain security policies and standards - own them as living controls, not documents that sit in a drive
  • Own Roofr's compliance program end to end: map controls to NIST CSF 2.0, SOC 2, and CCPA/CPRA, run the audits, close the gaps, and keep evidence current between them
  • Run tabletop exercises and incident playbook drills
  • Push secure-by-design practices into engineering workflows - threat modeling in design review, security requirements in the SDLC, not a gate bolted on at the end
What You’ll Bring to the Role
Qualifications
  • Bachelor's degree in computer science, IT, cybersecurity, or equivalent hands-on experience
  • 5-8+ years in security engineering, incident response, or related infrastructure roles, including time as the primary or senior responder on real incidents
  • Certifications are a strong plus — CISSP, OSCP, GCIH, or CEH
Technical
  • Deep network security fundamentals - firewalls, VPNs, routing/segmentation, network boundaries, TLS, DNS, and how attackers actually abuse them
  • Hands-on cloud security in AWS - IAM policy design, VPC architecture, KMS/secrets management, CloudTrail/GuardDuty or equivalent
  • Real incident response experience - triage, containment, forensics, root cause, not just theory from a course
  • Working knowledge of SIEM/SOAR tooling, writing detection logic (Python/Bash), and building your own tooling when nothing off-the-shelf fits
  • Fluent in compliance frameworks - NIST CSF 2.0, SOC 2, and CCPA/CPRA - and translating controls into policy people actually follow
  • Strong software engineer at heart - comfortable reading and writing real application code, not just scripts, so you can dig into the codebase directly instead of filing a ticket and waiting
  • Confident being the only security voice in the room - makes the call and owns it
  • Translates technical risk into business terms leadership can actually act on
  • Calm and decisive under incident pressure; documents as they go, not after
  • Ownership-oriented; builds the process that doesn't exist yet instead of waiting for one
  • Strong individual contributor who wants to stay hands-on - this role builds the foundation directly, it doesn't lead from the side
Bonus Points:
  • Experience using AI/LLM tooling for threat intelligence - alert triage, detection summarization, or hunting workflows - not required, but a plus for a team building modern security practice from scratch
  • Familiarity with GDPR - a plus as Roofr's customer base grows internationally
  • Experience with PHP/Laravel - a plus for digging into Roofr's own codebase directly, not required
  • Comfortable around Postgres - helpful, not required

Our compensation ranges are built using multiple market benchmarks and reflect both the scope of the role and current market data. While many hires fall within the beginning to midpoint of the band to allow for growth over time, we tailor offers based on each candidate’s experience, seniority, and demonstrated impact.

What we offer (US + Canada)
  • 1st week of employment is mandatory PTO! Start your journey with Roofr by decompressing and recharging - we will see you in week 2!
  • 1 Friday off per month (we call those our laundry days!)
  • Company wide paid shutdown for the week between Christmas and New Years
  • Flexible time off
  • 80% employer-paid benefits in the U.S. and 100% employer-paid premiums for Extended Healthcare and Dental in Canada
  • Generous Parental Leave policy
  • We host an annual company retreat with great team building activities
  • Ample learning and development opportunities to continue growing your career
  • Home office setup stipend
  • Internet and phone allowance
  • Remote first culture
  • Weekly Friday paydays!

We're big fans of AI. It helps us write job descriptions that don't put you to sleep, takes notes during interviews so we can actually listen, and even helps us track down awesome humans like you.

Feel free to use AI to prep, research, or get pumped up for your interview (we see you, ChatGPT power users ). But when it's time to chat, we'd love to meet you, not your AI alter ego. Bring your real, unfiltered self, we promise we will too.

And don't worry, a real, live human is behind every part of our process. Every application is reviewed by a real person, and you'll always speak with real humans throughout the interview process. No bots, just good people

We've been made aware of an individual impersonating Roofr using a fraudulent domain: roofrr.com (note the extra r). Our company takes the security and privacy of job applicants very seriously. We will never ask for payment, bank details, or personal financial information as part of the application process. All our legitimate job postings can be found on our official career site. Please be cautious of job offers that come from non-company email addresses, instant messaging platforms, or unsolicited calls.

To ensure your application is legitimate, please apply directly through our official careers page: https://roofr.com/careers .

If you receive any suspicious messages or have questions, reach out to us at talent@roofr.com.

Your safety and security are important to us - thank you for your vigilance!

Roofr is proud to be an equal opportunity employer. We are committed to equal employment opportunity in the workplace regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or veteran status.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Staff Data Scientist
Staff Data Scientist

Roofr • Canada

Hybrid
CAD 140,000 - 160,000
PTO first week
Fridays off
Paid shutdown
+8
Senior People Operations Specialist (Contract)
Senior People Operations Specialist (Contract)

Roofr • Canada

Hybrid
CAD 80,000 - 95,000
1st week PTO
Friday off per month
Company-wide shutdown for holidays
+8
Director, Product Marketing
Director, Product Marketing

Roofr • Canada

Remote
CAD 150,000 - 175,000
PTO first week
Fridays off
Company shutdown
+5
Senior Revenue Operations Specialist
Senior Revenue Operations Specialist

Roofr • Canada

Remote
CAD 90,000 - 105,000
1st week of PTO
Friday off per month
Company-wide paid shutdown
+4
Senior Security Engineer
Senior Security Engineer

Rootly • Toronto

On-site
CAD 100,000 - 130,000
Competitive compensation
Comprehensive medical, dental, and vision coverage
3 weeks of vacation plus unlimited sick and mental health days
+2
Manager, Security Incident Response
Manager, Security Incident Response

Embedded Shishya • Canada

Remote
CAD 171,000 - 248,000
Maternity & parental leave
Health benefits
Generous PTO
Staff Security Engineer, Security Incident Response
Staff Security Engineer, Security Incident Response

1Password LLC • Canada

Hybrid
CAD 167,000 - 242,000
RSU program
Retirement matching
Free 1Password account
+2
Senior Security Engineer, Incident Response
Senior Security Engineer, Incident Response

1Password • Canada

On-site
CAD 143,000 - 193,000
Generous benefits program
Paid volunteer days
Remote-first work environment
+1
Senior Customer Engineer, Fed
Senior Customer Engineer, Fed

Webhosting • Ottawa

Hybrid
CAD 120,000 - 160,000
Manager, Security Incident Response
Manager, Security Incident Response

1Password LLC • Canada

Hybrid
CAD 171,000 - 248,000