Senior Software Security Engineer

TimePlay

Toronto

On-site

CAD 120,000 - 180,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

TimePlay is seeking a Senior Security Engineer to own and mature the security function across product, infrastructure, operations, and governance. This hands-on IC role requires partnering with Engineering, DevOps, Product, IT, Legal, and leadership to embed security into design, build, deployment, and operations.

The ideal candidate will define the security roadmap, lead threat modelling, manage incident response, and provide executive-level reporting on posture, risks, and remediation

Qualifications

  • Strong knowledge of application security, cloud security, infrastructure security, identity and access management, encryption, monitoring, vulnerability management, and secure software dev practices.
  • Experience conducting threat modelling and technical risk assessments.
  • Ability to review architecture and make sound, risk-based security decisions.
  • Strong understanding of incident response processes, including detection, triage, containment, investigation, communication, and remediation.
  • Familiarity with modern cloud platforms, CI/CD pipelines, infrastructure-as-code, secrets management, container security, and DevOps practices.
  • Practical knowledge of SOC 2, ISO 27001, or similar security and compliance frameworks.
  • Ability to define security policies and standards that are practical, enforceable, and aligned with how teams work.
  • Strong analytical judgment and ability to prioritize security work based on likelihood, impact, exploitability, exposure, and business context.
  • Ability to communicate technical security risks clearly to engineering teams and business leaders.
  • Strong written communication skills, including risk documentation, executive reporting, incident summaries, and policy writing.
  • Ability to influence without relying on formal authority.
  • Comfortable operating independently in a growing and rapidly evolving security environment.
  • Balanced judgement; able to push hard on material risks while remaining pragmatic abot business needs and delivery timelines.

Responsibilities

  • Define and maintain the company’s security strategy, roadmap, and operating model.
  • Identify, assess, and prioritize security risks across product, infrastructure, cloud, data, vendors, and internal operations.
  • Lead threat modelling for new products, systems, integrations, and significant architectural changes.
  • Own security risk assessment processes and maintain visibility into material risks, control gaps, and remediation plans.
  • Partner with Engineering and DevOps to embed secure-by-design practices into dev, deployment, and ops workflows.
  • Own the incident response process, including prep, triage, containment, investigation, communication, post-incident review, and remediation tracking.
  • Provide executive-level reporting on security posture, key risks, incidents, roadmap progress, control maturity, and remediation status.
  • Translate technical security issues into clear business impact, trade-offs, and recommended decisions.
  • Contribute hands-on where needed through tooling, automation, configuration, detection logic, documentation, and secure implementation patterns.

Skills

Threat modelling
Incident response
Security governance
Cloud security
Security architecture
Risk assessment
Security policies
Executive reporting
Secure-by-design practices

Job description

We are looking for a Senior Security Engineer to own and mature our security function across product, infrastructure, operations, and governance. This is a senior individual contributor role for someone who is deeply technical, pragmatic, and comfortable operating with both engineering teams and executive leadership.

This person will be accountable for security risk outcomes, not just advisory input. They will define the security roadmap, lead threat modelling and risk assessment, own incident response, provide security sign-off on architecture, establish core security policies, and report clearly on the organizations security posture.

The ideal candidate is a hands-on security leader who can work closely with Engineering, DevOps, Product, IT, Legal and leadership teams to embed security into how we design, build, deploy, and operate systems.

Key Responsibilities and Duties:
  • Define and maintain the company’s security strategy, roadmap, and operating model.
  • Identify, assess, and prioritize security risks across product, infrastructure, cloud, data, vendors, and internal operations.
  • Lead threat modelling for new products, systems, integrations, and significant architectural changes.
  • Own security risk assessment processes and maintain visibility into material risks, control gaps, and remediation plans.
  • Partner with Engineering and DevOps to embed secure-by-design practices into dev, deployment, and ops workflows.
  • Own the incident response process, including prep, triage, containment, investigation, communication, post-incident review, and remediation tracking.
  • Provide executive-level reporting on security posture, key risks, incidents, roadmap progress, control maturity, and remediation status.
  • Translate technical security issues into clear business impact, trade-offs, and recommended decisions.
  • Contribute hands-on where needed through tooling, automation, configuration, detection logic, documentation, and secure implementation patterns.
Knowledge, Skills and Abilities:
  • Strong knowledge of application security, cloud security, infrastructure security, identity and access management, encryption, monitoring, vulnerability management, and secure software dev practices.
  • Experience conducting threat modelling and technical risk assessments.
  • Ability to review architecture and make sound, risk-based security decisions.
  • Strong understanding of incident response processes, including detection, triage, containment, investigation, communication, and remediation.
  • Familiarity with modern cloud platforms, CI/CD pipelines, infrastructure-as-code, secrets management, container security, and DevOps practices.
  • Practical knowledge of SOC 2, ISO 27001, or similar security and compliance frameworks.
  • Ability to define security policies and standards that are practical, enforceable, and aligned with how teams work.
  • Strong analytical judgment and ability to prioritize security work based on likelihood, impact, exploitability, exposure, and business context.
  • Ability to communicate technical security risks clearly to engineering teams and business leaders.
  • Strong written communication skills, including risk documentation, executive reporting, incident summaries, and policy writing.
  • Ability to influence without relying on formal authority.
  • Comfortable operating independently in a growing and rapidly evolving security environment.
  • Balanced judgement; able to push hard on material risks while remaining pragmatic abot business needs and delivery timelines.
What We’re Looking For:
  • We are looking for someone who has operated as a senior security individual contributor (IC) and has been accountable for outcomes, not just recommendations.
  • The right candidate may have held titles such as Senior Security Engineer, Security Architect, Application Security Engineer, Cloud Security Engineer, Infrastructure Security Engineer, or Lead Security Engineer.
  • You should be comfortable working hands-on with Engineering and DevOps teams rather than auditing from the outside. You should be able to review technical designs, challenge risky decisions, help implement better controls, lead incidents, brief executives, and build a practical roadmap for improving security maturity over time.

We are especially interested in candidates who:

  • Have experience owning security risk across multiple domains.
  • Can move fluidly between technical detail and executive-level communication.
  • Are credible with engineering teams and can provide practical, implementable guidance.
  • Understand how to balance security, delivery speed, operational complexity, and business priorities.
  • Have experience supporting SOC 2, ISO 27001, or similar frameworks.
  • Can create structure, process, and visibility in an environment where the security function is still maturing.
  • Are comfortable being the internal authority for security architecture, incident response, and risk prioritization.
  • Prefer collaborative, embedded security work over checkbox compliance or purely advisory review.
What You’ll Gain:
  • The opportunity to own and shape the security function at a meaningful level.
  • A senior IC role with direct influence on architecture, engineering practices, risk management, and executive decision-making.
  • The chance to build a practical, high-impact security program rather than inherit a rigid or overly bureaucratic one.
  • Broad exposure across product, infrastructure, cloud, data, vendor risk, compliance, and incident response.
  • Close partnership with Engineering, DevOps, Product, IT, Legal, and leadership.
  • The ability to define security standards and processes that scale with the business.
  • A role where security work is connected directly to business risk, customer trust, and operational resilience.
  • A high-trust environment where strong judgment, ownership, and technical credibility are valued.
  • This role operates in a collaborative, fast-moving environment where security must be practical, risk-based, and closely connected to product and engineering delivery.
  • The Senior Security Engineer will work cross-functionally with Engineering, DevOps, Product, IT, Legal, and executive leadership. The role requires comfort switching between deep technical work, risk assessment, incident coordination, policy development, and executive communication.
  • This is a hands-on senior IC role. The successful candidate should expect to participate directly in technical reviews, control design, incident response, tooling decisions, vendor assessments, documentation, and roadmap execution.
  • The environment is best suited to someone who is proactive, structured, collaborative, and comfortable creating clarity where processes are still evolving.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer II
Senior Security Engineer II

United States Digital Space LLC • Toronto

On-site
CAD 153,000 - 241,000
RSUs equity
Total Rewards package
Senior Security Engineer, Enterprise Security
Senior Security Engineer, Enterprise Security

United States Digital Space LLC • Toronto

On-site
CAD 133,000 - 209,000
Senior Cybersecurity Test Architect
Senior Cybersecurity Test Architect

Myticas Consulting • Ottawa

On-site
CAD 120,000 - 160,000
Senior Cyber Security Specialist
Senior Cyber Security Specialist

NDT Global GmbH & Co. • Quebec

On-site
CAD 110,000 - 150,000
Chief Software Engineering Architect
Chief Software Engineering Architect

DataStealth Inc. • Mississauga

Hybrid
CAD 180,000 - 240,000
Hybrid schedule
Senior Manager, Cybersecurity & GRC
Senior Manager, Cybersecurity & GRC

Axiom Global Technologies • Mississauga

On-site
CAD 150,000 - 210,000
Senior Manager, Engineering - Platform Security
Senior Manager, Engineering - Platform Security

United States Digital Space LLC • Denver

Hybrid
CAD 317,000 - 380,000
Medical, dental, vision insurance
401(k) with company match
Employee Stock Purchase Program
+1
Senior Cyber Security Specialist
Senior Cyber Security Specialist

NDT Global • Quebec

On-site
CAD 110,000 - 170,000
Great long-term career prospects
Challenging tasks in innovative teams
Attractive compensation system
+1
Senior Security Engineer
Senior Security Engineer

fispan • Vancouver

On-site
CAD 130,000 - 160,000
Extended health and dental benefits
Paid time off
Savings and retirement plan matching
+5
Security Architect
Security Architect

Chartwell Retirement Residences • Mississauga

Hybrid
CAD 120,000 - 170,000
Hybrid working
Minimum 2 office days per week
Occasional after-hours work