3h ago
Product Security Engineer
Toronto
$133,000-$173,000 / year
full-timemidMarketing technology
Tech Stack
Description
You will secure our codebases, CI/CD pipelines, and development practices, balancing a security-first mindset with practical delivery. Implement and maintain SAST, SCA, and secrets scanning tools, integrate security into CI/CD, triage vulnerabilities, and help educate developers on secure coding.
Requirements
- 2+ years in application security, DevSecOps, or security-focused software engineering
- Hands-on experience with SAST, SCA, or secrets scanning tools
- Familiarity with CI/CD pipelines and GitHub Actions
- Understanding of OWASP Top 10 vulnerabilities
- Experience reading code in Ruby, Python, JavaScript, or Go
Responsibilities
- Implement and maintain SAST using Semgrep
- Configure and improve SCA tooling (Dependabot)
- Manage secrets detection scanning (Trufflehog)
- Integrate security scanning into CI/CD pipelines (GitHub Actions)
- Triage and prioritize vulnerability findings with engineering teams
0 views 0 saves 0 applications