3h ago

Product Security Engineer

Toronto

$133,000-$173,000 / year

full-timemidMarketing technology

Tech Stack

Description

You will secure our codebases, CI/CD pipelines, and development practices, balancing a security-first mindset with practical delivery. Implement and maintain SAST, SCA, and secrets scanning tools, integrate security into CI/CD, triage vulnerabilities, and help educate developers on secure coding.

Requirements

  • 2+ years in application security, DevSecOps, or security-focused software engineering
  • Hands-on experience with SAST, SCA, or secrets scanning tools
  • Familiarity with CI/CD pipelines and GitHub Actions
  • Understanding of OWASP Top 10 vulnerabilities
  • Experience reading code in Ruby, Python, JavaScript, or Go

Responsibilities

  • Implement and maintain SAST using Semgrep
  • Configure and improve SCA tooling (Dependabot)
  • Manage secrets detection scanning (Trufflehog)
  • Integrate security scanning into CI/CD pipelines (GitHub Actions)
  • Triage and prioritize vulnerability findings with engineering teams
0 views 0 saves 0 applications