About the Role
Canary Technologies is hiring a Lead Security Engineer to lead our Security team within the Platform organization. This is a player-coach role: you'll manage and grow a small team of security engineers while owning Canary's security and compliance program end to end, including our control framework, audits, policies, and risk posture across a platform that handles guest data and payments for thousands of hotels worldwide. You'll also be Canary's primary security voice to customers, partners, and auditors, translating our security posture for everyone from a hotel group's CISO to our own executive team. You should be as comfortable running an audit and presenting to a customer's security team as you are reviewing a threat model with engineers.
What You’ll Do
- Lead, coach, and grow the Security team, including hiring, performance, priorities, and career development
- Own Canary's security and compliance program (SOC 2, PCI DSS, GDPR/CCPA, and other applicable frameworks)
- Serve as the primary security point of contact for Canary
- Own vendor and third-party risk management
- Write, maintain, and communicate security policies and standards company-wide; run security awareness and training
- Set technical direction for security tooling and stay hands-on in architecture and threat-model reviews
What We’re Looking For
- 8+ years in security engineering, including 2+ years leading a team as a manager or tech lead
- Proven experience owning compliance programs end to end (SOC 2 Type II, PCI DSS, ISO 27001, or similar)
- Exceptional written and verbal communication
- Hands-on technical foundation in cloud security (AWS), identity and access management, application security, and vulnerability management
- Experience with vendor risk management and reviewing security terms in customer and vendor contracts
- Track record of building pragmatic, risk-based security programs at a growth-stage SaaS company
- Nice to have: hospitality, fintech, or payments industry experience; CISSP, CISM, or CISA

