This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Developer, Vulnerability Management based in Canada.
This is a high-impact security engineering role focused on transforming vulnerability management from a manual, reactive process into an automated, intelligent platform.
You will own and evolve a custom vulnerability management platform, building integrations, automations, workflows, and data pipelines that operate across the security lifecycle.
Your work will help engineering teams identify, prioritize, route, validate, and remediate vulnerabilities with significantly less manual intervention.
You will collaborate closely with developers, security specialists, and platform teams to turn complex security findings into actionable solutions.
The role offers a greenfield opportunity to shape vulnerability management architecture while integrating AI-assisted development and security automation.
You will work with modern cloud and DevSecOps technologies across AWS, Kubernetes, CI/CD, container environments, and security tooling.
This is an ideal opportunity for an experienced security engineer who combines strong vulnerability management expertise with a developer mindset and a passion for automation.
Accountabilities
- Own and continuously evolve the custom vulnerability management platform, contributing to its deployment, architecture, integrations, data model, and automation workflows.
- Build automation across the vulnerability management lifecycle, including triage, ticket routing, SLA tracking, ownership resolution, remediation follow-up, and vulnerability closure.
- Develop and maintain integrations with vulnerability scanners and security tools, transforming raw scanner output into enriched, actionable findings and tickets.
- Expand the platform beyond existing team workflows by integrating vulnerability management into engineering processes and making security workflows easier for development teams to adopt.
- Build and maintain queries, dashboards, reports, and data workflows that provide security teams and leadership with clear visibility into vulnerability posture and remediation progress.
- Work with AI-assisted development tools and automation platforms to reduce manual effort and improve the speed and consistency of security operations.
- Contribute to the integration of vulnerability management with a cyber reasoning system, supporting future workflows where validated findings can be tested in a sandbox and translated into potential fixes or pull requests.
- Assess vulnerabilities across application and infrastructure layers, helping teams distinguish genuine security risks from inaccurate or low-value findings.
- Support risk assessment and prioritization by considering real-world attack surface, exposure, architecture, traffic flows, and business context rather than relying solely on vulnerability scores.
- Partner with developers to explain findings, resolve disagreements, troubleshoot unsuccessful remediation attempts, and translate security requirements into practical solutions.
- Collaborate with teams responsible for CI/CD, deployment, threat intelligence, bug bounty, responsible disclosure, and compliance to strengthen the broader vulnerability management ecosystem.
- Stay current with emerging threats, vulnerability research, exploitation techniques, and the evolving role of AI in security, incorporating relevant developments into platform strategy and prioritization.
- 4+ years of hands-on experience in vulnerability management, security engineering, or a closely related field, including scanner integration, vulnerability triage, remediation tracking, and security workflow development.
- Strong understanding of the software development lifecycle, with the ability to identify where vulnerabilities are introduced and assess whether security findings accurately represent real risks.
- Production experience with AWS and practical knowledge of modern cloud infrastructure and security practices.
- Strong automation-first mindset, with a proven track record of building solutions that replace or significantly reduce manual processes.
- Deep familiarity with vulnerability management tooling such as Tenable, Semgrep, Rapid7, or comparable platforms, including experience building API-based integrations.
- Strong understanding of application and infrastructure vulnerabilities, including vulnerability classes such as XSS and CSRF, as well as code, package, library, container, and infrastructure vulnerabilities.
- Hands-on exposure to SAST, DAST, SCA, OWASP fundamentals, and knowledge of where different security scanners fit within CI, production, and network environments.
- Experience with GitHub Actions, ArgoCD, Kubernetes, AMIs, container images, and container registries such as ECR or comparable technologies.
- Understanding of attack surface and exposure management, with the ability to evaluate actual security exposure and business risk when making prioritization or risk-acceptance decisions.
- Strong communication and stakeholder-management skills, particularly when working with developers and technical teams who may challenge or disagree with security findings.
- Understanding of how vulnerability management connects with CI/CD and deployment pipelines, threat intelligence, bug bounty or responsible disclosure programs, and compliance controls.
- Familiarity with vulnerability scoring and prioritization frameworks such as CVSS, EPSS, and SSVC is beneficial.
- Active experience using AI-assisted development tools such as Claude Code, Cursor, Copilot, or similar solutions, with the judgment to use AI effectively while validating its output.
- Experience with security orchestration platforms such as Tracecat, Tines, XSOAR, or comparable tools is a plus.
- Experience with bug bounty or responsible disclosure programs, open-source security contributions, or work in fintech or other regulated environments is advantageous.
- Strong problem-solving skills, curiosity, ownership, and the ability to work effectively in a fast-moving engineering environment.
- Competitive annual base salary range of CA$151,200-CA$189,000, with actual compensation determined by skills, experience, and role level.
- Equity compensation for permanent employees, providing an opportunity to participate in the organization's long-term growth.
- Clear job levels and market-based salary bands designed to support fair and consistent compensation.
- Comprehensive health benefits and life insurance.
- Long-term group savings program with employer matching.
- 20 vacation days plus 4 wellness days annually.
- Unlimited sick days and mental health days.
- Flexibility to work outside Canada for up to 90 days per year.
- Remote working environment with a distributed team across North America.
- Opportunities to collaborate with highly skilled, curious, and technically driven colleagues.
- Employee resource groups supporting inclusion and community, including groups focused on 2SLGBTQ+ employees, women, and Black employees.
- An environment that encourages experimentation, thoughtful technology choices, AI adoption, and continuous improvement.
- Commitment to an inclusive and accessible hiring and working environment, with reasonable accommodations available throughout the recruitment process.

