Overview
Company
Profile match
Impact
Conditions
Benefits
Hiring process
Similar jobs
Jobgether is an AI-powered job platform focused on remote and flexible work. It matches candidates with relevant roles using skills and preference-based algorithms, and also offers career coaching and job-search guidance.

This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Sr. Staff Security Engineer based in Canada.

This is a senior-level security architecture role with broad ownership across cloud infrastructure, applications, identity, networks, and data protection.

You will serve as a key technical authority, shaping secure-by-default architectures and influencing how engineering teams design and operate systems.

The role combines hands-on architecture with strategic leadership, threat modeling, governance, and security enablement.

You will work closely with engineering, product, technology leadership, privacy, compliance, and security teams to embed security throughout the development lifecycle.

A major focus will be building scalable security practices that enable teams rather than creating unnecessary delivery bottlenecks.

You will also help protect sensitive health information while strengthening resilience against evolving threats in a highly regulated environment.

This is an opportunity to establish durable architecture standards, mentor security professionals, and make a measurable organization-wide impact.

Accountabilities:

  • Own and continuously evolve security architecture across cloud infrastructure, applications, corporate systems, identity, networks, and data, establishing standards, patterns, and reference architectures for engineering teams.
  • Lead threat modeling for product, engineering, and infrastructure initiatives, with particular attention to sensitive health data flows, patient-facing applications, and virtual care systems, while coaching engineers to perform threat modeling independently.
  • Conduct architecture reviews for new and existing systems, assess designs against security principles and regulatory requirements, and provide practical recommendations that balance risk, usability, scalability, and delivery speed.
  • Design and scale the architecture review process through self-service patterns, risk-tiered workflows, and clear criteria for when deeper security review is required.
  • Partner with technology and enterprise architecture leaders to integrate security governance into existing technical processes rather than creating parallel or disruptive workflows.
  • Define and promote application security standards covering secure design, API security, authentication and authorization, OAuth/OIDC, SAML, data protection, and healthcare interoperability standards such as HL7 and FHIR.
  • Establish and govern zero trust strategies across identity, network, endpoint, and data layers, as well as key management, secrets management, encryption, and certificate lifecycle practices.
  • Define security architecture for third-party integrations and external systems, ensuring supply-chain and integration risks are addressed at the design stage.
  • Act as a trusted security partner to product and engineering leaders, participating early in design and planning discussions to help teams build secure-by-default systems.
  • Translate privacy, compliance, audit, and governance requirements into concrete architectural controls, with particular attention to HIPAA Security Rule technical safeguards, HITRUST, NIST, and SOC 2.
  • Maintain architecture decision records, reference designs, control frameworks, and other durable documentation that supports consistent security practices.
  • Partner with senior security leadership on long-term architecture strategy, risk measurement, executive reporting, and security roadmap development.
  • Mentor and elevate security engineers and promote stronger architectural thinking across security and engineering teams.
  • Monitor emerging threats and attack techniques, particularly those affecting healthcare environments, and incorporate relevant intelligence into security architecture decisions.
  • Establish measurable outcomes around architecture risk, threat modeling adoption, reference architecture usage, and the shift of security findings from late-stage remediation toward earlier design-stage prevention.
  • Requirements:

    • Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent professional experience.
    • 10+ years of progressive security experience, including at least 5 years focused on security architecture across enterprise and cloud environments.
    • Deep expertise across multiple security domains, including application security, cloud security, identity and access management, network security, and data protection.
    • Strong hands-on experience architecting cloud security solutions covering network security, IAM, encryption, key management, secrets management, and cloud-native security services.
    • Proven experience leading structured threat modeling using methodologies such as STRIDE, PASTA, or equivalent, from individual features through complex systems, and mentoring engineers in threat-modeling practices.
    • Strong knowledge of secure software development lifecycles, OWASP principles, application security patterns, and modern authentication and authorization approaches including OAuth 2.0, OIDC, and SAML.
    • Experience designing key management, secrets management, PKI, and certificate lifecycle controls in cloud-native environments.
    • Working knowledge of HIPAA and its Security Rule technical safeguards, HITRUST CSF, NIST CSF, and SOC 2, with the ability to translate requirements into practical technical controls.
    • Demonstrated ability to communicate complex technical risks clearly to both engineering teams and executive stakeholders.
    • Experience working across identity, network, application, and data security rather than operating within a single security domain.
    • Strong architectural judgment and the ability to balance security, operational practicality, scalability, and engineering velocity.
    • Self-directed and comfortable bringing structure to ambiguous technical problems while influencing decisions across teams.
    • Preferred experience in healthcare, digital health, or another highly regulated industry.
    • Preferred experience designing or scaling zero trust architectures and enterprise architecture review processes, including risk-tiering and self-service models.
    • Familiarity with API security, HL7, FHIR, SABSA, or TOGAF security extensions is advantageous.
    • Experience mentoring senior engineers or establishing security architecture practices from the ground up is a plus.
    • Benefits:

      • Remote work opportunity for employees based in the United States or Toronto, Canada.
      • Medical, dental, and vision insurance plans.
      • Flexible Spending Accounts and Health Savings Accounts.
      • Flexible paid time off.
      • 401(k) retirement plan with company matching.
      • Life insurance coverage.
      • Pet insurance.
      • Opportunity to work in a relatively flat environment that encourages autonomy, ownership, and ideas from employees.
      • Significant opportunity to influence security architecture, engineering practices, and organization-wide technical standards.
      • Leadership and mentoring opportunities at the highest technical level of the security function.

Recommended for you based on this role

Similar stack
Same company
In your city
Remote • Full-Time • Canada
Databases
ClickHouse
StarRocks
Trino
AI/ML
Claude
Cursor
DevOps
Incident Management
Apply
$143k – $178k per year • Equity • Remote • Full-Time • 8+ year exp • Montreal
Python
SQL
Databases
Snowflake
AI/ML
dbt
Marketing
Amplitude
Apply
Remote • Full-Time • Brazil
Marketing
HubSpot
Pipedrive
Salesforce
Apply
$93k – $118k per year • Remote • Full-Time • Canada
Elixir
Python
SQL
Databases
Apache Kafka
Apache Pulsar
Databricks
AI/ML
Flink
DevOps
AWS
CloudFormation
GCP
SLI/SLO/SLA
Terraform
Apply
Remote • Full-Time • Canada
Databases
ClickHouse
StarRocks
Trino
AI/ML
Claude
Cursor
Apply
Remote • Full-Time • 3+ year exp • Bachelor's Degree • Brazil
AI/ML
Claude
DevOps
Azure
Azure DevOps
Analytics
Power BI
Management
Jira
Marketing
Salesforce
Zendesk
Apply
$143k – $178k per year • Equity • Remote • Full-Time • 8+ year exp • Montreal
Python
SQL
Databases
Snowflake
AI/ML
dbt
Web3
Bitcoin
Marketing
Amplitude
Apply
$225k – $250k per year • Remote • Full-Time • Spain
Python
AI/ML
LLM
Apply
$180k – $225k per year • Remote • Full-Time • Washington
SQL
TypeScript
Apply
$85k – $115k per year • Remote • Full-Time • 5+ year exp • Bachelor's Degree • New York
JavaScript
Python
SQL
DevOps
Rest API
QA
Cypress
Playwright
Postman
Selenium
Apply
Career impact
Discover how this job can transform your career
Get a personal career forecast for this job - salary uplift, next-level role, skill boost and a 3-year financial impact, all calculated from your profile.
Personal salary uplift vs. your current pay
Your 3-year career trajectory
Skills you will level up in this role
3-year financial impact in dollars
Create free account
Free forever • Less than a minute • No credit card

Work setup

Location
Toronto
Remote work
Remote (United States, Canada)
Employment
Full-Time

Compensation

Benefits
Insurance coverage, Life insurance, Retirement plans, Vision insurance