679,351open jobs
39,352companies
99,642added this week
Browse all
Salary
$55k – $120k per year (Estimated)
Location
Remote/Hybrid (Toronto, Canada)
Seniority
Junior · 2+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match

About League

League is one of the fastest-growing technology companies in Canada and the leading healthcare experience platform. Getting healthcare is often the easy part - finishing it is where things fall apart: people book the appointment and skip the follow-up, fill the prescription and stop taking it, get the referral and never make the call. That gap costs health plans and health systems money, and it costs people their health. League closes that gap - identifying what each person needs to do next, clearing what’s in their way, and getting it done, for the 70 million+ people whose care already runs through our platform. Health plans and health systems trust us to do this at scale. Organizations like Manulife, SCAN, Geisinger, and Medibank on the payer side, and Baptist and Shoppers Drug Mart on the provider side. 

Position Summary

League's security engineering team is responsible for scaling security across the development lifecycle. We believe in security by design and follow a paved-road philosophy: we build or buy tooling that integrates into our platform so it is easier for engineers to do the right thing than the wrong thing. Security is everyone's responsibility, and security engineering is how we make it possible for engineers to ship high-quality code to production several times a day with security built in.

This role is an intermediate security engineer who splits their time between engagement work and engineering work. On the engagement side you will run security reviews for new product work, contribute to technical deep dives on existing systems, assess vendors before they are approved for use, and review third-party vendors that handle League customer data. On the engineering side you will write code and engage with tooling and systems: automation that removes manual review steps, checks that run in our pipelines, and tooling that makes findings easier to route, track and close.

League ships AI-enabled features and our engineers work with AI-assisted development tooling daily. Reviewing those systems, and reasoning about the security of code and fixes that AI produces, is a standing part of this role rather than a specialty.

You will bring some experience with threat modeling and cloud architecture to meaningfully contribute to secure design practices, while senior engineers and architects own the broader security strategy. You think in systems and processes, which is how you will find the second-order, long-term fix rather than the quick, most immediate one. You share what you learn, and you can explain risk clearly to a software engineer and to infrastructure leadership in the same week.

We welcome new ideas and encourage diverse experience, in every meaning of the word - if you have a unique background, deep interests in a niche topic of security or engineering, or some experience that brings new approaches to security and engineering, this is a strength that we welcome on the team. While this summary outlines the main job responsibilities, it is by no means exhaustive - we are a fast-moving organization, and change can happen quickly here, especially when it raises the bar of security for League and our customers. So, bring your ideas, your unique insights, and challenge the norm. We will be better for it.

What You will do:

  • Conduct security reviews of product features, integrations, and platform changes, documenting resulting security requirements
  • Participate in threat modeling exercises to identify risks in system design and data flow
  • Perform security assessments of applications, APIs, and cloud configuration, and provide remediation guidance engineering teams can act on
  • Review AI-enabled product features for prompt injection, excessive agency and unintended exposure of member data
  • Triage and score security findings, and drive remediation with the owning teams
  • Own the configuration, tuning, and triage workflow for security tooling
  • Automate manual review efforts and embed security checks into the SDLC
  • Build training materials and documentation on secure coding practices and common vulnerabilities; regularly share knowledge with peers
  • Support League’s shift left by contributing reusable security controls to our paved road so that common vulnerabilities are prevented by default
  • Contribute to the development and maintenance of League’s security standards and internal documentation.
  • Conduct security reviews of third-party vendors that process or store League data, and support customer security assurance requests.
  • Support SOC 2 Type II, HITRUST, HIPAA, and PHIPA control design, testing, and evidence gathering in partnership with the Privacy and Compliance team.
  • Communicate risk findings clearly to different audiences, adapting language and level of detail for engineers versus leadership.

What You Bring

  • 2+ years of professional experience in application or product security, or in software engineering with substantial security responsibility
  • Ability to find what scanners miss: broken access control, tenant isolation failures, business logic flaws
  • Working knowledge of authentication and authorization in modern applications, including OAUTH 2.0 / OIDC, session and token handling, and role or attribute-based access control
  • Familiarity with CI / CD and software supply chain security, including pipeline-integrated testing, dependency management, and secrets handling
  • Solid working knowledge of common application vulnerabilities (e.g., OWASP Top 10) and their mitigations
  • Experience with AI and LLM application security, including prompt injection, agentic tool-use risk and retrieval pipeline exposure
  • Some exposure to cloud security concepts and secure cloud architecture, ideally GCP, including containerized workloads.
  • A track record of writing and shipping code other people rely on, in Python, Go, or a comparable language
  • Some experience with threat modeling methodologies (e.g. STRIDE)
  • General awareness of SOC 2 Type II, HITRUST, HIPAA and PIPEDA

Nice-to-have

  • Experience handling PHI or comparably  sensitive data in a regulated environment.
  • Exposure to incident response.
  • Self-driven security work: side projects, CTFs, published research, or a coordinated disclosure history

Security-Related Responsibilities

  • Ensure access management is performed in compliance with the employee's role and responsibilities
  • Responsibility and accountability for executing League's policies and procedures within the department/ team
  • Notification of HR, Legal, Compliance & Security of any incidents, breaches or policy violations
  • Compliance with Information Security Policies

CANADA APPLICANTS ONLY: The Canada-specific compensation range below for this full-time position is exclusive of bonus, equity and benefits. This range reflects the minimum and maximum target for base salaries for the position across all Canadian locations. The salary range is intentional to account for the performance and career progressions a Leaguer will experience in the role throughout their time at League. Where in the band you may land is determined by job-related skills/experience. Your recruiter can share more about the specific salary range specific to your skills and experience during the hiring process.

Compensation range for Canada applicants only

$109,100—$136,400 CAD

AI Fluency & Ways of Working

At League, we are an AI-native organization. We expect all employees regardless of role or level to thoughtfully leverage AI to improve the quality, speed, and impact of their work.

What this means in practice:

  • Use AI tools as part of your daily workflow  to enhance productivity, problem-solving, and decision-making (e.g., drafting, analysis, coding, research, or process automation)
  • Apply judgment and accountability  when using AI by reviewing outputs for accuracy, bias, and quality before use
  • Continuously learn and adapt  as new AI tools and capabilities emerge, incorporating them into your ways of working
  • Identify opportunities to improve how work gets done  from personal productivity to team-level workflows by leveraging AI effectively
  • Operate with strong data responsibility and security awareness, especially when working with sensitive or regulated information

How this scales by level:

  • Individual Contributors:  Use AI to improve personal productivity and quality of output
  • Senior ICs / Managers:  Integrate AI into team workflows and improve processes
  • Leaders:  Drive AI adoption at the organizational level and shape how work is done across teams

What we look for:

  • Demonstrated experience using AI tools in a practical, responsible way
  • Curiosity and openness to experimenting with new technologies
  • Ability to balance efficiency with quality and sound judgment

Our employees come from different backgrounds, and we celebrate those differences. We are looking for the best candidates for our open roles, but do not expect applicants to meet every qualification in order to be considered. If you are excited about what you could accomplish at League and believe you can add value to our team, we would love to hear from you.

We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. If you are an individual in need of assistance at any time during our recruitment process, please contact us at [email protected].

Our Application Process:

Applying to a role you love can be exhausting, and understanding the next steps can feel vague and uncertain. You have done the hard part of submitting your application; let's do ours by sharing potential next steps

  • You should receive a confirmation email after submitting your application.
  • A recruiter (not a computer) reviews all applications at League.
  • If we see alignment with League's needs, a recruiter will reach out to learn more about your goals. The recruiter will also share the team-specific interview process depending on the roles you are exploring.
  • The final step is an offer, which we hope you will accept!
  • Prior to joining us, we conduct reference and background checks. Additional checks could be required for US Candidates, depending on the role you are exploring.

Here are some additional resources to learn more about League:

Work Location:

We have a mix of office-centric roles based in our vibrant Toronto office, and remote-eligible roles based anywhere in Canada or US. Each job posting will indicate where the role will be based. Regardless of the role’s posted location, all Toronto-area Leaguers (living within 65 km of our downtown HQ) collaborate in-office Monday through Thursday. Depending on your distance to the office, you’ll enjoy 10 or 20 Flexible Remote Days each quarter for focus and deep-work time. We are committed to fostering a meaningful work environment and connections for all Leaguers regardless of location.

Recognize and Avoid Employment scams. Practice safe job searching.

Scammers are getting craftier and leveraging fake job postings to get personal information. Know the warning signs and protect yourself from scammers. Learn more here.

Use of AI Notice

We are committed to ensuring fairness and transparency throughout our hiring process. League may use Artificial Intelligence (AI) tools to assist in the screening of applicants for this position. Please check out our stance on using AI in recruitment here.

Privacy Policy

Review our Privacy Policy for information on how League is protecting personal data.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
679,351 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account Continue with Google
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Toronto
SR. AI Engineer 5 hours ago
$59k – $147k per year (Estimated) • In office • Full-Time • 3+ years exp • Bachelor's Degree • Taichung
Python
Go
JavaScript
Rust
SQL
Databases
Snowflake
MS SQL
AI/ML
Model Context Protocol
AI Agents
LLM
Agentic Workflows
DevOps
Rest API
GCP
Azure
CI/CD
AWS
Docker
Kubernetes
Analytics
ETL/ELT
Apply
SENIOR DATA SCIENTIST 5 hours ago
$51k – $124k per year (Estimated) • In office • Full-Time • Master's Degree • Taichung
Python
JavaScript
SQL
Python
pySpark
Databases
Snowflake
AI/ML
Spark
AI Agents
LLM
Streamlit
DevOps
GCP
Apply
Software Engineer 1 hour ago
$95k – $183k per year (Estimated) • Remote/Hybrid • Full-Time • Sydney
Python
Go
JavaScript
Java
C#
Node JS
Databases
PostgreSQL
Redis
DynamoDB
MS SQL
AI/ML
Copilot
Claude Code
RAG
DevOps
GCP
Azure
AWS
Apply
In office • 5+ years exp
JavaScript
TypeScript
SQL
C#
C#
.NET
DevOps
GCP
Azure
CI/CD
Git
AWS
Management
Power Automate
Power Apps
Agile
Apply
Software Engineer I 5 hours ago
$99k – $129k per year • Remote • Full-Time • Bachelor's Degree
JavaScript
TypeScript
SQL
C#
C#
ASP.NET Core
Blazor
WPF
Frontend
Angular
DevOps
Azure
CI/CD
Git
Apply
$115k – $250k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 6+ years exp
JavaScript
TypeScript
AI/ML
Claude Code
Model Context Protocol
AI Agents
Frontend
React.js
DevOps
GCP
Design
Figma
Apply
$94k – $195k per year (Estimated) • Remote/Hybrid • Full-Time • 7+ years exp • Bachelor's Degree • Toronto
Python
Databases
Google BigQuery
BigQuery
AI/ML
Claude
Falcon
LLM
OpenAI
DevOps
Terraform
GCP
Azure
AWS
Google Cloud Run
Incident Management
Cybersecurity
Crowdstrike
Wiz
GDPR
Apply
$179k – $297k per year (Estimated) • Equity • Remote/Hybrid • Full-Time • 10+ years exp
Go
AI/ML
Cursor
Claude Code
Model Context Protocol
Context Engineering
Multi-Agent Systems
DevOps
GCP
Kubernetes
Platform Engineering
Apply
$92k – $192k per year (Estimated) • Remote/Hybrid • Full-Time • 5+ years exp • Toronto
AI/ML
LLM
DevOps
GCP
CI/CD
AWS
Kubernetes
Platform Engineering
Apply
Director, FP&A 20 days ago
$108k – $220k per year (Estimated) • Remote/Hybrid • Full-Time • 10+ years exp • Toronto
AI/ML
Claude
Model Context Protocol
AI Agents
Agentic Workflows
DevOps
GCP
Management
Outlook
Apply
$115k – $214k per year • Equity • Remote/Hybrid • Full-Time • 7+ years exp • Frisco • New York • Toronto • Ann Arbor
AI/ML
Agentic Workflows
Apply
$115k – $214k per year • Equity • Remote/Hybrid • Full-Time • 7+ years exp • Frisco • New York • Toronto • Ann Arbor
AI/ML
Agentic Workflows
Apply
$181k – $337k per year • Equity • Remote/Hybrid • Full-Time • 5+ years exp • New York • Frisco • Toronto • Ann Arbor
Apply
$91k – $141k per year • Remote/Hybrid • Full-Time • 7+ years exp • Bachelor's Degree • Toronto
Python
SQL
Scala
Python
pySpark
Databases
Databricks
AI/ML
Spark
DevOps
Azure
AWS
Analytics
ETL/ELT
Management
Agile
Apply
Account Supervisor 1 day ago
$54k – $111k per year (Estimated) • In office • Full-Time • 5+ years exp • Toronto
Management
Outlook
Apply
See all jobs
This is one of many
679,351 more open roles from verified company boards, updated every day.