{"id":901510,"url":"https://alion.io/job/localcoin-cybersecurity-engineer","title":"Cybersecurity Engineer","company":{"id":679678,"name":"Localcoin","domain":"localcoin.com","url":"https://alion.io/company/localcoin","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":null,"work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"explicit","locations":["Canada"],"countries":["CA"],"hiring_countries":[],"hiring_countries_total":0,"salary":{"min":100000,"max":150000,"currency":"CAD","period":"year","gross":null,"usd_annual":105369},"salary_estimate":null,"experience_years_min":5,"visa_sponsorship":true,"relocation_package":false,"has_equity":false,"technologies":[{"name":"AWS","optional":false},{"name":"IAM","optional":false},{"name":"Linux","optional":false},{"name":"SIEM","optional":false},{"name":"Threat Modeling","optional":false},{"name":"Amazon EC2","optional":true},{"name":"Amazon ECS","optional":true},{"name":"Bitcoin","optional":true},{"name":"Java","optional":true},{"name":"PCI DSS","optional":true},{"name":"Snowflake","optional":true},{"name":"SOC 2","optional":true}],"status":"live","first_seen_at":"2026-06-03T14:10:37Z","employer_posted_date":"2026-09-03","last_verified_at":"2026-10-04T01:26:15Z","board_verified":true,"closed_at":null,"days_open":122,"trust":{"level":"stale","repost_count":0,"flags":["stale"],"days_open":121},"description":"ABOUT US\nLocalcoin, founded in 2017 with headquarters in Toronto, is on a mission to simplify the process and experience of buying or selling digital currencies globally. We envision bringing digital currency to the mainstream financial market through partnerships with leading corporate and franchised retail spaces. With terminals across Canada, Poland and the APAC region, including Australia, Hong Kong, and New Zealand, Localcoin is now the fastest growing Bitcoin ATM operator in the world.\nAt its core, Localcoin believes that everyone should be able to own cryptocurrency and have a deep understanding of blockchain technology. As a member of our rapidly growing team, you'll join a talented, dynamic group of team members who will encourage you to learn, grow, and thrive in your career every step of the way.\nWe are a high-ownership engineering organization focused on building secure, resilient, and scalable systems in a rapidly evolving regulatory and threat landscape.\nAs one of the earliest dedicated security hires, you’ll play a foundational role in shaping our security posture, tooling, and engineering practices across the company.\nTHE ROLE\nSalary Range: $100,000 - $150,000\nWe’re looking for a hands-on Cyber Security Engineer with strong DevSecOps instincts to help design, build, and mature security capabilities across our infrastructure, applications, and operational environments.\nThis is primarily an engineering role (roughly 80% engineering / 20% governance) focused on implementing scalable security solutions, improving visibility and detection capabilities, hardening infrastructure, and partnering closely with engineering teams to build secure systems by default.\nYou’ll work directly with the Director of Engineering and collaborate across platform, backend, infrastructure, compliance, and operations teams.\nThis role is ideal for someone who thrives in high-autonomy environments, enjoys solving difficult infrastructure and security problems, and wants meaningful ownership in a fast-moving fintech/crypto company.\nThis position will be based out of our office in Etobicoke, ON, and will have a hybrid work schedule of 2 days a week. \nWHAT YOU’LL BE DOING \nDesign, implement, and harden security infrastructure across our AWS-based cloud environment.\nBuild and improve vulnerability management and reporting processes across infrastructure and applications.\nLead and coordinate security incident response efforts, including investigation, remediation, and postmortem analysis.\nImplement and manage SIEM, monitoring, alerting, and detection capabilities\nPartner with engineering teams to design and maintain secure systems and development practices.\nDevelop automation and tooling to improve security operations and reduce manual processes.\nEvaluate and strengthen IAM policies, access controls, and cloud security configurations\nSupport application security initiatives including secure SDLC practices, threat modeling, and testing workflows.\nManage external penetration testing engagements and remediation tracking\nCollaborate with vendors, auditors, and compliance stakeholders on security and regulatory initiatives.\nContribute to policies, standards, and operational procedures aligned with evolving regulatory requirements.\nAssess the organization’s overall security posture and provide practical recommendations for improvement.\nWHAT WE’RE LOOKING FOR \n5 - 10 years of hands-on experience securing AWS and cloud-native infrastructure, including infrastructure hardening, IAM, networking, and cloud security best practices. \nDeep understanding of networking, Linux systems, IAM, and infrastructure security principles.\nExperience with application security practices and secure software delivery.\nExperience managing penetration testing programs and remediation processes.\nExperience operating in fintech, cryptocurrency, or other regulated environments.\nStrong understanding of modern security threats, attack vectors, and defensive controls.\nAbility to write code, automation, or tooling to improve security operations.\nExperience working cross-functionally with engineering and infrastructure teams.\nStrong incident response and troubleshooting capabilities.\nComfortable operating in high-ownership, fast-moving environments with evolving priorities.\nNICE TO HAVE: \nExperience implementing or operating SIEM platforms.\nSecurity automation and orchestration experience.\nDetection engineering experience.\nExperience with SAST/DAST tooling and workflows.\nFamiliarity with compliance and regulatory frameworks such as FINTRAC, MiCA, DORA, PIPEDA, PCI-DSS, or SOC 2.\nSecurity certifications such as OSCP, CISSP, GIAC, Security+, or cloud security certifications.\nOUR ENVIRONMENT\nYou’ll work across a modern cloud-native stack including:\nAWS\nEC2 / ECS\nRDS\nSnowflake\nJava-based services\nCrypto ATM infrastructure\nComplex VPC and networking environments\nWHAT SUCCESS LOOKS LIKE:\nIn your first 6-12 months, you will:\nEvaluate and improve our overall security posture.\nIdentify key risks and security gaps across infrastructure and applications.\nEstablish scalable vulnerability management and reporting processes.\nImprove monitoring, detection, and incident response capabilities.\nHelp engineering teams adopt stronger security-by-default practices.\nContribute to building a mature and pragmatic security program that scales with the business.\nWHAT YOU’LL LOVE ABOUT US\nCompetitive Salary & Benefits - We value and reward our team members.\nRRSP Group Matching Program - We invest in your financial well-being.\nHybrid Work Environment - Enjoy flexibility while being part of a dynamic team.\nProfessional Development - Opportunities for learning and growth covered by Localcoin.\nTeam Culture & Events - Regular socials, team meetings, and collaborative workspaces.\nImpactful Work - Play a key role in a growing company and make a real difference.\nGreat Place to Work® Certified - Proudly recognized for our positive workplace culture and employee experience 2 years in a row. \nJOIN OUR INCLUSIVE TEAM\nLocalcoin is committed to building an inclusive, accessible, and equitable workplace. We welcome applicants from all backgrounds and do not discriminate based on race, ancestry, place of origin, color, ethnic origin, citizenship, creed, sex, sexual orientation, gender identity or expression, age, marital status, family status, or disability.\nIf you require accommodation at any stage of the recruitment process, please notify the Talent team or email .\nApplicants must be legally eligible to work in Canada. At this time, we are not able to provide visa sponsorship.\nAI DISCLOSURE STATEMENT\nWe want to share that we may use artificial intelligence (AI) tools to help screen and assess applications. While technology helps us stay organized and efficient, every hiring decision at Localcoin is made by real people who care about finding the best addition to our team. These tools are used to support our process-not to replace the human judgment and connection that are core to our culture.","description_format":"text","description_chars":7050,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Hybrid work","Professional development"],"hiring_locations":[{"name":"Canada","iso":"CA","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Cryptocurrencies"],"lifecycle":[{"event":"open","at":"2026-09-14T11:46:25Z"}],"visa":[],"liveness":{"score":9,"band":"cold","label":"Long shot","p_open":1,"p_active":0.325,"p_room":0.28,"age_days":121,"expected_fill_days":42,"reasons":["conf:2","win:tail","crowd:"],"computed_at":"2026-10-03T05:45:00Z"},"pay":{"stated_usd_annual":105369,"is_top_pay":false},"html_url":"https://alion.io/job/localcoin-cybersecurity-engineer","json_url":"https://alion.io/job/localcoin-cybersecurity-engineer.json","meta":{"generated_at":"2026-10-04T02:16:51Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3201,"day_limit":5000,"remaining_today":1799,"minute_limit":60,"resets_at":"2026-10-05T00:00:00Z"}}}