368,634open jobs
9,437companies
50,578added this week
Browse all
Salary
$180k – $233k per year
Location
Remote (Columbia, Ontario, United States)
Seniority
Senior · 6+ years exp
Employment
Full-Time
Overview
Company
Impact
Profile match
Thumbtack is an American technology company headquartered in San Francisco, California, and was founded in 2008. The company operates an online marketplace that connects consumers with local service professionals for a wide range of tasks, including home improvement, event planning, and wellness services. It serves millions of customers across all 50 U.S. states, providing a platform for small business owners to manage leads and grow their client base through a mobile app and website.

Thumbtack helps millions of people confidently care for their homes.

Thumbtack is the one app you need to take care of and improve your home - from personalized guidance to AI tools and a best-in-class hiring experience. Every day in every county of the U.S., people turn to Thumbtack to complete urgent repairs, seasonal maintenance and bigger improvements. We help homeowners know which projects to do, when to do them and who to hire from our growing community of 300,000 local service businesses. If making an impact inspires you, join us. Imagine what we’ll build together.

About the Cyber Security Team

The Security Engineering team at Thumbtack is focused on enabling innovation at scale by making the secure path the easiest path. We believe strong security is not a blocker to velocity, but a force multiplier when it is designed into systems, platforms, and developer workflows from the start.

We partner closely with teams across the organization to shape system design, guide architectural decisions, and evolve Thumbtack’s security posture as the company scales. Through collaboration, automation, and thoughtful tradeoffs, we help ensure Thumbtack can ship fast, innovate boldly, and maintain customer trust.

The challenge

AI is reshaping how work gets done at Thumbtack. Employees leverage AI assistants in their daily work and teams are building autonomous agents that act on their behalf - reading data, calling APIs, and making changes across enterprise systems. This introduces changes in the risk landscape. Identities now belong to agents and services as often as to people. Protocols like MCP are opening new pathways between AI and enterprise data. And the pipelines feeding AI systems cross more services, vendors, and trust boundaries than they have previously.

The challenge is to evolve security controls to address these shifts in the technology and risk landscape driven by AI-adoption: hardening IAM for non-human and delegated identities, defining safe defaults for MCP servers and autonomous agents, and securing the data pipelines that feed AI systems. We package these controls as secure defaults, paved paths, and reusable patterns so teams can adopt them with confidence. The goal is straightforward - keep Thumbtack moving fast on AI while keeping customer and employee data protected.

What you’ll do

  • This role focuses on improving AI-adjacent security at Thumbtack, including the agents, identities, integrations, and data pipelines that modern AI systems depend on. It also covers broader security engineering work across the enterprise platforms and services that support them.

  • Deliver high-quality security assessments and threat models for first-party and third-party AI tools, agents, and AI-integrated systems, ensuring they adhere to enterprise security principles and approved patterns, with sound authentication, authorization, data access, and observability by design.

  • Design and validate technical guardrails and reusable patterns that keep AI usage safe at Thumbtack. This spans AI behavior (safe defaults for agent actions, tool and permission scoping, human-in-the-loop boundaries for sensitive access, input and output controls, audit and observability) and AI connectivity (MCP servers, integrations, trust boundaries, and the data pipelines that feed first- and third-party AI systems). Contribute to the frameworks and tooling that support secure AI development and use across Thumbtack.

  • Harden IAM across the enterprise, with particular focus on the non-human and delegated identities behind AI systems (service accounts, agent credentials, SaaS-to-SaaS OAuth, and SCIM federation). Bring least-privilege and lifecycle hygiene to identities that increasingly act at machine speed.

  • Provide broader security engineering support across Thumbtack's enterprise platforms and services, including SaaS security and posture management, third-party and integration security, data governance, endpoint security, and identity-centric controls. Build paved paths, shared tooling, and automation that scale these controls.

  • Lead cross-functional security initiatives end-to-end. Partner with IT, Engineering, Legal, Privacy, Procurement, and business stakeholders to surface risk early, set clear requirements, and support scalable adoption of secure patterns. Conduct security design and architecture reviews for enterprise applications, SaaS platforms, and internally developed systems.

  • Mentor engineers and partner-team members, raising the overall security bar through guidance and example.

  • Support security incident response and drive learning through post-incident analysis.

In order to be successful, you must bring

  • 6+ years of experience in security engineering, enterprise security, application security, cloud security, or a related field.

  • Experience developing threat models and proposing technical guardrails for AI tooling and agentic systems, including non-human identities, tool/permission scoping, and safe defaults for agent behavior.

  • Deep expertise in modern enterprise security disciplines: authentication and authorization (SSO, OAuth/OIDC, SAML, federation, SCIM), API security and token handling, secrets management, least-privilege design, SaaS security and posture management.

  • Strong experience evaluating risk and conducting security design and architecture reviews across enterprise applications, SaaS platforms, integrations, and internally developed systems, including evaluating data flows, third-party integrations, trust boundaries, automation platforms, AI-connected workflows, and emerging integration patterns such as MCP.

  • Strong experience securing modern, cloud-native systems (AWS and/or GCP) and familiarity with core control domains such as audit logging, encryption, access control, data retention, and incident response.

  • Strong sense of ownership and accountability, balancing hands-on technical execution with the ability to mentor others, raise standards, and drive measurable improvements in enterprise security.

  • Excellent written and verbal communication skills, with the ability to influence without authority and translate technical risk into clear requirements and actionable guidance for both technical and non-technical audiences.

Expected salary ranges

  • For candidates living in Ontario and British Columbia, the expected salary range for the role is currently $180,200.00 - $233,200.00.

Actual offered salaries will vary and will be based on various factors, such as calibrated job level, qualifications, skills, competencies, and proficiency for the role.

Thumbtack embraces diversity. We are proud to be an equal opportunity workplace and do not discriminate on the basis of sex, race, color, age, pregnancy, sexual orientation, gender identity or expression, religion, national origin, ancestry, citizenship, marital status, military or veteran status, genetic information, disability status, or any other characteristic protected by federal, provincial, state, or local law. We also will consider for employment qualified applicants with arrest and conviction records, consistent with applicable law.

Thumbtack is committed to working with and providing reasonable accommodation to individuals with disabilities. If you would like to request a reasonable accommodation for a medical condition or disability during any part of the application process, please contact: [email protected].

For information about how Thumbtack collects, uses, and shares personal information about job applicants, please see our Job Applicant Privacy Policy.

We put as much craftsmanship into candidate safety as we do into the hiring experience itself. While scammers may try to impersonate our team, we’ll never ask you for money, banking info, or SSNs during hiring. Check out our blueprint on how to spot the fakes.

Free account
Stop reading job ads. Get the ones that fit.
One free account turns this page into a shortlist built around your stack, your level and your pay.
Match on every job. Stack, seniority, pay and location, scored against your profile.
368,634 open roles. Read straight off company career pages, refreshed every day.
Unlimited applications. Every one you send is tracked in one place, on-site or on a company board.
3 tailored CVs a month. Rewritten for the exact job you are applying to. Included free.
Create a free account
Free forever. No card. Under a minute.

Your match

How well do you fit this role?
Two answers are enough for a real match. No account needed.
Check my fit
Answers stay in this browser until you create an account.

Recommended for you based on this role

Similar stack
Same company
Ontario
$28k – $65k per year (Estimated) • In office • Full-Time • 12+ years exp • Bengaluru
Bash
PowerShell
Python
Node JS
JavaScript
Node JS
Commander.js
AI/ML
AI Agents
DevOps
Amazon EC2
Amazon EKS
AWS
Azure
Kubernetes
Amazon ECS
IAM
Cybersecurity
Crowdstrike
Zero Trust
Apply
$71k – $170k per year (Estimated) • In office • Full-Time • Netanya
Python
TypeScript
AI/ML
Accelerate
Fine-tuning
LangChain
LLM
NLP
Prompt Engineering
PyTorch
RAG
Edge AI
Hugging Face
AI Agents
DevOps
AWS
Azure
Docker
GCP
Kubernetes
Apply
$20k – $54k per year (Estimated) • In office • Full-Time • Pune
Java
SQL
DevOps
GCP
Incident Management
Kubernetes
IAM
QA
JMeter
Selenium
Apply
AI Engineer 1 day ago
$25k – $103k per year (Estimated) • In office • Full-Time • Bachelor's Degree • Gurgaon
Python
SQL
Databases
Databricks
Microsoft Fabric
AI/ML
AI Agents
Embeddings
Gemini
Hallucination
LangChain
LangGraph
LLM
Multimodal AI
Prompt Engineering
PyTorch
RAG
Semantic Search
Spark
TensorFlow
Hugging Face
LLM Guardrails
LLMOps
OpenAI
Semantic Search
DevOps
AWS
Azure
CI/CD
Apply
$26k – $64k per year (Estimated) • In office • Full-Time • 12+ years exp • Bachelor's Degree • Hyderabad
DevOps
AWS
Azure
GCP
Cybersecurity
Cyber Kill Chain
Diamond Model
MITRE ATT&CK
Apply
$270k – $330k per year • Remote • Full-Time • 10+ years exp
Apply
$25k – $56k per year (Estimated) • Remote • Full-Time • 6+ years exp
Python
DevOps
AWS
GCP
Cybersecurity
MITRE ATT&CK
PCI DSS
SOC 2
Apply
$201k – $260k per year • Remote • Full-Time
Apply
$201k – $260k per year • In office • Full-Time • 5+ years exp
Apply
Senior Data Engineer 1 month ago
$180k – $233k per year • Remote • Full-Time • 4+ years exp • Ontario • Columbia
Python
SQL
Databases
Google BigQuery
AI/ML
Airflow
dbt
Feature Store
Analytics
ETL/ELT
Apply
$101k – $202k per year (Estimated) • Equity • Remote • Full-Time • 8+ years exp • Ontario
C#
SQL
TypeScript
JavaScript
Assembly
C#
.NET
Entity Framework Core
Assembly
Keystone Engine
Frontend
Angular
DevOps
CI/CD
Apply
$73k – $171k per year (Estimated) • Equity • Remote • Full-Time • Ontario
Python
JavaScript
Databases
PostgreSQL
AI/ML
LangChain
LangGraph
Prompt Engineering
Frontend
React.js
Redux
DevOps
AWS
Management
n8n
Apply
$68k – $183k per year (Estimated) • Equity • Remote • Contractor • 3+ years exp • Ontario
Databases
OpenSearch
Redis
AI/ML
Claude
DevOps
AWS
Kubernetes
Apply
$94k – $168k per year (Estimated) • Equity • Remote • Contractor • 8+ years exp • Ontario
Apply
$96k – $236k per year (Estimated) • Equity • Remote • Contractor • Ontario
AI/ML
AI Agents
DevOps
AWS
Incident Management
Kubernetes
IAM
Cybersecurity
Okta
Zero Trust
Apply
See all jobs
This is one of many
368,634 more open roles from verified company boards, updated every day.