Skip to main content
NMI

Senior Staff Information Security Engineer

RemoteCanada only
Published
Role
Security
Experience
Staff
Employment
Full-time
CAD 175k–CAD 195k/yr
Check eligibility

Open to CA only. Set where you work from to check your eligibility.

No BS summary

Senior Staff security engineer with deep AWS and hybrid infrastructure experience. Must be proficient in Python/Go and infrastructure-as-code. Remote Canada based.

Core skills

AWS

Required skills

Python/Go

Optional skills

KubernetesContainer securitySoftware supply-chain securityPolicy-as-codeCNAPPCSPMSIEMEDR

What you'll do

  • Lead Infrastructure Security Architecture.
  • Define and evolve security architecture across AWS and our colocation estate.
  • Establish secure reference architectures, engineering standards, and reusable control patterns.
  • Provide technical leadership for major infrastructure, platform, and product initiatives.
  • Identify systemic risks and lead practical, sustainable programmes to address them.
  • Strengthen Cloud and Hybrid Security.
  • Design and improve security across cloud accounts, networks, identities, workloads, and shared services.
  • Establish effective controls for identity and access management, segmentation, encryption, secrets, logging, monitoring, and workload protection.
  • Develop preventative guardrails through infrastructure-as-code, policy-as-code, automation, and cloud-native security services.
  • Improve consistency across the enterprise including cloud, on-premises infrastructure, and the connectivity between them.
  • Partner with Engineering and Product.
  • Engage early in the design of new products, platforms, services, and integrations.
  • Lead threat modelling, security architecture reviews, and technical risk assessments.
  • Translate security risks into clear, practical engineering recommendations.
  • Help teams adopt secure-by-design principles through reusable patterns, tooling, and documentation.
  • Build, Automate, and Apply AI.
  • Design and implement security tooling, integrations, and automated controls.
  • Embed security capabilities into infrastructure provisioning, engineering workflows, and CI/CD pipelines.
  • Use AI-assisted tooling to improve scripting, detection development, alert analysis, vulnerability triage, threat modelling, and technical documentation.
  • Validate AI-generated outputs and ensure AI tools are used with appropriate controls for confidentiality, accuracy, access, and human oversight.
  • Improve Risk Reduction and Resilience.
  • Provide technical direction for vulnerability and exposure management across AWS and on-premises infrastructure.
  • Identify recurring patterns across incidents, penetration tests, vulnerabilities, and control assessments.
  • Act as a senior technical escalation point during significant security incidents.
  • Ensure investigations and lessons learned result in durable architectural and engineering improvements.
  • Provide Senior Technical Leadership.
  • Lead complex security initiatives spanning multiple teams and planning cycles.
  • Mentor security engineers and provide guidance to engineers in adjacent teams.
  • Raise the standard of security architecture, automation, documentation, and technical decision-making.
  • Communicate security risks and recommendations clearly to technical teams, product leaders, and senior stakeholders.

What they require

  • Significant experience in security engineering, infrastructure security, cloud security, security architecture, or platform engineering.
  • Deep, hands-on experience securing AWS environments.
  • Strong knowledge of AWS identity and access management, network architecture, account governance, encryption, logging, monitoring, secrets management, and workload protection.
  • Experience designing or securing on-premises, data-centre, or colocation-hosted infrastructure.
  • Strong knowledge of enterprise networking, segmentation, firewalls, secure remote access, privileged administration, and hybrid connectivity.
  • Experience with infrastructure-as-code, CI/CD security, containerised environments, and cloud-native platforms.
  • Demonstrated experience designing and implementing automated security controls and engineering solutions.
  • Proficiency with scripting or software development using Python, Go, or a comparable language.
  • Practical experience using AI-assisted tooling to improve security engineering and operational workflows.
  • Experience leading complex initiatives across multiple engineering, infrastructure, or product teams.
  • Strong knowledge of security architecture, threat modelling, vulnerability management, detection, and incident response.
  • The ability to operate independently, navigate ambiguity, and influence decisions across technical and leadership audiences.
  • Preferred: An advanced AWS certification in security, architecture, networking, or cloud engineering.
  • Preferred: Experience in fintech, payments, SaaS, or another regulated technology environment.
  • Preferred: Experience securing large or complex AWS multi-account estates.
  • Preferred: Experience with Kubernetes, container security, software supply-chain security, and policy-as-code.
  • Preferred: Experience with technologies such as CNAPP, CSPM, SIEM, EDR, DLP, WAF, vulnerability-management, network-security, or secrets-management platforms.
  • Preferred: Familiarity with PCI DSS, SOC 2, GDPR, NIST, or ISO 27001.
  • Preferred: Experience supporting significant security incidents, penetration tests, audits, or customer security assessments.

Benefits

  • Competitive compensation package
  • 40 hours week with flexi-time
  • Health and Dental Insurance
  • Life, ADD, Short-term and Long-term Disability insurance
  • Extended Health Care/Emergency Travel Assistance
  • Employee Assistance Program
  • Work Remotely
  • Vacation, Personal Wellness and Sick time
  • 10 Paid Holidays
  • Bonusly colleague reward scheme
  • Employee referral scheme with generous financial reward

NMI

Payment Technologies

NullEnterprise
CAD 175k–CAD 195k/yr