Senior Security Engineer 3, Product & Application Security at PagerDuty
Toronto, ON, Canada -
Full Time


Start Date

Immediate

Expiry Date

15 Jun, 25

Salary

0.0

Posted On

15 Mar, 25

Experience

4 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

No

Skills

Interpersonal Skills, Java, Cloud, Management Skills, Ownership, Mentoring, Sca, Oral Communication, Revenue, Bash, Infrastructure Security, Product Security, Splunk, Ruby, Security Incident Response, Commission, Framework, Coaching

Industry

Information Technology/IT

Description

PagerDuty empowers teams of all kinds to do the critical work that moves business forward through the PagerDuty Operations Cloud.
Visit our careers site to explore life at PagerDuty, discover opportunities, and sign-up for job alerts!
PagerDuty is seeking a Senior Security Engineer to join our diverse, customer-focused team! As a Senior Security Engineer, you will be a key contributor in leading, driving and delivering security initiatives for PagerDuty’s SaaS offerings, focusing on application & product security through architecture reviews, threat modeling sessions, and defining secure-by-design product standards and protections that support PagerDuty’s security mission. Since we own and operate what we build, you’ll collaborate closely with engineers across many product development teams. You will work closely with our internal development teams to ensure we deliver secure, highly reliable, and scalable solutions to our customers.
This is an exciting opportunity to build security solutions that make developers and customers happy. The ideal candidate will have a blend of experiences across large enterprise environments and small or mid-size environments and will have focused on establishing security standards, coordinating with product development teams, developing strategies for secure-by-default architectures, and corresponding process and tooling selection and implementation. Things that make you smile: secure product architectures, providing an engaging Developer Experience for security adoption, and cute animal memes.
This role is expected to come into our Toronto office 1 day/month, so you can thrive in your new role and fully embrace being a Dutonian!

BASIC QUALIFICATIONS

  • Proficiency with Application & Product Security typically associated with 4 - 5 years of experience in a Security Engineering role working with a cloud-native, microservices environment, preferably AWS.
  • Familiarity with cloud-native product technologies including:


    • Vulnerability detection via multiple approaches including SAST, DAST, SCA, and runtime (e.g., Qualys/Nessus, Wiz, Snyk, GHAS, Semgrep, etc.)

    • CI/CD technologies and integrations (e.g., CircleCI, Buildkite, Helm, Terraform, Chef)
    • Product security event logging standards and analysis tools (e.g., SIEM such as: SumoLogic, LogRythm, or Splunk, etc.)
    • Security Incident Response & Risk Management processes and tools
    • Proficiency in at least one programming language and framework (e.g. Python, Bash, Phoenix/Elixir, Java, Ruby on Rails), typically associated with 3 - 4 years of experience with the language/framework.
    • Have exceptional written, oral communication, and interpersonal skills.
    • Organizational skills with the ability to successfully manage multiple priorities and deadlines.

    PREFERRED QUALIFICATIONS

    • Ability to analyze complex problems, develop solutions under guidance, and assist in implementing these solutions with a growing set of change management skills.
    • Possesses a strong sense of ownership and a keen discernment for excellence in securing systems within a SaaS environment, demonstrating the ability to distinguish what constitutes truly robust and effective product security.
    • Current or past experience with obtaining and maintaining FedRAMP authorization.
    • Experience working at a SaaS company larger than 1000 employees and $100M in revenue.
    • Familiarity with Cloud Infrastructure security (such as AWS GuardDuty, AWS CloudTrail, AWS Secrets Manager, AWS IAM & Identity Center, AWS Control Tower, Azure Security Center, Microsoft Defender for Cloud, etc.)
    • Familiarity with Container Security (e.g., Kubernetes, EKS, AKS, service mesh, baseline/benchmark hardening, identity and secrets orchestration, etc.)
    • Demonstrated history of mentoring and coaching.
      The base salary range for this position is 139,000 - 207,000 CAD. This role may also be eligible for bonus, commission, equity, and/or benefits.
      Our base salary ranges are determined by role, level, and location. The range, which is subject to change based on primary work location, reflects the minimum and maximum base salary we expect to pay newly hired employees for the position. Within the range, we determine pay for an individual based on a number of factors including market location, job-related knowledge, skills/competencies and experience.
      Your recruiter can share more about the specific offerings for this role, as well as the salary range for your primary work location during the hiring process.

    NOT SURE IF YOU QUALIFY?

    Apply anyway! We extend opportunities to a broad array of candidates, including those with diverse workplace experiences and backgrounds. Whether you’re new to the corporate world, returning to work after a gap in employment, or simply looking to take the next step in your career path, we are excited to connect with you.

    Responsibilities
    • Embrace the role of hands-on technical lead in defining product security standards and guiding platform protections.
    • Establish criteria and conduct comprehensive security reviews throughout all stages of product development to identify and address security risks.
    • Perform regular threat assessments, coordinate with third-party testers for penetration testing, and conduct internal penetration testing to identify and mitigate security risks.
    • Mentor and guide team members to ensure product and business objectives are prioritized in project implementations, fostering a strong documentation culture with project charters and design documents.
    • Work with loosely defined requirements where you exercise your analytical skills to clarify questions, share your approach, and collaborate with the team to design and implement effective security frameworks. Maintain a strong appetite for challenging problems with a high degree of ownership.
    • Participate in the team’s On-Call rotation, triaging and addressing security issues as they arise, and implement measures to prevent future occurrences.
    • Enable service team security implementations by developing security-as-code constructs, including infrastructure-as-code (IaC) modules, libraries and frontend components, while creating and maintaining developer-focused documentation to promote easy adoption.
    • Establish and uphold baseline standards and hardened configurations for platform components.
    • Continuously enhance security frameworks by focusing on product security standards and software supply chain protections, tailored for application security in cloud-native, microservices environments.
    Loading...