Senior Security Engineer at Lime
Canada, Ontario, Canada -
Full Time


Start Date

Immediate

Expiry Date

22 Nov, 26

Salary

0.0

Posted On

24 Aug, 26

Experience

0 year(s) or above

Remote Job

Yes

Telecommute

Yes

Sponsor Visa

Yes

Skills

Industry

Information Technology & Services

Description

Responsibilities

Application Security & Secure Development: Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features, APIs, mobile applications, and backend services. Provide actionable and risk-calibrated guidance that helps Lime ship securely without slowing down

Security Tooling & Automation: Develop and maintain scalable security tools and pipelines to automate vulnerability detection, dependency scanning, and security testing across the software development lifecycle. Contribute to and extend our security pipeline and CI/CD security gates (SAST, DAST, SCA, secrets management)

Security Architecture & Design Reviews: Contribute to security architecture reviews for new product platforms and features. Evaluate authentication and authorization designs, API security posture, and data handling practices to ensure risks are identified and addressed early

Bug Bounty & External Programs: Support the operations of our BugCrowd bug bounty program, including triage, researcher communication, remediation coordination, and internal validation of reported findings

Incident Response: Serve as a product security point of contact for security incidents affecting Lime's applications and services. Contribute to investigation, root-cause analysis, corrective action, and post-incident improvement

Cross-functional Partnership & Mentorship: Work closely with Software, Platform, Mobile, and Infrastructure engineering teams to embed security into development workflows. Share knowledge, drive security-by-default practices, and mentor engineers and peers on product security fundamentals

Stay Ahead of the Threat Landscape: Continuously evaluate emerging threats, vulnerabilities, and regulatory requirements (including EU CRA) relevant to Lime's product and infrastructure stack. Bring proactive recommendations to the team

Participate in the team's on-call rotation, responding to incidents, troubleshooting issues, and contributing to root cause analysis and service reliability improvements

Respond to and troubleshoot production issues, outages, and critical alerts during assigned on-call shifts


Escalate incidents as needed and collaborate with team members to restore service


Document issues and contribute to improvements that reduce recurring incidents


Be available to provide occasional after-hours, weekend, and holiday support while on call

Qualification

checkRepresents the skills you have

Find out how your skills align with this job's requirements. If anything seems off, you can easily click on the tags to select or unselect skills to reflect your actual expertise.

checkApplication SecuritycheckSecure Development PracticescheckThreat ModelingcheckRisk AssessmentAPI SecuritycheckMobile Security iOScheckMobile Security AndroidcheckBackend Services SecuritycheckSecurity Tooling and AutomationcheckVulnerability DetectionDependency ScanningcheckSecurity Testing SASTcheckSecurity Testing DASTcheckSecurity Testing SCAcheckSecurity Testing Secrets ManagementcheckSecurity Architecture ReviewscheckAuthentication and Authorization Patterns OAuthcheckAuthentication and Authorization Patterns OIDCcheckAuthentication and Authorization Patterns RBACBug Bounty Program OperationscheckIncident ResponsecheckDetection EngineeringcheckSecurity MonitoringDetection-as-Code PipelinescheckSIEMcheckLog AnalysischeckAlert TuningcheckIoT SecuritycheckConnected Hardware SecuritycheckVehicle/Firmware SecurityRequired

5+ years of experience in a dedicated product security, application security, or security engineering role, with a strong track record of hands-on technical contribution across the software development lifecycle

Demonstrated expertise across core product and application security domains

Experience with detection engineering, security monitoring, or building detection-as-code (DaC) pipelines for product or application security threats (SIEM, log analysis, alert tuning)

Familiarity with IoT, connected hardware, or vehicle/firmware security in a product security context

Experience operating or contributing to a vulnerability disclosure or bug bounty program

Exposure to regulatory frameworks relevant to connected products, such as EU CRA, UNECE WP.29, or OWASP MASVS

Mobile security (iOS, Android) and API security

Secure development practices and SDLC security integration (SAST, DAST, SCA, secrets management)

Vulnerability management tooling and processes

Cloud security fundamentals (AWS, GCP) and container/infrastructure security

Authentication and authorization patterns (OAuth, OIDC, RBAC)

Strong analytical skills with the ability to triage ambiguous security signals, identify meaningful risk, and propose pragmatic mitigations that teams can act on

Clear written and verbal communicator who can translate complex technical security risks into actionable guidance for both engineering peers and non-technical stakeholders

Comfortable operating in a lean, remote-first, high-trust environment

Ability to participate in a shared on-call rotation supporting production systems, including occasional after-hours, weekend, and holiday coverage, with responsibility for responding to critical alerts, coordinating escalations to restore service, and documenting issues to help prevent recurrence

Preferred

Bachelor's degree in Computer Science, Cybersecurity, or a related field preferred but not required

Relevant certifications such as OSCP, CSSLP, GWEB, or equivalent are a plus


Responsibilities
Loading...