Senior Security Engineer
OpenTable View all jobs
- Toronto, ON
- $130,000-160,000 per year
- Permanent
- Full-time
- Conduct threat modeling and security design reviews for new and changing application features, APIs, and integrations; provide actionable guidance to engineering and product teams.
- Own incident triage and response for application/security events: coordinate stakeholders, drive containment/eradication/recovery, and ensure clear communications throughout the incident lifecycle.
- Partner with Product and Engineering to translate business requirements into security requirements, performing risk assessments and defining compensating controls when needed.
- Validate feature-level security controls and ensure alignment with compliance and industry best practices.
- Drive post-incident and post-release learning: lead root cause analysis, write postmortems, and track corrective actions to completion (detection improvements, guardrails, design changes).
- Translate vulnerability findings and incident learnings into prioritized remediation plans and mitigations,
- including short-term risk reduction and long-term design improvements.
- Collaborate across teams to anticipate emerging threats, incorporate them into design reviews, and improve detection/response playbooks.
- Build and maintain automation and tooling to streamline incident investigation (telemetry, alert enrichment, evidence collection) and application vulnerability management workflows.
- Evaluate and implement vendor security solutions that improve detection, response, and secure design (e.g., logging/SIEM, SOAR, runtime protections, SAST/DAST), ensuring effective integration into SDLC and IR processes.
- 5-7 years of combined Information Security Experience
- B.S. or M.S. Computer Science or a related field, or equivalent experience
- You have a breadth of knowledge and experience in Incident Response, application, infrastructure and systems security domains.
- You are a fast learner and have experience partnering with cross-functional teams.
- Technical certifications within information security are a plus (CISSP, CCSP, OSCP, OSWE or equivalents)
- Hacker mindset, passion for security, always strive to think like an attacker
- Experience in assessing new Application Features and establishing secure guidelines for Product teams
- Excellent written and oral communication skills
- Excellence in communicating business risk from cybersecurity issues.
- Proficiency in software development (Java, JS, Go, Python, C++, Ruby, etc.).
- Solid understanding of network and web protocols.
- Experience with the security of intra-company and third-party APIs.
- Solid experience with Incident Response and Threat Analysis
- Operate with a high level of independence
- Candidate Bonus Points for the Following:
- Experience with applied cryptography including PKI, SSL, and key management
- Experience with access and identity management
- Experience with SIEM and log management
- Generous paid vacation + time off for your birthday
- Work from (almost) anywhere for up to 20 days per year
- Focus on mental health and well-being:
- Company-paid therapy sessions through SpringHealth
- Company-paid subscription to Headspace
- Annual company-wide week off a year - the whole team fully recharges (and returns without a pile-up of work!)
- Paid parental leave
- Paid volunteer time
- Focus on your career growth:
- Development Dollars
- Leadership development
- Access to thousands of on-demand e-learnings
- Travel Discounts
- Employee Resource Groups
- Private health and dental insurance
- Life and Disability insurance