Role Overview
This individual contributor position is responsible for advancing and maintaining robust security foundations at scale, with a primary focus on identity systems, authentication, and secure development practices. The role works closely with Engineering, Infrastructure, and Product teams to integrate security into the core of development and deployment processes, ensuring both protection and agility.
Key Responsibilities
- Evaluate and enhance security across applications, infrastructure, and software delivery pipelines
- Develop and enforce scalable security standards using automated, auditable methods aligned with compliance requirements
- Collaborate with technical leadership to align security initiatives with business goals and delivery timelines
- Proactively identify emerging threats and design systems to reduce long-term risk exposure
- Own the design, implementation, and maintenance of identity and access solutions, including authentication, authorization, and secure machine-to-machine communication
- Strengthen login mechanisms and establish consistent, secure authentication patterns across internal and customer-facing systems
- Build and maintain internal tooling to support secure development, monitoring, and compliance
- Integrate security controls into CI/CD workflows, including static and dynamic analysis, software composition analysis, container security, and secret management
- Support engineering teams in identifying, assessing, and resolving security vulnerabilities
- Provide practical security guidance during architecture and design phases
- Work cross-functionally to integrate security into development without impeding velocity
- Communicate complex security topics clearly to technical and non-technical audiences
- Act as a trusted advisor to engineering teams, balancing risk reduction with product innovation
- Lead through influence by setting security standards, building tools, and mentoring others
- Model ownership, accountability, and transparency in all security-related decisions
- Stay current with evolving practices in application security, cloud security, and identity management
- Apply industry frameworks such as OWASP, NIST, and CIS Controls in practical, production-focused ways
- Continuously refine identity architecture and security automation to support business growth
Required Qualifications
- 5–7+ years of experience in security engineering or software engineering with a strong security focus
- Proven track record building and maintaining production systems or internal tools
- Deep knowledge of application and infrastructure security, including secure CI/CD pipelines
- Hands-on experience with identity and access management, authentication systems, and machine-to-machine security
- Experience applying OWASP, NIST, or CIS Controls in real-world environments
- Familiarity with cloud security platforms (AWS, Azure, or GCP), SIEM/SOAR tools, and Infrastructure-as-Code security scanning
- Experience supporting SOC 2 or ISO 27001 compliance
- Working knowledge of modern backend technologies such as C# and cloud-native architectures
- Ability to work across teams and influence engineering culture toward better security outcomes
- Strong communication skills, with the ability to translate technical risks into clear, actionable insights
Preferred Qualifications
- Experience designing or migrating large-scale identity systems
- Background in building internal developer-focused security tooling
- Experience in high-growth technology environments
Work Mode
This role is hybrid, based in Boston, MA; Vancouver, BC; Chicago, IL; or Vancouver, WA. There is flexibility to consider fully remote candidates for select positions.
Company Culture
The organization values impact, strategic thinking, and customer focus. Team members are encouraged to be curious, collaborative, and resilient, with a strong emphasis on accountability, emotional intelligence, and inclusion. The culture prioritizes growth, transparency, and systemic equity—valuing contributions that expand perspectives rather than simply fitting in.
Equal Opportunity Employer
All applicants are considered without regard to race, color, religion, gender, gender identity or expression, national origin, disability, or age. The company is committed to diversity, inclusion, accessibility, and equitable practices in hiring, compensation, and advancement.