Senior Security Engineer

Forma.aiToronto, ON
CA$160,000 - CA$190,000

About The Position

As a Senior Security Engineer, you will be a hands-on technical leader strengthening security across Forma's application, cloud infrastructure, development lifecycle, internal systems, and incident-response practices. Security today is shared across Engineering and DevOps. You'll work closely with both teams and have real room to shape how Forma approaches security as we grow. Depending on your interests and the needs of the business, the role could develop into a deeper individual-contributor position or help build a dedicated security team. You'll work directly with Engineering, DevOps, IT, Product, Legal, and Privacy to identify risks, design practical controls, automate security processes, and help teams ship secure and reliable software.

Requirements

  • Six or more years of experience in security engineering, cloud security, application security, DevSecOps, or infrastructure engineering.
  • Strong hands-on experience securing AWS environments, including IAM, networking, encryption, logging, and secrets management.
  • Experience with Terraform, Kubernetes, containers, and security controls in CI/CD pipelines.
  • Strong understanding of application and API security, authentication, authorization, and multi-tenant SaaS risks.
  • Experience with vulnerability management, threat modelling, incident response, and security automation.
  • Ability to write scripts using Python, Bash, PowerShell, or a similar language.
  • Strong communication, troubleshooting, and cross-functional collaboration skills.

Nice To Haves

  • Experience supporting SOC 2, ISO 27001, privacy programs, or enterprise customer security reviews.
  • Experience securing analytics platforms, data pipelines, or systems handling sensitive customer data, including row-level, column-level, or attribute-based access controls.
  • Experience with AWS security services, EKS, Datadog, Wiz, Snyk, CrowdStrike, or similar tools.
  • Experience securing AI applications, large language models, agents, or Amazon Bedrock workloads.
  • Experience in a B2B SaaS or high-growth technology company.
  • Relevant security or cloud certifications.

Responsibilities

  • Design and implement security controls across Forma's AWS environments, with a focus on IAM, least-privilege access, service identities, and account boundaries.
  • Embed security requirements into Terraform and other Infrastructure as Code, and improve secrets, certificate, encryption-key, and credential management.
  • Build automated checks for insecure configurations, excessive permissions, exposed resources, and configuration drift across Kubernetes, containers, serverless workloads, networking, and data services.
  • Run threat modelling and security architecture reviews for new products, services, APIs, data pipelines, and third-party integrations.
  • Strengthen tenant isolation, authorization enforcement, and fine-grained data access controls at the schema, table, row, and column level.
  • Help protect sensitive compensation, financial, customer, and employee data across databases, data warehouses, S3, analytics services, and internal tools, including logging and auditability for sensitive-data access.
  • Review AI and agentic workflows for data leakage, prompt injection, insecure tool use, and excessive permissions; ensure agents operate strictly within the calling user's permissions; and define secure patterns for approved services such as Amazon Bedrock.
  • Identify and help remediate application vulnerabilities, and build tooling and reusable libraries that make the secure path the easy one for engineers.
  • Embed security testing into CI/CD — static analysis, dependency and container scanning, secrets detection, Infrastructure as Code scanning, and dynamic testing — without creating unnecessary friction for developers.
  • Define practical vulnerability-severity, remediation, exception, and escalation standards, and partner with developers to separate real risk from noise and fix root causes.
  • Improve software supply-chain security, including build permissions, artifact integrity, dependency governance, and GitHub administration.
  • Improve security visibility across cloud infrastructure, applications, identities, endpoints, and SaaS systems, and build alerts and detection logic that are worth acting on.
  • Lead investigations and coordinate containment, remediation, and root-cause analysis, supported by clear runbooks, ownership, and escalation paths.
  • Run tabletop exercises, and track and communicate security metrics and material risks to technical and business stakeholders.
  • Strengthen SSO, MFA, privileged access, and onboarding, offboarding, and access-review processes across AWS, GitHub, Microsoft 365, Entra ID, production systems, and internal SaaS — automating provisioning, entitlement reviews, and evidence collection where practical.
  • Translate security and compliance requirements into concrete technical controls, and support customer security reviews, audits, and programs such as SOC 2 and ISO 27001.
  • Evaluate third-party tools and integrations for security, privacy, and access-control risk, and help select, consolidate, and rationalize Forma's security tooling for both coverage and cost.
  • Maintain clear technical standards and provide practical guidance, training, and mentorship that raises security capability across Engineering.

Benefits

  • Employee stock ownership plan
  • Medical insurance
  • Dental insurance
  • Vision insurance
  • Disability insurance
  • Life insurance
  • Paid parental leave program
  • $750 yearly training stipend
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service