ApplySarthi

Senior Security Engineer - Vulnerability & Data/SaaS Security

Jobgether

Tailor my CV for this job, freeView job and applyYour CV rewritten for this role, from your real experience. Sign in with Google, nothing to install.

Got this interview? Our apps help you get the job.

Skills named in this job

Read from the description itself, not inferred.

This role on the market

68 open vulnerability roles across 30 companies are on ApplySarthi right now, most of them in Bengaluru (3), Chennai (1).

What vulnerability roles keep asking for: Python (47%), AWS (35%), C++ (25%), Go (25%), Java (16%) — counted across their open postings here.

Security Engineer jobs in Canada · Remote Security Engineer jobs · AWS jobs · IAM jobs · Python jobs · REST APIs jobs

Jobgether has 3,748 open roles listed here.

Counted across 14 company job boards, updated as roles open and close.

Preparing for this interview

Interviews for vulnerability roles keep coming back to Python, AWS, C++, Go. Practise those questions before you sit with Jobgether.

Questions you are likely to be asked

  1. Why do you want to join Jobgether?
  2. What is your experience with SaaS? Tell me one thing you learned the hard way.
  3. Walk me through how code gets from a commit to production where you work.
  4. Tell me about an outage you handled. What did you learn from it?
  5. How do you decide what to monitor, and what should wake someone up at night?

Prep Sarthi gives you a free mock interview: an AI interviewer asks you questions like these out loud, from your own CV and this job, and shows your score and your weakest answer.

Practise the Senior Security Engineer - Vulnerability & Data/SaaS Security at Jobgether interview free →

Accountabilities: Own the end-to-end vulnerability management lifecycle, including triage, risk-based prioritization, remediation tracking, SLA enforcement, and exception management across infrastructure, applications, and containers. Review vulnerability findings from application security and dynamic testing platforms, coordinate remediation with relevant teams, and maintain compliance with established remediation timelines. Develop and continuously improve risk-prioritization models that consider severity, exploitability, business criticality, regulatory requirements, and potential impact. Lead the cloud security posture management program across AWS, identifying misconfigurations, configuration drift, and control violations while strengthening secure baselines for IAM, networking, storage, encryption, compute, and containers. Manage data security posture initiatives, including sensitive-data discovery, automated classification, data-flow and lineage visibility, and monitoring of cross-environment data replication. Operate and mature SaaS security posture management capabilities, including sanctioned and shadow SaaS discovery, OAuth and third-party application governance, and SaaS data exposure monitoring. Partner with application, cloud, platform, and data engineering teams to translate security policies into effective technical controls and remediation actions. Automate findings aggregation, ticket creation, remediation workflows, ownership assignment, SLA tracking, escalation, and risk-exception processes. Build and maintain API integrations between security platforms and downstream systems such as ticketing platforms, SIEMs, CMDBs, and data warehouses. Develop Python scripts and automation to enrich security findings with asset and ownership context, reduce manual triage, and improve the reliability of security dashboards. Define and maintain security KPIs and KRIs, including MTTD, MTTR, SLA compliance, coverage, and risk-reduction trends. Produce accurate executive dashboards and recurring reports that translate technical security findings into clear business-risk narratives and compliance insights. Support compliance alignment across frameworks such as PCI DSS, SOX, SOC 2, and ISO 27001. Continuously improve the reliability and coverage of security tooling integrations and monitoring programs. Requirements 5+ years of professional experience in security engineering, with hands-on ownership of vulnerability management, cloud security, application security, data security, or SaaS security programs. Direct experience with vulnerability management and application security platforms such as Tenable, Snyk, and StackHawk or equivalent technologies. Strong experience securing AWS environments and working with cloud security posture management tools. Experience with endpoint and cloud workload detection and response platforms such as CrowdStrike Falcon. Hands-on experience with data security posture management and SaaS security posture management solutions, such as Sentra and Reco or comparable platforms. Experience with security findings aggregation or application security posture management platforms such as ArmorCode, including integrations with ticketing systems such as Jira. Strong Python scripting and REST API integration skills, with the ability to build and maintain security data pipelines across multiple platforms. Experience developing security metrics, KPIs, KRIs, and executive-level dashboards from security tooling data. Familiarity with SIEM integrations and security automation or orchestration practices is an asset. Strong understanding of security and compliance frameworks relevant to regulated environments, including PCI DSS, SOX, SOC 2, and ISO 27001. Excellent written and verbal communication skills, with the ability to translate complex technical risks into clear business terms for non-technical and executive stakeholders. Strong analytical and problem-solving skills, with the ability to prioritize risks and drive remediation across multiple teams. Experience establishing vulnerability, risk-exception, and SLA governance processes is highly valued. Experience in fintech, payments, financial services, or another highly regulated industry is considered an advantage. Benefits Competitive annual base salary of CAD $136,800–$171,000 , calibrated according to skills, experience, and working location. Annual bonus opportunities based on individual and overall company performance. Multiple health insurance options. Flexible vacation time plus additional floating holidays. Retirement savings program with company contributions. Equity participation in a publicly traded company. Monthly stipend to support remote work. Annual professional development stipend. Family-forming benefits. Up to 20 weeks of parental leave. Flexible-first remote working model for employees based in Ontario or British Columbia. Opportunity to work across vulnerability management, AWS security, data security, SaaS security, automation, and security analytics. High-impact role with broad visibility across engineering, security, compliance, and leadership teams. Collaborative environment emphasizing responsible innovation, continuous improvement, customer focus, and inclusive teamwork.

Match this job to your CV

ApplySarthi scores your CV against this role, shows the skills you are missing, and writes a tailored version for the application.

Check my match →

Similar open roles

Need answers during your interview? Try Live Sarthi.

Live Sarthi, an Interview Sarthi app, shows answer suggestions during the call.

Try Live Sarthi free →

A Windows app, from the same team as ApplySarthi.

Listed on lever · posted 2026-10-07. ApplySarthi collects openings and links to application pages; the role is advertised by Jobgether, not by us.