- Salary
- $70 – $80
- Workplace
- Remote
- Type
- Contract
- Department
- Engineering
- Seniority
- Senior
- Source
- RecruiterFlow
Description
OVERVIEW
We are seeking an experienced Senior Software Engineer, Security Engineering with a strong background in supply chain security and cloud-native security to support strategic initiatives for the client's Security Engineering team. The successful candidate will bring technical expertise in implementing and continuously improving security controls across infrastructure supply chain, containerized environments, and security automation, including AI/ML/LLM-based solutions. This person will be a key contributor to security best practices for containerized environments and to maturing the client's overall security posture.
This role is ideal for a highly motivated, hands-on security engineer who is comfortable working across container security, Kubernetes, CI/CD pipelines, and vulnerability remediation at scale, and who wants to help shape emerging AI-driven security automation.
Location: Toronto, Ontario / Fully remote
Contract Length: 5+ months
Hours: 40/h week
Experience Level: Senior
Pay: IC: $70-$80 / T4: $65-70
RESPONSIBILITIES
- Design and implement the process for building and maintaining hardened container base images for development and production environments, focusing on minimizing attack surface.
- Provide technical support and engineering solutions for securing Kubernetes (K8s) and containerized workloads, including runtime security, network policies, and admission controllers.
- Secure end-to-end infrastructure supply chain, including CI/CD tooling, Infrastructure as Code (IaC) templates, base images, Helm charts, and third-party dependencies.
- Build and contribute to security automation initiatives, including custom tooling development.
- Triage vulnerabilities identified through application security reviews, internal penetration testing, SAST, DAST, and SCA sources.
- Drive prioritization and remediation planning for vulnerabilities in partnership with engineering teams, including developing and committing patches to remediate issues.
QUALIFICATIONS
Required
- Deep, proven experience with container security, including designing and deploying hardened container images and securing Kubernetes clusters.
- Experience with Infrastructure as Code (IaC) tools, especially Terraform, for provisioning security controls.
- Strong practical experience building and operating security automation, with development expertise in languages such as Go and/or Python.
- Expertise using GitHub and CI/CD systems (GitHub Actions, Jenkins) from an architectural and engineering perspective.
- Expert-level proficiency in Software Composition Analysis (SCA), with hands-on experience remediating third-party and open-source dependency vulnerabilities at scale.
- Direct experience or strong conceptual understanding of applying AI/ML, Large Language Models (LLMs), or MCP techniques to security challenges (e.g., automated vulnerability fixing, intelligent alert grouping).
- Expert familiarity with cloud platforms (AWS, Azure) and their security services, with a focus on container orchestration.
Preferred
- Experience with Artifactory/JFrog.
- Advanced knowledge of application security (OWASP Top 10).
- Experience with supply chain security frameworks (e.g., SLSA).
- Post-secondary degree in Computer Science, Information Security, or related discipline (or equivalent practical experience).
Notes for Applicants
Resumes must clearly demonstrate hands-on experience with container and Kubernetes security, infrastructure-as-code, and vulnerability remediation at scale.