2

Offensive Security Engineer Remote Jobs in Toronto, ON

Remote Role Responsibilities * Use frontier AI coding agents to complete and evaluate complex security engineering tasks . * Review model-generated code and architectures for vulnerabilities and ...

Software Engineer Job Type: Contract Location: Remote Job Summary: We are looking for experienced ... Identify tradeoffs around scalability, maintainability, performance, reliability, security, and ...

Senior AI Engineer - Remote

Toronto, ON · On-site +1

CA$147K - CA$245K/yr

We are currently seeking a Senior AI Engineer - Remote to join our team in Toronto, Ontario (CA-ON ... security, connectivity, data centers and application services. Our consulting and industry ...

Senior AI Engineer - Remote

Toronto, ON · On-site +1

CA$147K - CA$245K/yr

We are currently seeking a Senior AI Engineer - Remote to join our team in Toronto, Ontario (CA-ON ... security, connectivity, data centers and application services. Our consulting and industry ...

This leader will own the data security engineering pillar, with accountability for data ... This role is remote-friendly within North America. For those who prefer in-office or hybrid work ...

Security Design * Queueing * Automated testing * Continuous integration tools * Server ... However, we will consider remote applicants +/- 3 hours from eastern time zone. Why work here * We ...

Security Design * Queueing * Automated testing * Continuous integration tools * Server ... However, we will consider remote applicants +/- 3 hours from eastern time zone. Why work here * We ...

This is a great opportunity to anchor a growing team, work with top notch security and engineering ... US Remote - 164,000 - 237,000 USD per year * Austin, Metro Area 164,000 - 237,000 USD per year

Azure Cloud Engineer

Toronto, ON · Remote

CA$58K - CA$96K/yr

Remote Reference code: 133824 Primary Location: Toronto, ON All Available Locations: Toronto, ON ... Design and deploy Azure services, ensuring compliance with best practices for security, scalability ...

New

next page

Showing results 1-20

Offensive Security Engineer Remote information

What is the difference between Offensive Security Engineer Remote vs Penetration Tester?

AspectOffensive Security Engineer RemotePenetration Tester
CertificationsOSCP, OSWE, CEHOSCP, CEH, GPEN
Work EnvironmentRemote, collaborative security teamsOften client-site or remote assessments
Industry UsageSecurity teams, cybersecurity firmsConsulting firms, security assessments
Search & Comparison IntentUnderstanding roles, skills, and remote opportunitiesJob scope, certifications, and remote work options

Offensive Security Engineer Remote and Penetration Tester roles share overlapping skills and certifications like OSCP and CEH. However, Offensive Security Engineers typically work within security teams on ongoing security infrastructure, often remotely, focusing on offensive security strategies. Penetration Testers usually perform specific security assessments, sometimes on-site, and may have a broader consulting focus. Both roles are vital in cybersecurity but differ in scope and work environment.

What are the key skills and qualifications needed to thrive as an Offensive Security Engineer (Remote), and why are they important?

To thrive as an Offensive Security Engineer (Remote), you need strong expertise in penetration testing, vulnerability assessment, and cybersecurity principles, often supported by a degree in computer science or a related field. Familiarity with tools like Metasploit, Burp Suite, and Kali Linux, as well as certifications such as OSCP or CEH, is typically required. Attention to detail, problem-solving skills, and effective written communication are critical soft skills for success in this role. These abilities are essential for identifying vulnerabilities, reporting findings clearly, and helping organizations strengthen their security posture against evolving threats.

What are some common challenges faced by remote Offensive Security Engineers, and how can they be addressed?

Remote Offensive Security Engineers often face challenges such as coordinating effectively with geographically dispersed teams, maintaining secure access to sensitive systems, and staying updated on rapidly evolving threat landscapes. Overcoming these hurdles typically involves strong communication skills, leveraging secure collaboration tools, and establishing regular check-ins with colleagues. Additionally, continuous learning through online resources and industry forums is vital to remain effective and proactive in identifying and addressing security vulnerabilities.

What does an Offensive Security Engineer do, especially when working remotely?

An Offensive Security Engineer is responsible for proactively identifying and mitigating security vulnerabilities in an organization’s systems, networks, and applications. Working remotely, they perform penetration testing, vulnerability assessments, and simulated cyberattacks to discover weaknesses before malicious actors can exploit them. They also provide detailed reports and recommendations to help organizations improve their overall security posture. Remote Offensive Security Engineers use a variety of tools and collaborate with other security professionals to ensure effective communication and secure operations across distributed environments.
What are popular job titles related to Offensive Security Engineer Remote jobs in Toronto, ON? For Offensive Security Engineer Remote jobs in Toronto, ON, the most frequently searched job titles are:
What job categories do people searching Offensive Security Engineer Remote jobs in Toronto, ON look for? The top searched job categories for Offensive Security Engineer Remote jobs in Toronto, ON are:
Infographic showing various Offensive Security Engineer Remote job openings in Toronto, ON as of July 2026, with employment types broken down into 94% Full Time, 3% Part Time, and 3% Contract. Highlights an 86% Physical, 7% Hybrid, and 7% Remote job distribution.

Senior Cloud Security Engineer (Remote Canada)

Smile Digital Health

Toronto, ON • Remote

Full-time

Medical, Life, Retirement, PTO

Posted 12 days ago


Job description

Working for a company like Smile Digital Health means supporting our mandate for #BetterGlobalHealth. We strive towards this goal every day, and the results can be seen in the impact of our innovative health data platform and data management solutions, which are used in over 20 countries. We were #19 on Deloitte's Technology Fast 50 Ranking for 2024! 
 
Smile Digital Health makes it easy for healthcare stakeholders to collect and exchange data with our leading FHIR-based data liberation platform.
 
At its heart, the Smile platform enables people and organizations to better manage healthcare data. We help generate and liberate structured healthcare data to ensure effective delivery across care teams and health systems bringing  #BetterGlobalHealth to patients everyday!

Apply today and find plenty of reasons to SMILE!

The Senior Cloud Security Engineer is responsible for designing, automating and deploying production grade services on behalf of the customers to a variety of clouds such as AWS, Azure, OCI and GCP.
 
This role combines strategic security architecture with hands-on operational execution owning cloud security posture management (CSPM), threat detection and response, application security testing (SAST/DAST), and RBAC governance. The successful candidate works closely with DevOps, Platform Engineering, and Development teams to embed security throughout the software delivery lifecycle and ensure all environments meet healthcare-grade compliance requirements
Responsibilities:
  • Design, implement, and continuously improve cloud security architecture and controls across Azure-based environments.
  • Lead threat modelling, vulnerability assessments, and security architecture reviews for cloud-native and hybrid infrastructure.
  • Own and operate cloud security posture management (CSPM) using Prisma Cloud - configure policies, monitor posture, triage findings, and drive remediation with engineering teams.
  • Deploy, tune, and manage Microsoft Defender for Cloud (and related Defender suite products) across Azure subscriptions; investigate alerts and drive incident response.
  • Integrate SAST and DAST tooling into CI/CD pipelines; triage findings, define severity thresholds, and partner with developers to close vulnerabilities prior to production release.
  • Own the RBAC governance process: design role models, conduct periodic access reviews, enforce least-privilege principles, and document role assignments across Azure and application layers.
  • Collaborate with DevOps and Platform Engineering teams to embed security controls (secrets management, image scanning, policy-as-code) into DevOps pipelines and IaC workflows (Terraform, Ansible).
  • Act as SME for security compliance frameworks relevant to healthcare data (SOC 2, HIPAA, ISO 27001, PHIPA/PHIPPA); map controls and support audits.
  • Provide Level 3 escalation for security incidents; participate in on-call rotation for incident response and forensic triage.
  • Lead and educate internal teams and clients on cloud security best practices, secure-by-design patterns, and zero-trust principles.
  • Document security runbooks, post-incident reviews, threat models, and lessons learned; maintain a living security knowledge base.
  • Ensure all working hours are accurately reported in the Time tracking system; the majority of hours are expected to be billed to client engagements.
  • Comply with all privacy, security, and confidentiality policies; hold all PHI and confidential information in strict confidence throughout and after employment.
Requirements :
  • 7+ years of hands-on experience in cloud security, with the majority of that experience focused on Microsoft Azure (Azure Security Center, Azure Policy, Azure AD / Entra ID, Key Vault, NSGs, Private Endpoints, Defender for Cloud).
  • Proven, production-level experience with Prisma Cloud (CSPM/CWPP) - policy management, alert triage, and remediation workflows.
  • Hands-on experience with Microsoft Defender for Cloud and the broader Microsoft Defender suite (Defender for Servers, Containers, Identity, Endpoint).
  • Practical experience implementing and operating SAST and DAST tools (e.g., MEND, SonarQube,GitHub Advanced Security,  OWASP ZAP, Burp Suite) within CI/CD pipelines.
  • Deep familiarity with DevOps pipeline security securing GitHub Actions / Azure DevOps pipelines, secrets management (Azure Key Vault, HashiCorp Vault), container image scanning, and supply-chain security.
  • Strong RBAC design and governance experience, building and enforcing role models, access review processes, and least-privilege controls across Azure and multi-tier application stacks.
  • Solid IaC experience with Terraform and/or Ansible; ability to write and review security-hardened infrastructure code.
  • Experience with Kubernetes / OpenShift and container security (runtime protection, admission controllers, image policies).
  • Solid understanding of networking fundamentals as they apply to cloud security: VNets, NSGs, Azure Firewall, Private Link, Zero Trust network segmentation.
  • Demonstrated knowledge of compliance frameworks applicable to healthcare (SOC 2, HIPAA, ISO 27001, PHIPA); experience supporting audits and mapping technical controls.
  • Professional cloud or security certifications preferred (e.g., AZ-500, MS-500, SC-200, CCSP, CISSP, or equivalent).
  • Excellent written and verbal communication skills; ability to convey complex security concepts to both technical and non-technical stakeholders
$130,000 - $145,000 a year
Smile discloses that artificial intelligence (AI) may be used in portions of the recruitment and selection process, such as resume screening or application assessment. All hiring decisions are ultimately made by qualified human decision-makers, and AI tools are used to support - not replace - fair and equitable hiring practices. 
This position is a new role, created to support Smile's continued growth and commitment to operational excellence.

Some of the benefits we offer:
* Remote Work Environment
* Flexible Time Away From Work Policy including PTO, Personal and Sick Days
* Competitive Salary and Health/Medical Benefits
* RRSP/TFSA/401K Employee Contribution
* Life and Disability
* Employee Assistance Program
* FHIR Study Program and Skillsoft Learning
* Super HAPI Fun Club

Smile's core values include respect, inclusion, embracing our differences, and celebrating shared values because our people are the foundation of our success. We are big on creating a sense of belonging and empowering each other to bring our authentic selves to work.  We are dedicated to fostering a workplace that values diversity, equity, and inclusion.
 
We welcome and encourage candidates of all backgrounds to apply. Candidates are encouraged to inform us if they wish to discuss or require accommodations during interviews or while working at Smile.
We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
apply for this job