1

Security Engineer Jobs in Toronto, ON (NOW HIRING)

Position Summary League's security engineering team is responsible for scaling security across the development lifecycle. We believe in security by design and follow a paved-road philosophy: we build ...

Security Engineer Advantage Group International is seeking a Security Engineer to join our Technology team. This is a unique opportunity to build and shape our security posture from the ground up.

Security Engineer

Toronto, ON · On-site

CA$130K - CA$140K/yr

Security Engineer Advantage Group International is seeking a Security Engineer to join our Technology team. This is a unique opportunity to build and shape our security posture from the ground up.

The Cloud Security Engineer is responsible for researching, deploying, and maintaining security technologies that support our defense-in-depth strategy in accordance with TMX regulations and ...

The Opportunity We're looking for a Staff Security Engineer to join Fullscript's Security Engineering team as a senior technical leader and hands-on builder. This role is ideal for someone who ...

Job Summary We are seeking a Security Engineer with deep expertise in Snyk, DevSecOps, and security platform engineering to drive enterprise-wide migration, integration, and optimization of Snyk and ...

New

The Cloud Security Engineer is responsible for researching, deploying, and maintaining security technologies that support our defense-in-depth strategy in accordance with TMX regulations and ...

We are looking for a Senior Security Engineer to own and mature our security function across product, infrastructure, operations, and governance. This is a senior individual contributor role for ...

Posted today

Security today is shared across Engineering and DevOps. You'll work closely with both teams and have real room to shape how Forma approaches security as we grow. Depending on your interests and the ...

The Cloud Security Engineer, Cloud Security Engineering will be responsible for providing technical delivery of solutions within a diverse team of cloud security engineers, deploying cutting edge ...

The Cloud Security Engineer, Cloud Security Engineering will be responsible for providing technical delivery of solutions within a diverse team of cloud security engineers, deploying cutting edge ...

Engineering background with experience in architecture, design, and development. * Experience related to cybersecurity, including deployment of security technologies. * Hands-on experience with ...

Posted today

Security Engineer

Richmond Hill, ON · On-site

CA$100K - CA$130K/yr

We're hiring a SOC Engineer! Are you an Elastic SIEM expert with a passion for threat detection and ... Investigate security incidents using log data to identify threats and vulnerabilities. * Respond to ...

New

The Senior Security Engineer, Security Solutions Engineering will be responsible for providing senior technical leadership as a hands-on developer and solution designer, building secure full-stack ...

We're looking for a Senior Cloud Security Engineer II to join our Security Engineering function as a senior individual contributor and technical leader for cloud security. This is a step up from our ...

As a Senior Security Engineer you will: * Serve as trusted advisor to team's leadership and partner teams by clearly articulating business risks associated with security issues * Lead security ...

The Opportunity As a Senior Security Engineer, you will be a hands-on technical leader strengthening security across Forma's application, cloud infrastructure, development lifecycle, internal systems ...

New

As a Senior Security Engineer you will: * Serve as trusted advisor to team's leadership and partner teams by clearly articulating business risks associated with security issues * Lead security ...

New

next page

Showing results 1-20

Security Engineer information

What is a security engineer?

A service provider is responsible for delivering professional quality services on behalf of a business or organization. The types of services vary depending on the businesses they work with. Many companies partner with experts in the local community to perform functions on their behalf rather than developing the expertise in-house. A service provider performs the services based on a written legal agreement and charges fees for their work.

How does a security engineer typically collaborate with other IT teams within an organization?

Security Engineers work closely with various IT teams such as network administrators, software developers, and system administrators to ensure security protocols are integrated at every level. This collaboration often involves conducting security assessments, reviewing code for vulnerabilities, and assisting with incident response. Regular meetings and cross-functional projects are common, as Security Engineers provide guidance on best practices and help teams understand potential threats. Effective communication and teamwork are key, as security is a shared responsibility across the organization.

What are the key skills and qualifications needed to thrive as a Security Engineer, and why are they important?

To thrive as a Security Engineer, you need expertise in information security principles, network architecture, vulnerability assessment, and commonly a degree in computer science or a related field. Familiarity with tools like SIEM systems, firewalls, intrusion detection/prevention systems, and certifications such as CISSP or CEH are typically required. Strong problem-solving skills, attention to detail, and effective communication set outstanding Security Engineers apart. These competencies are essential to proactively protect organizations from cyber threats, ensure compliance, and minimize security risks.

What is the difference between Security Engineer vs Network Security Specialist?

AspectSecurity EngineerNetwork Security Specialist
Required CertificationsCompTIA Security+, CISSP, CEHCompTIA Security+, Cisco CCNA Security, CISSP
Work EnvironmentDesigning, implementing, and maintaining security systems across IT infrastructureMonitoring, analyzing, and securing network traffic and infrastructure
Employer & Industry UsageTech companies, finance, government agenciesTelecommunications, enterprise networks, cybersecurity firms

Security Engineers focus on developing and deploying security solutions across IT systems, while Network Security Specialists concentrate on protecting network infrastructure and traffic. Both roles require similar certifications and often work together to ensure comprehensive security.

Do security engineers need a degree?

Security engineers typically do not require a formal degree but often benefit from a background in computer science, information technology, or related fields. Many employers value certifications such as CISSP, CEH, or Security+ and practical experience with security tools and protocols. Continuous learning and hands-on skills are important in this role.

How much do security engineers earn?

Security engineers typically earn a median annual salary ranging from $90,000 to $130,000, depending on experience, location, and certifications such as CISSP or CEH. Entry-level positions may start lower, while experienced professionals with specialized skills can earn over $150,000 annually.

What do you do as a security engineer?

A security engineer designs, implements, and maintains security systems to protect an organization’s networks, systems, and data from cyber threats. They analyze vulnerabilities, develop security protocols, and often use tools like firewalls, intrusion detection systems, and encryption. Certifications such as CISSP or CEH can enhance their effectiveness in this role.

What are the most commonly searched types of Security Engineer jobs in Toronto, ON?

The most popular types of Security Engineer jobs in Toronto, ON are:

What are popular job titles related to Security Engineer jobs in Toronto, ON?

For Security Engineer jobs in Toronto, ON, the most frequently searched job titles are:

What job categories do people searching Security Engineer jobs in Toronto, ON look for?

The top searched job categories for Security Engineer jobs in Toronto, ON are:

Infographic showing various Security Engineer job openings in Toronto, ON as of September 2026, with employment types broken down into 85% Full Time, 13% Part Time, and 2% Contract. Highlights an 87% Physical, 2% Hybrid, and 11% Remote job distribution.

Security Engineer

Toronto, ON • On-site

Full-time

Posted 17 days ago


Key responsibilities

  • Conduct security reviews of product features, integrations, and platform changes, documenting resulting security requirements

  • Participate in threat modeling exercises to identify risks in system design and data flow

  • Automate manual review efforts and embed security checks into the SDLC


Job description

Position Summary

League's security engineering team is responsible for scaling security across the development lifecycle. We believe in security by design and follow a paved-road philosophy: we build or buy tooling that integrates into our platform so it is easier for engineers to do the right thing than the wrong thing. Security is everyone's responsibility, and security engineering is how we make it possible for engineers to ship high-quality code to production several times a day with security built in.

This role is an intermediate security engineer who splits their time between engagement work and engineering work. On the engagement side you will run security reviews for new product work, contribute to technical deep dives on existing systems, assess vendors before they are approved for use, and review third-party vendors that handle League customer data. On the engineering side you will write code and engage with tooling and systems: automation that removes manual review steps, checks that run in our pipelines, and tooling that makes findings easier to route, track and close.

League ships AI-enabled features and our engineers work with AI-assisted development tooling daily. Reviewing those systems, and reasoning about the security of code and fixes that AI produces, is a standing part of this role rather than a specialty.

You will bring some experience with threat modeling and cloud architecture to meaningfully contribute to secure design practices, while senior engineers and architects own the broader security strategy. You think in systems and processes, which is how you will find the second-order, long-term fix rather than the quick, most immediate one. You share what you learn, and you can explain risk clearly to a software engineer and to infrastructure leadership in the same week.

We welcome new ideas and encourage diverse experience, in every meaning of the word - if you have a unique background, deep interests in a niche topic of security or engineering, or some experience that brings new approaches to security and engineering, this is a strength that we welcome on the team. While this summary outlines the main job responsibilities, it is by no means exhaustive - we are a fast-moving organization, and change can happen quickly here, especially when it raises the bar of security for League and our customers. So, bring your ideas, your unique insights, and challenge the norm. We will be better for it.

What You will do:
  • Conduct security reviews of product features, integrations, and platform changes, documenting resulting security requirements
  • Participate in threat modeling exercises to identify risks in system design and data flow
  • Perform security assessments of applications, APIs, and cloud configuration, and provide remediation guidance engineering teams can act on
  • Review AI-enabled product features for prompt injection, excessive agency and unintended exposure of member data
  • Triage and score security findings, and drive remediation with the owning teams
  • Own the configuration, tuning, and triage workflow for security tooling
  • Automate manual review efforts and embed security checks into the SDLC
  • Build training materials and documentation on secure coding practices and common vulnerabilities; regularly share knowledge with peers
  • Support League's shift left by contributing reusable security controls to our paved road so that common vulnerabilities are prevented by default
  • Contribute to the development and maintenance of League's security standards and internal documentation.
  • Conduct security reviews of third-party vendors that process or store League data, and support customer security assurance requests.
  • Support SOC 2 Type II, HITRUST, HIPAA, and PHIPA control design, testing, and evidence gathering in partnership with the Privacy and Compliance team.
  • Communicate risk findings clearly to different audiences, adapting language and level of detail for engineers versus leadership.

What You Bring

  • 2+ years of professional experience in application or product security, or in software engineering with substantial security responsibility
  • Ability to find what scanners miss: broken access control, tenant isolation failures, business logic flaws
  • Working knowledge of authentication and authorization in modern applications, including OAUTH 2.0 / OIDC, session and token handling, and role or attribute-based access control
  • Familiarity with CI / CD and software supply chain security, including pipeline-integrated testing, dependency management, and secrets handling
  • Solid working knowledge of common application vulnerabilities (e.g., OWASP Top 10) and their mitigations
  • Experience with AI and LLM application security, including prompt injection, agentic tool-use risk and retrieval pipeline exposure
  • Some exposure to cloud security concepts and secure cloud architecture, ideally GCP, including containerized workloads.
  • A track record of writing and shipping code other people rely on, in Python, Go, or a comparable language
  • Some experience with threat modeling methodologies (e.g. STRIDE)
  • General awareness of SOC 2 Type II, HITRUST, HIPAA and PIPEDA

Nice-to-have

  • Experience handling PHI or comparably  sensitive data in a regulated environment.
  • Exposure to incident response.
  • Self-driven security work: side projects, CTFs, published research, or a coordinated disclosure history

Security-Related Responsibilities

  • Ensure access management is performed in compliance with the employee's role and responsibilities
  • Responsibility and accountability for executing League's policies and procedures within the department/ team
  • Notification of HR, Legal, Compliance & Security of any incidents, breaches or policy violations
  • Compliance with Information Security Policies