1

Senior Security Engineer Jobs in Ontario (NOW HIRING)

The Opportunity As a Senior Security Engineer, you will be a hands-on technical leader strengthening security across Forma's application, cloud infrastructure, development lifecycle, internal systems ...

... Senior Physical Security Consultant with experience leading risk-based physical security system ... Resourcing and project management of a team of physical security consultants and engineers working ...

We're looking for a Senior Cloud Security Engineer II to join our Security Engineering function as a senior individual contributor and technical leader for cloud security. This is a step up from our ...

The Senior Security Analyst is accountable for Support Safety and Security Organization for the ... Bachelor'sdegree in Security, Engineering or Technical/Physical Science Desired Skills/ Knowledge

This leader will own the data security engineering pillar, with accountability for data ... The Senior Manager will partner closely with peer leaders across IAM, Network, SaaS, and Endpoint ...

TheProduct Security Managerleads our Product Security Core team, a group of senior engineers responsible for scaling security across Thomson Reuters' product portfolio. In this role, you will own the ...

League is looking for a Principal Security Engineer to serve as the senior technical leader within our Security Engineering organization. This role entails designing and driving security architecture ...

CA$137K - CA$189K/yr

We are hiring a Senior Software Engineer to join our Server Security team. The Server Security team is a development-focused group within MongoDB's core engineering organization. Operating "close to ...

The role is suited to a senior engineer with deep expertise in AI/ML security, modern software engineering, and secure-by-design approaches. You will champion secure architectures, embed DevSecOps ...

The role is suited to a senior engineer with deep expertise in AI/ML security, modern software engineering, and secure-by-design approaches. You will champion secure architectures, embed DevSecOps ...

The role is suited to a senior engineer with deep expertise in AI/ML security, modern software engineering, and secure-by-design approaches. You will champion secure architectures, embed DevSecOps ...

next page

Showing results 1-20

Senior Security Engineer information

See Ontario salary details

$58K

$130.5K

$184.5K

How much do senior security engineer jobs pay per year?

As of Aug 29, 2026, the average yearly pay for senior security engineer in Ontario is $130,454.00, according to ZipRecruiter salary data. Most workers in this role earn between $110,500.00 and $146,500.00 per year, depending on experience, location, and employer.

What skills and qualifications are needed to be a senior security engineer?

To thrive as a Senior Security Engineer, you need deep expertise in network security, risk assessment, incident response, and a relevant degree or equivalent experience. Familiarity with security tools such as SIEM platforms, firewalls, IDS/IPS, and certifications like CISSP or CEH are typically required. Strong analytical thinking, effective communication, and leadership abilities help you excel in complex security environments. These skills and qualifications are crucial to safeguard organizational assets and maintain robust defense against evolving cyber threats.

How does a senior security engineer collaborate with other departments to enhance organizational security?

Senior Security Engineers frequently work cross-functionally, partnering with IT, software development, and compliance teams to implement security best practices and respond to incidents. They play a key role in conducting security reviews, advising on secure design, and leading incident response efforts. Effective communication and collaboration are essential, as these engineers often translate technical risks into business terms and provide guidance during audits or vulnerability assessments. This collaborative approach helps ensure comprehensive protection across all organizational assets.

What is the difference between Senior Security Engineer vs Security Analyst?

AspectSenior Security EngineerSecurity Analyst
Required CredentialsCertifications like CISSP, CISA, CEH; Bachelor's or Master's in Cybersecurity or related fieldsCertifications like CompTIA Security+, GIAC Security Essentials; Bachelor's in Cybersecurity, Information Technology, or related fields
Work EnvironmentDesigning security systems, implementing security measures, leading security projectsMonitoring security alerts, analyzing threats, conducting security assessments
Employer & Industry UsageUsed in tech companies, finance, healthcare for security infrastructure rolesCommon in various industries for threat detection and incident response

The main difference is that Senior Security Engineers focus on designing and implementing security solutions, while Security Analysts primarily monitor and analyze security threats. Both roles require relevant certifications and work in similar environments, but their responsibilities differ in scope and focus.

What are the most commonly searched types of Security Engineer jobs in Ontario?

The most popular types of Security Engineer jobs in Ontario are:

What job categories do people searching Senior Security Engineer jobs in Ontario look for?

The top searched job categories for Senior Security Engineer jobs in Ontario are:

What cities in Ontario are hiring for Senior Security Engineer jobs?

Cities in Ontario with the most Senior Security Engineer job openings:

Infographic showing various Senior Security Engineer job openings in Ontario as of August 2026, with employment types broken down into 78% Full Time, and 22% Contract. Highlights an 80% In-person, and 20% Remote job distribution, with an average salary of $130,454 per year, or $62.7 per hour.

Senior Security Engineer

Toronto, ON โ€ข On-site

Full-time

Posted 17 days ago


Job description

The Opportunity

As a Senior Security Engineer, you will be a hands-on technical leader strengthening security across Forma's application, cloud infrastructure, development lifecycle, internal systems, and incident-response practices.

Security today is shared across Engineering and DevOps. You'll work closely with both teams and have real room to shape how Forma approaches security as we grow. Depending on your interests and the needs of the business, the role could develop into a deeper individual-contributor position or help build a dedicated security team.

You'll work directly with Engineering, DevOps, IT, Product, Legal, and Privacy to identify risks, design practical controls, automate security processes, and help teams ship secure and reliable software.

What you'll doCloud and infrastructure security
  • Design and implement security controls across Forma's AWS environments, with a focus on IAM, least-privilege access, service identities, and account boundaries.
  • Embed security requirements into Terraform and other Infrastructure as Code, and improve secrets, certificate, encryption-key, and credential management.
  • Build automated checks for insecure configurations, excessive permissions, exposed resources, and configuration drift across Kubernetes, containers, serverless workloads, networking, and data services.
Application, data, and AI security
  • Run threat modelling and security architecture reviews for new products, services, APIs, data pipelines, and third-party integrations.
  • Strengthen tenant isolation, authorization enforcement, and fine-grained data access controls at the schema, table, row, and column level.
  • Help protect sensitive compensation, financial, customer, and employee data across databases, data warehouses, S3, analytics services, and internal tools, including logging and auditability for sensitive-data access.
  • Review AI and agentic workflows for data leakage, prompt injection, insecure tool use, and excessive permissions; ensure agents operate strictly within the calling user's permissions; and define secure patterns for approved services such as Amazon Bedrock.
  • Identify and help remediate application vulnerabilities, and build tooling and reusable libraries that make the secure path the easy one for engineers.
DevSecOps and secure delivery
  • Embed security testing into CI/CD - static analysis, dependency and container scanning, secrets detection, Infrastructure as Code scanning, and dynamic testing - without creating unnecessary friction for developers.
  • Define practical vulnerability-severity, remediation, exception, and escalation standards, and partner with developers to separate real risk from noise and fix root causes.
  • Improve software supply-chain security, including build permissions, artifact integrity, dependency governance, and GitHub administration.
Detection, monitoring, and incident response
  • Improve security visibility across cloud infrastructure, applications, identities, endpoints, and SaaS systems, and build alerts and detection logic that are worth acting on.
  • Lead investigations and coordinate containment, remediation, and root-cause analysis, supported by clear runbooks, ownership, and escalation paths.
  • Run tabletop exercises, and track and communicate security metrics and material risks to technical and business stakeholders.
Identity, governance, and enablement
  • Strengthen SSO, MFA, privileged access, and onboarding, offboarding, and access-review processes across AWS, GitHub, Microsoft 365, Entra ID, production systems, and internal SaaS - automating provisioning, entitlement reviews, and evidence collection where practical.
  • Translate security and compliance requirements into concrete technical controls, and support customer security reviews, audits, and programs such as SOC 2 and ISO 27001.
  • Evaluate third-party tools and integrations for security, privacy, and access-control risk, and help select, consolidate, and rationalize Forma's security tooling for both coverage and cost.
  • Maintain clear technical standards and provide practical guidance, training, and mentorship that raises security capability across Engineering.
What we're looking for
  • Six or more years of experience in security engineering, cloud security, application security, DevSecOps, or infrastructure engineering.
  • Strong hands-on experience securing AWS environments, including IAM, networking, encryption, logging, and secrets management.
  • Experience with Terraform, Kubernetes, containers, and security controls in CI/CD pipelines.
  • Strong understanding of application and API security, authentication, authorization, and multi-tenant SaaS risks.
  • Experience with vulnerability management, threat modelling, incident response, and security automation.
  • Ability to write scripts using Python, Bash, PowerShell, or a similar language.
  • Strong communication, troubleshooting, and cross-functional collaboration skills.

Strongly preferred

  • Experience supporting SOC 2, ISO 27001, privacy programs, or enterprise customer security reviews.
Nice to have
  • Experience securing analytics platforms, data pipelines, or systems handling sensitive customer data, including row-level, column-level, or attribute-based access controls.
  • Experience with AWS security services, EKS, Datadog, Wiz, Snyk, CrowdStrike, or similar tools.
  • Experience securing AI applications, large language models, agents, or Amazon Bedrock workloads.
  • Experience in a B2B SaaS or high-growth technology company.
  • Relevant security or cloud certifications.
Your first 30, 60, and 90 daysFirst 30 days: learn and assess
  • Build an understanding of Forma's application architecture, AWS environments, deployment processes, data flows, identity systems, and security obligations.
  • Meet key partners across Engineering, DevOps, IT, Product, Legal, and Privacy, and agree on how security reviews and escalations will operate.
  • Review existing controls, open findings, incidents, access patterns, monitoring, and compliance commitments.
  • Identify immediate risks, quick wins, and areas needing deeper assessment.
By 60 days: prioritize and improve
  • Deliver a prioritized security roadmap based on risk, business impact, and engineering effort.
  • Begin addressing the highest-priority gaps in cloud access, secrets management, CI/CD security, vulnerability management, and monitoring.
  • Introduce or improve a consistent process for threat modelling and security architecture reviews, and define vulnerability-severity, ownership, remediation, and exception standards.
  • Assess the current security tool stack for coverage, overlap, and cost, with consolidation recommendations.
  • Improve incident-response runbooks, alert ownership, and escalation paths for critical systems, and recommend measurable security objectives and reporting metrics.
By 90 days: operationalize and lead

The expectation here is momentum, not completion - these should be underway and demonstrably working, not finished.

  • A first set of automated security guardrails in place across AWS, Terraform, Kubernetes, GitHub, or CI/CD, with remaining coverage planned and underway.
  • Repeatable processes running for vulnerability management, access reviews, security assessments, and incident follow-up, even if still being refined.
  • Security reviews completed for the highest-priority product, data, or AI initiatives, with required controls agreed and in progress.
  • Improved visibility into high-risk identities, infrastructure changes, and sensitive-data access.
  • Progress, key risks, and the next phase of the security roadmap presented to leadership.

Additional Info:

  • This position is for an existing vacancy
  • Salary range: 160-190K