Shakepay13.02.26
AI SCORE 8.5

Staff Security Engineer - Remote Role at Shakepay

$220K/year

About the Role

We are seeking a Staff Security Engineer to join our team at Shakepay, where you will play a crucial role in safeguarding our infrastructure and customer data. This remote Staff Security Engineer position allows you to contribute to our mission of revolutionizing financial services in Canada while working from anywhere in the country.

What You'll Do

  • Design and implement security solutions across product and internal applications.
  • Conduct threat modeling for existing systems and new product initiatives.
  • Partner with engineering teams to embed security into development and delivery workflows.
  • Mentor engineers and share security best practices across the organization.
  • Build, tune, and automate security alerts, detections, and response workflows.
  • Participate in and help lead incident response as part of the on-call rotation.
  • Support governance, compliance, and regulatory efforts (SOC 2, ISO 27001, PCI, etc.).
  • Manage relationships with internal stakeholders and external security vendors.

Requirements

  • 7+ years of experience building and maintaining secure applications, with at least 3 years in a security role.
  • Strong experience in Application Security and best practices.
  • Ability to build and automate tools and processes to scale capacity across Security and Engineering.
  • Experience working in cloud environments (AWS preferred).
  • Hands-on experience with incident response and on-call rotations.
  • Strong communication skills and a clear sense of ownership.

Nice to Have

  • Experience working in fintech, crypto, or other regulated environments.
  • Exposure to product security and influencing product design.
  • Experience with offensive security or vulnerability research.
  • Passion for Artificial Intelligence.
  • Knowledge of Bitcoin and excitement to learn more.
  • Comfort using Git/GitHub for collaboration and process management.

What We Offer

  • Competitive compensation and stock options.
  • Health benefits from day 1, including health and wellness spending accounts.
  • Remote-friendly work environment with optional access to office spaces in Montreal and Toronto.
  • A $2,000 annual budget for courses, certifications, and training.
  • 20 days of vacation per year, with a $1,000 bonus if you use all your vacation.
  • Parental leave top-up to 100% of your salary for 18 weeks.
  • Home office setup including a MacBook and a $1,200 budget for improvements.
  • Option to receive salary in Bitcoin.

Join us as a Staff Security Engineer and help shape the future of money while enjoying a fulfilling career in a fast-paced and innovative environment.

Language Requirements
EnglishC1
BasicIntermediateAdvancedNative
Why This Job8.5 of 10

This Staff Security Engineer role at Shakepay offers a unique opportunity to work remotely while securing innovative financial services. With competitive compensation and a focus on personal growth, it's an attractive position for experienced security professionals.

Salary Range
Required
0/1
Optional
0/1
Bonus
0/1

Who Will Succeed Here

Strong proficiency in AWS security best practices, including IAM policies, VPC security, and CloudTrail logging, to effectively manage and secure cloud infrastructure.

Proactive mindset towards incident response and threat modeling, with hands-on experience in tools like AWS GuardDuty and Splunk for real-time threat detection and response automation.

Deep understanding of compliance frameworks such as PCI DSS and ISO 27001, with the ability to implement security controls that meet regulatory requirements in a fast-paced fintech environment.

Learning Resources

OWASP Application Security Verification Standardguide

Career Path

Staff Security Engineer(Now)Lead Security Architect(2-4 years)Chief Information Security Officer (CISO)(5-7 years)

Market Overview

Market Size 2024
$18.2B
Annual Growth
12.5%
AI Adoption
34%
Investment
+45%
Labour Demand
+30%
Avg Salary
$140K

Skills & Requirements

Required
Application SecurityAWSIncident Response
Growing in Demand
DevSecOpsContainer SecurityCloud Security Posture Management (CSPM)
Declining
Static Application Security Testing (SAST)Traditional Network Security

Domain Trends

Rise of DevSecOps
Integration of security into DevOps processes is increasing, with 70% of organizations reporting improved security posture.
Increased Regulation Compliance
Compliance with regulations like GDPR and CCPA is driving demand for Application Security, with 60% of firms investing more in compliance-related security measures.
Shift to Cloud-Native Security
With 80% of enterprises adopting cloud services, the focus on cloud-native security solutions is paramount, leading to a 50% increase in related job postings.

Industry News

Loading latest industry news...

Finding relevant articles from the last 6 months

All job postings are automatically gathered by algorithms. We do not review or verify listings, be careful when applying and do not sign-in with iCloud or Google services.