← Back to job listings
WE
Senior Security Developer (Vulnerability Management)
Wealthsimple · Canada
About The Role
Join our team as a Senior Security Developer focused on Vulnerability Management. In this role, you will design automations, integrations, and workflows to enhance our vulnerability management platform. You will work on deployment, integrations, data model, and automation workflows, and build automation across the full VM lifecycle. You will also integrate scanner data into our VM pipeline, build queries and dashboards, and stay current on the threat landscape. This is a greenfield opportunity to shape the future of our VM platform.
- Concevoir et mettre en œuvre des automatisations, des intégrations et des flux de travail pour améliorer la gestion des vulnérabilités.
- Posséder et faire évoluer la plateforme de gestion des vulnérabilités personnalisée, en travaillant sur le déploiement, les intégrations, le modèle de données et les flux de travail d'automatisation.
- Construire des automatisations tout au long du cycle de vie de la gestion des vulnérabilités : triage, routage des tickets, suivi des SLA, résolution de la propriété et suivi.
- Understands the difference between package and library vulnerabilities well enough to know where a fix actually belongs, and understands vulnerability classes across application and infrastructure layers (XSS vs. CSRF, code vs. container issues) well enough to have a real conversation with a developer who disagrees with a finding. Knows which scanners belong at which stage of the pipeline (CI, production, network) and how a vulnerability actually ends up running in production, including in containers. Hands-on exposure to SAST/DAST/SCA tooling and OWASP fundamentals helps here
- Can translate business and partner needs into solutions. You'll spend real time with developers who don't understand a finding, disagree with it, or say a fix didn't work, and you need to work through that without losing the thread
- Has 4+ years of hands-on vulnerability management and/or security engineering experience, including scanner integration, triage workflows, and remediation tracking. If vulnerability management isn't explicitly on your resume, you should be able to explain clearly why you understand it anyway
- Has a strong understanding of the programs vulnerability management connects to: CI/CD and deployment pipelines, threat intelligence, and bug bounty or responsible disclosure programs. VM doesn't operate in a vacuum, and we want someone who understands the connections that exist today and the ones that should exist but don't yet
- Is familiar with the software development lifecycle end to end, well enough to recognize where a vulnerability was actually introduced in the process and to tell when an AI tool is hallucinating a finding instead of catching a real one
- Has deep familiarity with VM tooling (Tenable, Semgrep, Rapid7, or comparable scanners) and knows how to build integrations on top of them via API
- Has a strong automation-first mindset. You've built things that replace manual processes
- Is familiar with different compliance programs and vulnerability management controls
- Has hands-on familiarity with GitHub Actions, ArgoCD, Kubernetes, AMIs, and container images (ECR or comparable). You'll need this to help maintain our VM platform, and because each of these carries its own patch management burden since they all run code
- Understands attack surface and exposure management, including how a basic web app's architecture and traffic flow map to real risk. You'll be making risk acceptance calls, and that requires seeing the actual exposure, not just a CVE score
- Is actively using AI-assisted development workflows (Claude Code, Cursor, Copilot, or similar) and treats them as a force multiplier, not a novelty
- Has production AWS experience
- Experience with security orchestration platforms (Tracecat, Tines, XSOAR, or comparable)
- Experience with bug bounty or responsible disclosure programs like HackerOne
- Familiarity with vulnerability scoring and prioritization frameworks (CVSS, EPSS, SSVC). This is quick to pick up on the job, so it's weighted lower than the items above
- Experience in a fintech or regulated-industry environment
- Open-source security tooling contributions
Similar roles you might like
See all →V
Medium Voltage Transformer Specialist
versysgroup
Salary not disclosedPosted today
V
Relay/Protection & Control Specialist
versysgroup
Salary not disclosedPosted today
V
Medium Voltage Cable Termination Technician
versysgroup
Salary not disclosedPosted today
E
Intermediate Software QA Developer
Edel
C$83,000 – 102,000/yrPosted today
E
Cloud Security Specialist
Edel
C$119,000 – 136,000/yrPosted today
TC
Opérateur de machine - Soir
Tremco CPG Inc.
Salary not disclosedPosted today
E
School Sport & Recreation Coordinator
eskasonischoolboard
Salary not disclosedPosted today
I
Manager, Marketing & Communications
innfromthecold
Salary not disclosedPosted today
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
