Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Security Engineer

Full-time

Forma.ai

About Forma.ai:  


Forma.ai is a Series B startup that's revolutionizing how sales compensation is designed, managed and optimized. We handle billions in annual managed commissions for market leaders like Edmentum, Stryker, and Autodesk. 

Our growth has been fuelled by our passion for fundamentally changing and shaping how companies use sales intelligence to drive business strategy.  

We’re welcoming equally driven individuals who are excited about creating something big! 

The Opportunity


As a Senior Security Engineer, you will be a hands-on technical leader strengthening security across Forma's application, cloud infrastructure, development lifecycle, internal systems, and incident-response practices.

Security today is shared across Engineering and DevOps. You'll work closely with both teams and have real room to shape how Forma approaches security as we grow. Depending on your interests and the needs of the business, the role could develop into a deeper individual-contributor position or help build a dedicated security team.

You'll work directly with Engineering, DevOps, IT, Product, Legal, and Privacy to identify risks, design practical controls, automate security processes, and help teams ship secure and reliable software.

What you'll do


Cloud and infrastructure security



  • Design and implement security controls across Forma's AWS environments, with a focus on IAM, least-privilege access, service identities, and account boundaries.

  • Embed security requirements into Terraform and other Infrastructure as Code, and improve secrets, certificate, encryption-key, and credential management.

  • Build automated checks for insecure configurations, excessive permissions, exposed resources, and configuration drift across Kubernetes, containers, serverless workloads, networking, and data services.

Application, data, and AI security



  • Run threat modelling and security architecture reviews for new products, services, APIs, data pipelines, and third-party integrations.

  • Strengthen tenant isolation, authorization enforcement, and fine-grained data access controls at the schema, table, row, and column level.

  • Help protect sensitive compensation, financial, customer, and employee data across databases, data warehouses, S3, analytics services, and internal tools, including logging and auditability for sensitive-data access.

  • Review AI and agentic workflows for data leakage, prompt injection, insecure tool use, and excessive permissions; ensure agents operate strictly within the calling user's permissions; and define secure patterns for approved services such as Amazon Bedrock.

  • Identify and help remediate application vulnerabilities, and build tooling and reusable libraries that make the secure path the easy one for engineers.

DevSecOps and secure delivery



  • Embed security testing into CI/CD — static analysis, dependency and container scanning, secrets detection, Infrastructure as Code scanning, and dynamic testing — without creating unnecessary friction for developers.

  • Define practical vulnerability-severity, remediation, exception, and escalation standards, and partner with developers to separate real risk from noise and fix root causes.

  • Improve software supply-chain security, including build permissions, artifact integrity, dependency governance, and GitHub administration.

Detection, monitoring, and incident response



  • Improve security visibility across cloud infrastructure, applications, identities, endpoints, and SaaS systems, and build alerts and detection logic that are worth acting on.

  • Lead investigations and coordinate containment, remediation, and root-cause analysis, supported by clear runbooks, ownership, and escalation paths.

  • Run tabletop exercises, and track and communicate security metrics and material risks to technical and business stakeholders.

Identity, governance, and enablement



  • Strengthen SSO, MFA, privileged access, and onboarding, offboarding, and access-review processes across AWS, GitHub, Microsoft 365, Entra ID, production systems, and internal SaaS — automating provisioning, entitlement reviews, and evidence collection where practical.

  • Translate security and compliance requirements into concrete technical controls, and support customer security reviews, audits, and programs such as SOC 2 and ISO 27001.

  • Evaluate third-party tools and integrations for security, privacy, and access-control risk, and help select, consolidate, and rationalize Forma's security tooling for both coverage and cost.

  • Maintain clear technical standards and provide practical guidance, training, and mentorship that raises security capability across Engineering.

What we're looking for



  • Six or more years of experience in security engineering, cloud security, application security, DevSecOps, or infrastructure engineering.

  • Strong hands-on experience securing AWS environments, including IAM, networking, encryption, logging, and secrets management.

  • Experience with Terraform, Kubernetes, containers, and security controls in CI/CD pipelines.

  • Strong understanding of application and API security, authentication, authorization, and multi-tenant SaaS risks.

  • Experience with vulnerability management, threat modelling, incident response, and security automation.

  • Ability to write scripts using Python, Bash, PowerShell, or a similar language.

  • Strong communication, troubleshooting, and cross-functional collaboration skills.

Strongly preferred


  • Experience supporting SOC 2, ISO 27001, privacy programs, or enterprise customer security reviews.

Nice to have



  • Experience securing analytics platforms, data pipelines, or systems handling sensitive customer data, including row-level, column-level, or attribute-based access controls.

  • Experience with AWS security services, EKS, Datadog, Wiz, Snyk, CrowdStrike, or similar tools.

  • Experience securing AI applications, large language models, agents, or Amazon Bedrock workloads.

  • Experience in a B2B SaaS or high-growth technology company.

  • Relevant security or cloud certifications.

Your first 30, 60, and 90 days


First 30 days: learn and assess



  • Build an understanding of Forma's application architecture, AWS environments, deployment processes, data flows, identity systems, and security obligations.

  • Meet key partners across Engineering, DevOps, IT, Product, Legal, and Privacy, and agree on how security reviews and escalations will operate.

  • Review existing controls, open findings, incidents, access patterns, monitoring, and compliance commitments.

  • Identify immediate risks, quick wins, and areas needing deeper assessment.

By 60 days: prioritize and improve



  • Deliver a prioritized security roadmap based on risk, business impact, and engineering effort.

  • Begin addressing the highest-priority gaps in cloud access, secrets management, CI/CD security, vulnerability management, and monitoring.

  • Introduce or improve a consistent process for threat modelling and security architecture reviews, and define vulnerability-severity, ownership, remediation, and exception standards.

  • Assess the current security tool stack for coverage, overlap, and cost, with consolidation recommendations.

  • Improve incident-response runbooks, alert ownership, and escalation paths for critical systems, and recommend measurable security objectives and reporting metrics.

By 90 days: operationalize and lead


The expectation here is momentum, not completion — these should be underway and demonstrably working, not finished.


  • A first set of automated security guardrails in place across AWS, Terraform, Kubernetes, GitHub, or CI/CD, with remaining coverage planned and underway.

  • Repeatable processes running for vulnerability management, access reviews, security assessments, and incident follow-up, even if still being refined.

  • Security reviews completed for the highest-priority product, data, or AI initiatives, with required controls agreed and in progress.

  • Improved visibility into high-risk identities, infrastructure changes, and sensitive-data access.

  • Progress, key risks, and the next phase of the security roadmap presented to leadership.

Additional Info:


  • This position is for an existing vacancy

  • Salary range: 160-190K

What you can expect from us


Meaningful compensation. In addition to your base salary, you’ll join our employee stock ownership plan to further recognize your contributions to Forma.ai ’s success.

Healthcare coverage. We have a full benefits package that includes medical, dental, vision, disability and life insurance, and a paid parental leave program.

Learning and development. Access the resources you want to help you grow in your role by utilizing our $750 yearly training stipend.

Growth. You’ll have a huge opportunity to build a career for yourself and gain the type of experience you’re looking for, whether that’s as an individual contributor or as a people leader.

Our Values:  



  • Work well, together. We’re real. We have kids and pets. Mortgages and student loans. We’re in this together, so no matter how brilliant any one of us is, we always play nice with one another – no exceptions.  

  • Be precise. Be relentless. We believe complacency breeds failure, so we set new goals as quickly as we achieve them. We persist in the face of adversity, learn from our mistakes, and push each other to continuously improve. The status-quo is kryptonite.

  • Love our tech. Love our customers. Our platform solves a very complex problem in a currently underserved market. While everyone at Forma isn’t customer-facing, we’re all customer-focused. Maybe even slightly customer-obsessed. ­ 


Use of AI for Recruitment


Currently, Forma.ai does not use artificial intelligence as part of our recruitment process, specifically but not limited to the screening, filtering and shortlisting of applicants.

Our commitment to you:  


Forma is a proud equal opportunity employer that is committed to creating a diverse and inclusive work environment.   Every effort to accommodate candidates for accessibility will be made upon request. Information received related to accommodations will be addressed confidentially. We know that applying to a new role takes a lot of effort. You're encouraged to apply even if your experience doesn't precisely match the job description. There are many paths to a successful career and we’re looking forward to reading yours.

We thank all candidates for their interest however only qualified applicants will be shortlisted.

Vacancy posted a month ago
Similar jobs that could be interesting for youBased on the Senior Security Engineer in Toronto, ON vacancy
  •  ...customers. Cohere is a team of researchers, engineers, designers, and more, who are passionate...  ...mission and shape the future! As a Senior Security Engineer you will: Serve as trusted...  ...tools are available ~ You understand secure engineering best practices, can... 
    Senior
    Full time
    Work at office
    Remote work
    Flexible hours

    Cohere

    Toronto, ON
    more than 2 months ago
  • $153k - $240.5k per year

     ...self-managed data stores such as MongoDB. We're looking for a Senior Cloud Security Engineer II to join our Security Engineering function as a senior...  ...and review. You'll go especially deep across three areas — secure architecture and threat modeling, detection engineering and... 
    Senior
    Full time
    Internship
    Work at office
    Local area
    Flexible hours

    Braze

    Toronto, ON
    28 days ago
  • $159.1k - $198k per year

     ...Summary League is seeking a Software Security Engineer to join our Security Engineering org and...  ...build tools and workflows that improve secure software delivery, automate security...  ...personal productivity and quality of output Senior ICs / Managers: Integrate AI into team... 
    Senior
    Full time
    Work at office
    Remote work
    Flexible hours

    League

    Toronto, ON
    more than 2 months ago
  •  ...within the Office of the Chief Information Security Officer (OCISO) at Kong. The ideal...  ...develop and track KPIs Collaborate with engineering, product, and business stakeholders to define...  ..., Kong Konnect, enables organizations to secure, manage, accelerate, govern, and monetize... 
    Senior
    Full time
    Work at office

    Kong Company

    Toronto, ON
    more than 2 months ago
  • $125k - $145k per year

     ...About the role: We’re hiring a Senior DevSecOps Engineer with 8–10+ years of experience, deep multi...  ...with the AVP of Corporate Information Security on strategy, mentor and grow the team,...  ...technical strategy across CI/CD, IaC, secure cloud architecture, detection, and compliance... 
    Senior
    Full time
    Work at office
    Remote work
    Relocation
    Monday to friday
    Flexible hours

    Peoples Group 2025

    Toronto, ON
    more than 2 months ago
  • $200k - $295k per year

     ...tools. About The Role The Security Team is responsible for...  ...problems with creativity and an engineering mindset. We work at a company...  ...about how we operate. As a Senior Security Engineer on this team...  ...the practices that keep Sentry secure as we grow: security reviews,... 
    Senior
    Hourly pay
    Full time
    Work at office

    Sentry

    Toronto, ON
    more than 2 months ago
  •  ...We are hiring a Senior Software Engineer to join our Server Security team. The Server Security team is a development-focused group within MongoDB's core engineering...  ...team builds features that enable database users to secure their data globally. You will work on critical... 
    Senior
    Full time
    Remote work
    Worldwide

    Mongodb

    Toronto, ON
    more than 2 months ago
  • $130k - $145k per year

     ...Apply today and find plenty of reasons to SMILE! The Cloud Security Engineer is responsible for designing, automating and deploying...  ...practices and lessons learned. Design, implement and maintain a secure and scalable infrastructure platform. Provide ongoing maintenance... 
    Senior
    Remote job
    Full time
    Flexible hours

    Smile Digital Health

    Toronto, ON
    more than 2 months ago
  • $130.6k - $163.2k per year

     ...side.  Position Summary League’s Security Engineering teams are responsible for scaling security...  ...engineers to do the right thing. As a Senior SecOps Engineer you will care deeply about...  ...Engineering who care about “build it secure” at League, your role is to ensure both... 
    Senior
    Remote job
    Full time
    Work at office
    Flexible hours
    Night shift

    League

    Toronto, ON
    14 days ago
  •  ...The Opportunity We're looking for a Staff Security Engineer to join Fullscript's Security Engineering team as a senior technical leader and hands-on builder. This role...  ...design and implementation; Understands how to build secure, scalable solutions in production environments.... 
    Senior
    Long term contract
    Full time
    Remote work
    Flexible hours

    Fullscript

    Toronto, ON
    more than 2 months ago
  •  ...looking for contract Sr. Network Engineer, details are as below:...  ...Winnipeg Role Title: Sr Network Security Engineer (8yr +), CL 18 Work...  ..., endpoint protection, and secure web gateway Attention to detail...  ...What you will do The Senior Network Security Engineer is responsible... 
    Senior
    Remplacement
    Permanent employment
    Full time
    Contract work
    Part time
    For contractors
    Work at office
    Shift work
    3 days per week

    Strategize It

    Toronto, ON
    a month ago
  • $110k - $150k per year

     ...company, we’d love to hear from you! We are looking for a Security Engineer to join our IT Team! Reporting to the Associate Director, IT,...  ...for information security programs and initiatives.  As a senior individual contributor, you will collaborate closely with the... 
    Senior
    Remote job
    Full time
    Work at office
    Home office
    Flexible hours
    Weekend work

    Zensurance

    Toronto, ON
    more than 2 months ago
  • $114k - $164k per year

     ...Work ®, seven years in a row! As a Senior Infrastructure Security Specialist , you will play a key...  ...response. You will work closely with IT, Engineering, Operations, and other business teams...  ...Kepler's infrastructure remains secure and resilient as the organization continues... 
    Senior
    Full time
    Contract work
    Internship
    Work at office
    Remote work
    Relocation package

    Kepler Communications Inc.

    Toronto, ON
    18 days ago
  •  ...independent retailers and brands. Security here isn't a compliance...  ...automation that lets product engineers build securely by default, without...  ...engineering teams to develop and deploy secure software that makes that...  ...Product Security, you'll be a senior technical contributor on the... 
    Senior
    Full time
    Work at office
    Local area
    Remote work
    Monday to friday
    3 days per week

    Faire

    Toronto, ON
    more than 2 months ago
  • $126k - $154k per year

     ...businesses. We’re looking for an Application Security Engineer II who thrives on autonomy, curiosity,...  ...) ensuring our applications are secure from design to deployment. You’ll blend...  ...room to grow. You'll be working next to senior engineers who are maintaining our auth system... 
    Senior
    Full time
    Internship

    Relay

    Toronto, ON
    a month ago
  • $100k - $110k per year

     ...and your care for people. Join us and shape the future of care. The Opportunity Fullscript is looking for a Cloud Security Engineer to help secure the cloud platforms that power care delivery for millions of patients. In this role, you’ll partner with engineering... 
    Full time
    Remote work
    Flexible hours

    Fullscript

    Toronto, ON
    more than 2 months ago
  •  ...logistics means our customers audit us before they trust us — security and compliance are a precondition for deploying our platform, not...  ...multi-account AWS organization, GCP footprint, and internal engineering platform. This role covers our own corporate and cloud environments... 
    Full time

    Nexxa.ai

    Toronto, ON
    25 days ago
  • $163k - $253k per year

     ...native future. About The Role The Security Team is responsible for securing all...  ...security problems with creativity and an engineering mindset. We work at a company with a strong...  ...practices that keep Sentry productive and secure as we grow. You’ll partner closely with Infrastructure... 
    Hourly pay
    Full time

    Sentry

    Toronto, ON
    more than 2 months ago
  •  ...Role Responsibilities Review and evaluate AI-generated outputs related to threat analysis, vulnerability assessment, and security architecture recommendations. Create realistic scenarios based on cybersecurity workflows such as incident response runbooks, threat... 
    Senior
    Hourly pay
    Full time
    Contract work
    Summer work
    Remote work

    Mercor

    Toronto, ON
    more than 2 months ago
  • $162k - $420k per year

     ...native future. About The Role The Security Team is responsible for securing all...  ...security problems with creativity and an engineering mindset. We work at a company with a strong...  ...contribute to practices that keep Sentry secure as we grow: alert triage for corporate and... 
    Hourly pay
    Full time

    Sentry

    Toronto, ON
    26 days ago
  • $110k - $125k per year

     ...Vice President of Information Technology as the first hire on our Security Operations Centre (SOC) team, you will be responsible for...  ...reports, driving post-incident corrective actions with IT and engineering partners. Document and maintain investigation runbooks, operational... 
    Senior
    Full time
    Internship
    Work at office
    Flexible hours
    Weekend work
    Afternoon shift

    Financeit

    Toronto, ON
    8 days ago
  •  ...The Security Specialist for Threat Risk Assessment, Threat Modelling, Vulnerability Assessment, Risk Identification will develop new workflows...  ...in a dynamic risk environment. Responsibilities: The Senior Security Specialist will be responsible for conducting Threat... 
    Senior
    Full time
    Work at office

    Maarut Inc

    Toronto, ON
    more than 2 months ago
  • $160k per year

     ...our customer About the role: As a Senior Front-end Engineer, you’ll lead the delivery of high...  ...improve quality, reliability, scalability, security, and performance Actively...  ...authentication, authorisation, and secure software design caching strategies,... 
    Senior
    Work at office
    Remote work

    Ignition

    Toronto, ON
    13 days ago
  •  ...ATT&CK) to map potential attack vectors and security gaps. Reviewing system architecture,...  ...identification of attack vectors to inform secure design decisions and guide risk mitigation...  ...delivering presentations to stakeholders and senior leadership.  10 Points Deliverables:... 
    Senior
    Full time

    Maarut Inc

    Toronto, ON
    a month ago
  •  ...The Sr. Security Specialist will support and deliver on multiple initiatives related to Security Governance, Risk and Compliance and...  ...risk registers, and delivering presentations to stakeholders and senior leadership.  20 points Requirements Deliverables include... 
    Senior
    Full time

    Maarut Inc

    Toronto, ON
    more than 2 months ago
  • $110k - $120k per year

     ...We’re looking to fill an opening for a Senior Systems Engineer to join our Technology Ops & Support Partners...  ...Linux, VMware, Azure, backup/recovery, security, automation, and core infrastructure...  ...implementation support for resilient, secure, supportable infrastructure solutions... 
    Senior
    Full time
    Internship

    Aviso Wealth

    Toronto, ON
    18 days ago
  • $121.64k - $152.41k per year

     ...simplified rebate management.   After securing $291M in Series A-D funding and...  ...our journey. Job Summary     As a Senior Engineer you will be responsible for contributing...  ...customer experience, building high-quality, secure, and scalable software.  Duties and Responsibilities... 
    Senior
    Long term contract
    Full time
    Temporary work
    Immediate start

    Enable

    Toronto, ON
    more than 2 months ago
  • $110k - $151.8k per year

     ...Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted...  .... If you are too, let's talk. We are looking for a Software Engineer II to join the Auth0 Security Engineering organization. You'll help... 
    Full time
    Local area
    Worldwide

    Okta

    Toronto, ON
    more than 2 months ago
  • $101.2k - $130.9k per year

     ...using the link below. Job posting link via Si Systems: Senior Integration Engineer Our Story & Purpose:   We’re Vancity, a member-owned...  ...Members :    VanCity is modernizing financial systems with secure, real-time, and scalable solutions. We’re seeking a Senior... 
    Senior
    Permanent employment
    Full time
    Internship
    Work at office
    Immediate start
    Flexible hours

    Vancity

    Toronto, ON
    more than 2 months ago
  • $120k - $160k per year

     ...experiences that feel effortless, connected, and customer-first. That’s where you come in. The Role We're hiring our Senior Data Engineer (Data / ML Platform) to stand up data engineering as a discipline at Flinks . You'll own the data and ML platform that turns... 
    Senior
    Full time
    Contract work
    Remote work
    Flexible hours

    Flinks

    Toronto, ON
    more than 2 months ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Security Engineer. Be the first to apply!