Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Senior Security Developer, Vulnerability Management

Full-time

Wealthsimple Technologies

Build something people love

Wealthsimple is Canada’s leading financial innovator. The company offers a full suite of simple, sophisticated financial products across managed investing, do-it-yourself trading, cryptocurrency, tax filing, spending and saving. Wealthsimple currently serves more than 4 million Canadians and holds over $155 billion in assets under administration. The company was founded in 2014 by a team of financial experts and technology entrepreneurs, and is headquartered in Toronto, Canada.

We're proud of what we've built — and we're just getting started. Read our Culture Manual and learn more about how we work .

About the Role

Most vulnerability management programs are still built around people manually triaging tickets and chasing down owners. We're taking a different approach: a platform that uses AI-assisted tooling to do a lot of that work for us, and this role is where that gets built. We want you to design the automations, integrations, and workflows that take those fundamentals further: less manual ticket routing, more systems that carry a finding through triage, ownership, and remediation on their own.

The skill set we're after, automation-first thinking, developer-level reasoning, and the ability to build integrations across systems, is what turns a program from manual and reactive into something that runs on its own. That's the job: build the automation and integrations that let our VM tooling handle the load without a person in the loop at every step. We're also building deeper integration with our CRS (Cyber Reasoning System) harness, so a finding can move from triage through automated sandbox validation to a generated fix with less manual handling at each stage.

We use AI-assisted development tools heavily and expect you to use them too.

In this role, you will have the opportunity to:

  • Own and evolve our custom VM platform, working on deployment, integrations, data model, and automation workflows. This is a greenfield opportunity to shape how the platform grows.

  • Build automation across the full VM lifecycle: triage, ticket routing, SLA tracking, ownership resolution, and follow-up. We use Claude Code and Tracecat, and you'll be expected to use and extend both meaningfully.

  • Take a platform built around one team's workflow to one that fits how the rest of engineering actually works. Get it in front of people, bake it into their existing processes, and make it something teams reach for.

  • Integrate scanner data into our VM pipeline and maintain the enrichment workflows that turn raw findings into actionable tickets.

  • Build the queries, dashboards, and automated reports that give the team and leadership clear visibility into vulnerability posture.

  • Stay current on the threat landscape, especially the growing role of AI in vulnerability research and exploitation, and factor that into how we build and prioritize.

  • Help build toward a future where a validated finding gets tested and patched by CRS in a sandbox, and comes back out as a PR, closing the loop with minimal manual work.

We are looking for someone who:

  • Is familiar with the software development lifecycle end to end, well enough to recognize where a vulnerability was actually introduced in the process and to tell when an AI tool is hallucinating a finding instead of catching a real one.

  • Has 4+ years of hands-on vulnerability management and/or security engineering experience, including scanner integration, triage workflows, and remediation tracking. If vulnerability management isn't explicitly on your resume, you should be able to explain clearly why you understand it anyway.

  • Has production AWS experience.

  • Has a strong automation-first mindset. You've built things that replace manual processes.

  • Has deep familiarity with VM tooling (Tenable, Semgrep, Rapid7, or comparable scanners) and knows how to build integrations on top of them via API.

  • Understands the difference between package and library vulnerabilities well enough to know where a fix actually belongs, and understands vulnerability classes across application and infrastructure layers (XSS vs. CSRF, code vs. container issues) well enough to have a real conversation with a developer who disagrees with a finding. Knows which scanners belong at which stage of the pipeline (CI, production, network) and how a vulnerability actually ends up running in production, including in containers. Hands-on exposure to SAST/DAST/SCA tooling and OWASP fundamentals helps here.

  • Has hands-on familiarity with GitHub Actions, ArgoCD, Kubernetes, AMIs, and container images (ECR or comparable). You'll need this to help maintain our VM platform, and because each of these carries its own patch management burden since they all run code.

  • Understands attack surface and exposure management, including how a basic web app's architecture and traffic flow map to real risk. You'll be making risk acceptance calls, and that requires seeing the actual exposure, not just a CVE score.

  • Can translate business and partner needs into solutions. You'll spend real time with developers who don't understand a finding, disagree with it, or say a fix didn't work, and you need to work through that without losing the thread.

  • Has a strong understanding of the programs vulnerability management connects to: CI/CD and deployment pipelines, threat intelligence, and bug bounty or responsible disclosure programs. VM doesn't operate in a vacuum, and we want someone who understands the connections that exist today and the ones that should exist but don't yet.

  • Is familiar with different compliance programs and vulnerability management controls.

  • Is actively using AI-assisted development workflows (Claude Code, Cursor, Copilot, or similar) and treats them as a force multiplier, not a novelty.

Nice to have:

  • Experience with security orchestration platforms (Tracecat, Tines, XSOAR, or comparable).

  • Experience with bug bounty or responsible disclosure programs like HackerOne.

  • Familiarity with vulnerability scoring and prioritization frameworks (CVSS, EPSS, SSVC). This is quick to pick up on the job, so it's weighted lower than the items above.

  • Experience in a fintech or regulated-industry environment.

  • Open-source security tooling contributions.

Why Wealthsimple?

Top-tier health benefits and life insurance

Long-term group savings with employer match, through Wealthsimple for Business

20 vacation days, 4 wellness days, and unlimited sick and mental health days per year

✈️ 90 days away: work outside Canada for up to 90 days per year

Employee resource groups, including Rainbow (2SLGBTQ), Women of WS, and Black at WS

We are a hybrid team with over 1,500 employees across North America. The people are one of the best parts of working here: you'll collaborate with incredibly talented, curious, and driven teammates who are deeply committed to doing great work.

ICYMI

Technology & Innovation at Wealthsimple: We move quickly and build thoughtfully. That means we're always looking for better ways to work — whether that's new tools, AI, or rethinking how we approach a problem. We don't expect you to have all the answers, but we do expect curiosity and a willingness to evolve alongside the products we're building.

Inclusion Statement: We're building products for a diverse world, and we need a diverse team to do it well. We strongly encourage applications from everyone, regardless of race, religion, colour, national origin, gender, sexual orientation, age, marital status, or disability status.

Accessibility Statement: We're committed to an accessible hiring experience. If you need any accommodations throughout the interview process, please let us know — we'll work with you to make sure you have what you need. We also welcome any feedback on how we can better accommodate candidates with accessibility needs.

AI in Hiring: We may use artificial intelligence (AI) tools to support parts of our hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our team but don't replace human judgment – all final hiring decisions are made by people. If you have questions about how your data is used, reach out to us.

Vacancy posted 12 hours ago
Similar jobs that could be interesting for youBased on the Senior Security Developer, Vulnerability Management in Remote vacancy
  •  ...Role: Vulnerability management (Remote, Canada) Location: Remote (Canada) Employment Type: Contract...  ...tool based. AppSec: Web Application Security  Mobile Application Security API...  .... Understanding of OWASP Top 10, secure coding practices, and application threat... 
    Suggested
    Remote job
    Contract work

    Aarorn Technologies

    Remote
    20 hours ago
  •  ...all structured and unstructured data — securing and protecting private information...  ...What is The Role We are seeking a Senior Software Developer to join the Elasticsearch Security team...  ...This includes authentication, identity management, cryptography, and data access management... 
    Senior
    Full time

    Elastic Nv

    Remote
    20 hours ago
  •  ...highly motivated and enthusiastic Cyber Threat and Vulnerability Management Specialist to join our Information Security team. As a Cyber Threat and Vulnerability...  ...security risks. Collaborate with multiple teams to develop, implement and enforce security controls, policies... 
    Senior
    Permanent employment
    Full time
    Remote work

    Tecsys Inc.

    Remote
    20 hours ago
  •  ...The Security Product Management team is vital in safeguarding customer trust and making data security a...  ...security features such as Resource Policies, Secure by Default at MongoDB, and other...  ...loss.  Partner with engineering to develop a prioritized product roadmap and backlog... 
    Senior
    Full time
    Internship
    Work at office
    Remote work
    Worldwide

    Mongodb

    Remote
    20 hours ago
  •  ...They are looking for an AppSec developer to play a cross-functional...  ...a center of excellence in secure development. This person will...  ...developed frameworks Identify vulnerabilities, assess their risks, and...  ..., secure secret management, encryption, traceability, and... 
    Suggested
    Full time
    Shift work

    Maarut Inc

    Remote
    20 hours ago
  •  ...structured and unstructured data — securing and protecting private...  ...a Principal Software Developer to join the Elasticsearch Security...  ...includes authentication, identity management, cryptography, and data...  ...from the outset. Drive vulnerability management efforts by collaborating... 
    Full time

    Elastic Nv

    Remote
    20 hours ago
  •  ...members. Role Overview The Security Operations Manager is a hands-on leader responsible for...  ...and post-incident activities. Act as senior incident leader for high-severity...  ...career growth paths, helping engineers develop technical depth, operational ownership... 
    Senior
    Long term contract
    Full time
    Remote work
    Worldwide

    Apollo.Io

    Remote
    20 hours ago
  • $130k - $150k per year

     ...Tigera provides Calico, a unified network security and observability platform to prevent...  ...Your Role Tigera is hiring a Senior Security Engineer to own product and...  ...products and SaaS infrastructure, drive vulnerability and CVE management end-to-end, and contribute to... 
    Senior
    Full time
    Flexible hours

    Tigera

    Remote
    20 hours ago
  •  ...We’re looking for a Senior Engineering Manager who is ready to lead through ambiguity and improve how software gets built at MongoDB. This role leads teams focused on developer productivity, with an emphasis on measurable improvements to the software development lifecycle.... 
    Senior
    Long term contract
    Full time
    Remote work
    Worldwide

    Mongodb

    Remote
    20 hours ago
  • $105.6k - $132k per year

     ...Nations. Every day, thousands of developers and marketers use our WebOps...  ...create. The Role Own Developer Experience—a strategic...  ...experience, including 3+ years managing developer-facing products or...  ...~ Demonstrated ability to manage a broad, complex product portfolio... 
    Senior
    Full time
    Work at office
    Local area
    Remote work
    Worldwide

    Pantheon Systems

    Remote
    20 hours ago
  • $182.82k - $268.13k per year

     ...What You'll Do Epic Games is looking for a Senior Security Programmer focused on Game Security to develop and improve anti-cheat capabilities within our games...  ...associated backend services in Go Proactively seek out vulnerable components in the Fortnite game client or backend,... 
    Senior
    Long term contract
    Full time
    Temporary work

    Epic Games

    Remote
    20 hours ago
  • $120k - $130k per year

     ...connection.   Reports to: Information Security Manager Location: Canada - Remote About the Role Backcountry needs a senior security engineer to protect and harden...  ...patching, configuration management, and vulnerability remediation Evaluate and govern the secure... 
    Senior
    Remote job
    Full time
    Internship
    Work at office

    Csc Generation

    Remote
    20 hours ago
  •  ...been one of the most loved brands in developer tooling, trusted by more than 20...  ..., verified images, and secure infrastructure that make autonomous...  ...We're looking for an Engineering Manager to lead this team. It's a small, very senior group that recently came together,... 
    Senior
    Full time
    Remote work
    Home office
    Visa sponsorship
    Shift work
    Afternoon shift

    Docker

    Remote
    20 hours ago
  •  ...Experience Platform (DXP) enables marketers, developers, and IT operations teams at thousands...  .... Role Overview As the Manager of Security Engineering, you lead a specialized team...  ...systematically surface and remediate vulnerabilities across product codebases. Shift the... 
    Full time
    Local area
    Shift work

    Acquia

    Remote
    20 hours ago
  • $150k - $180k per year

     ..., so everything stays clean, secure, and optimized. It lays the groundwork...  .... ShareGate is developed by Workleap Technologies, a Montréal...  ...As an Application Security Manager, you will be a hands-on...  ...remediation of application security vulnerabilities; Strengthen application... 
    Full time
    Local area

    Sharegate- En

    Remote
    20 hours ago
  •  ...board members. Role Overview The Senior Application Security Engineer II is a senior individual...  ..., external testing intake, and developer enablement. This role is calibrated...  ...models for new and existing systems. Vulnerability management and hands-on remediation... 
    Senior
    Long term contract
    Full time
    Worldwide

    Apollo.Io

    Remote
    20 hours ago
  •  ...difference. Job Description As a Senior/Staff Platform Developer at Vention, you will focus on...  ...environments. You will be a key player for managing our software inventory and lifecycle...  ...performance, highly-availability and secure cloud environments. Participate in... 
    Senior
    Full time
    Internship
    Work at office
    Work from home

    Vention

    Remote
    20 hours ago
  •  ...sophisticated financial products across managed investing, do-it-yourself...  ...how we work . The Security GRC team plays a critical...  ...reporting and dashboards for senior leadership and committee-level...  ...audiences Monitor the threat and vulnerability landscape and help translate... 
    Senior
    Long term contract
    Full time

    Wealthsimple Technologies

    Remote
    20 hours ago
  • $158k - $237k per year

     ...Menlo Security's mission is enabling the world to connect, communicate...  ...traditional VMs and modern managed and unmanaged container-based...  ...submissions and outside vulnerability reports. AI and large language...  ...cookies, Subresource Integrity), secure authentication/authorization... 
    Senior
    Full time
    Local area
    Immediate start

    Menlo Security

    Remote
    20 hours ago
  •  ...seamless payment solutions. We're seeking a Senior Software Developer to join our dynamic team. In this...  ...in building and maintaining scalable, secure, and compliant web applications. If...  ...maintenance. Collaborate with product managers, designers, support teams and other... 
    Senior
    Long term contract
    Full time
    Work at office
    Local area
    2 days per week

    Benji Pays

    Remote
    20 hours ago
  • $103k - $153k per year

     ...crime, protect assets, and guard national security.   With employees based around the...  ...from you!  Role Overview As a Senior iOS Developer on the Graykey AppLogic team , your...  ...including systems programming, memory management, and low-level interfaces. ~ Solid understanding... 
    Senior
    Full time
    Work at office
    Local area
    Remote work
    Flexible hours

    Magnet Forensics

    Remote
    20 hours ago
  •  ...driven decision making. As a Senior Data Engineer, you will hold a...  ...pipelines, versioning and change management Manage the complexity...  ...in versioned data pipelines Develop ETL/ELT processes to help extract...  ...accuracy, integrity, privacy, security, and compliance through quality... 
    Senior
    Full time
    Remote work

    3pillar

    Remote
    20 hours ago
  •  ...About the Role We are seeking a Senior Android Developer (Kotlin) for the Mobile Team dedicated...  ...application. Reporting to the Engineering Manager. The candidate is responsible for...  ...their experience and perspective to build security and performance into all they do, with... 
    Senior
    Full time
    Work at office
    Flexible hours

    Alayacare

    Remote
    20 hours ago
  •  ...About the Role We are seeking a Senior AI Developer to join our computer vision (CV) Engineering...  ...translate advanced research systems into secure, reliable, and scalable product...  ...SRE to develop the orchestration, state management, tool execution, guardrails, and supporting... 
    Senior
    Daily paid
    Full time
    Work at office
    Local area
    Remote work
    Worldwide
    Flexible hours
    3 days per week

    Hinge Health, Inc.

    Remote
    20 hours ago
  • $128k - $200k per year

     ...About The Role Hi, I'm Dmitri Grozenok , Senior Manager of Onboarding product development at...  ...here about a year, leading a team of eight developers working on a mission that's genuinely...  ...and setting a high bar for maintainable, secure code. Mentor and coach more junior... 
    Senior
    Full time
    Internship
    Remote work

    Jane

    Remote
    20 hours ago
  •  ...enables organizations to increase developer productivity, improve operational efficiency, reduce security and compliance risk, and...  ...evolution of GitLab's Security Risk Management (SRM) stage into a world-class platform for vulnerability analysis and remediation at enterprise... 
    Senior
    Full time
    Internship
    Remote work
    Home office

    Gitlab

    Remote
    20 hours ago
  •  ...one of the most loved brands in developer tooling, trusted by more than...  ..., verified images, and secure infrastructure that make autonomous...  ...default. We’re looking for a Senior Salesforce Developer to help...  ...Salesforce DevOps and release management lifecycle while establishing... 
    Senior
    Long term contract
    Full time
    Remote work
    Home office
    Shift work

    Docker

    Remote
    20 hours ago
  • $110k - $140k per year

     ...planning, organizational design, and manager effectiveness solutions, we...  ...knowledge. As the Data Developer on this initiative, you will own...  ...vector data stores to architect secure, production-grade DataOps...  ...arrangements may vary depending on your seniority, location and employment type.... 
    Senior
    Full time
    Work at office
    3 days per week

    Visier Solutions Inc

    Remote
    20 hours ago
  • $100k - $120k per year

     ...seeking a dynamic and creative Senior F irmware Engineer   to join our team in developing next-generation smart grid...  ...closely with hardware, product management, and testing teams to deliver reliable...  ...embedded firmware applications, security suites DLMS/cosem, metering data... 
    Senior
    Full time

    Corinex Communications

    Remote
    20 hours ago
  • $175k - $195k per year

     ...We are seeking a Senior Staff Information Security Engineer to help shape and advance security across our hybrid...  ...controls for identity and access management, segmentation, encryption, secrets, logging...  ..., and workload protection. Develop preventative guardrails through infrastructure... 
    Senior
    Remote job
    Full time
    Work at office

    Nmi Llc

    Remote
    20 hours ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Senior Security Developer, Vulnerability Management. Be the first to apply!