Senior Security Engineer

🏢 Roofr · all 9 jobs
📍 Canada
📅 Posted Sep 18, 2026 · via Himalayas
🏷 Security Engineering, Cloud Security, Infosec, Cybersecurity, Infrastructure Security, Security Engineer +7 more
Apply on original site ↗

At Roofr , we’re obsessed with our customers. We constantly gather feedback to shape, prioritize, and launch the products they truly need. That’s what makes Roofr ’s CRM special. We started by building essential sales tools like aerial roof measurements and digital sales proposals. But when our customers asked for a simple, affordable way to manage and scale their entire businesses, we listened. So, we created a CRM that connects these solutions—along with payments, material ordering, and more—into a seamless, powerful platform. With a clear roadmap ahead, we’re excited to continue expanding and leading the market with innovative products.

We have an amazing culture, strong financials, and best-in-class company metrics. It’s an exciting time to be part of an extraordinary startup that is already successful, yet still early enough to offer its team significant growth, equity, and the opportunity to make a real impact.

This position is for an existing vacancy.

As Senior Security Engineer, you'll report to the VP of Engineering and work closely with the CTO and DevOps as part of Roofr 's security guild. You'll contribute directly to improving Roofr 's security posture — sharpening what's already in place and driving it forward as the company scales. You'll own the tools and processes that detect and stop threats, partner with engineering on secure-by-design practices, and act as the front-line responder when something goes wrong.
What You’ll Get to Do

- Own design and hardening of security infrastructure across cloud environments — network segmentation, firewalls, IDS/IPS, VPNs, WAF, and endpoint detection and response (EDR)

- Lead vulnerability management end to end: run assessments and authenticated scans, triage and prioritize by exploitability and blast radius, and drive remediation SLAs with engineering

- Build and tune detection content (SIEM/SOAR rules, alerting logic) against real attack techniques — not just default vendor signatures

- Act as incident commander for security incidents: contain, eradicate, run forensics, and write the post-incident review

- Threat-model new features and infrastructure changes before they ship — catch design-level risk, not just implementation bugs

- Own IAM hygiene and cloud security posture (least privilege, key/secret management, network boundaries) across production AWS accounts

- Write, enforce, and maintain security policies and standards — own them as living controls, not documents that sit in a drive

- Own Roofr 's compliance program end to end: map controls to NIST CSF 2.0, SOC 2, and CCPA/CPRA, run the audits, close the gaps, and keep evidence current between them

- Run tabletop exercises and incident playbook drills

- Push secure-by-design practices into engineering workflows — threat modeling in design review, security requirements in the SDLC, not a gate bolted on at the end

What You’ll Bring to the Role
Qualifications

- Bachelor's degree in computer science, IT, cybersecurity, or equivalent hands-on experience

- 5-8+ years in security engineering, incident response, or related infrastructure roles, including time as the primary or senior responder on real incidents

- Certifications are a strong plus — CISSP, OSCP, GCIH, or CEH

Technical

- Deep network security fundamentals — firewalls, VPNs, routing/segmentation, network boundaries, TLS, DNS, and how attackers actually abuse them

- Hands-on cloud security in AWS — IAM policy design, VPC architecture, KMS/secrets management, CloudTrail/GuardDuty or equivalent

- Real incident response experience — triage, containment, forensics, root cause, not just theory from a course

- Working knowledge of SIEM/SOAR tooling, writing detection logic (Python/Bash), and building your own tooling when nothing off-the-shelf fits

- Fluent in compliance frameworks — NIST CSF 2.0, SOC 2, and CCPA/CPRA — and translating controls into policy people actually follow

- Strong software engineer at heart — comfortable reading a

Flights + hotels

This role requires you to be in Canada. If that means relocating or flying in, it is worth checking fares before you commit to a start date.

Compare flights and hotels →

← All remote jobs

Want more like this? Browse every live remote developer role.All remote developer jobs →
Get new developer jobs by email
Daily email, only when there's something new. One click to stop.

Get remote developer jobs like this by email

10 hand-picked jobs, one email a day. No spam, unsubscribe anytime.

Similar for you