/roles — ROLE_173
Software Engineer, Security
Seed-stage startup from repeat founders building a secure-by-design enterprise identity platform
The role
- COMP
- $180K - $230K
- EQUITY
- This role offers competitive early-stage equity as part of the total compensation package. Specific equity details are shared later in the interview process.
- LOCATION
- Canada
- WORKPLACE
- Remote
- EXPERIENCE
- 5+ years
- VISA
- None, Visa transfers
- STACK
- Go, GCP, Kubernetes, Python, Sigma
- INDUSTRY
- Enterprise, Security, Cybersecurity
The company
Seed-stage, fully remote startup rebuilding enterprise identity with security designed in from the start, founded by a team that previously built and sold a company to a major tech firm.
- STAGE
- early-stage
- TEAM
- ~10 people
- FOUNDED
- 2025
JD — the work
About the role
You would be the company's first full-time security engineer, owning security broadly: product and application security, detection and response, compliance, and corporate security. The founders previously built and sold a company to a major tech firm, and the small team works fully remotely across the US and Canada. You'd report to a co-founder with a security background and have room to grow a security team as the company scales. Visa transfers and TN are supported and O-1 may be an option for exceptional profiles, but the company cannot take on new H-1B cases or F-1 OPT/CPT.
What you'll do
- Own security for the whole product stack, working inside engineering from design through release
- Stand up foundational security infrastructure: audit logs, secrets handling, PKI and certificates, and vulnerability tracking
- Threat-model new features, review designs and code, and advise engineers on building securely
- Drive compliance for GDPR, CCPA, SOC 2, and ISO 27001 from an engineering angle
- Set up incident response and grow detection coverage, from writing detections to triage
- Cover product, corporate, and compliance security as a generalist, with room to hire a team later
What they're looking for
- 5+ years in security engineering; strong engineering depth matters more than prior program building
- Production Go that you currently write and ship, not only review
- Hands-on product security work in a shipping product, including design reviews, code review, and vulnerability fixes
- Detection and response: building detections as code in a SIEM (Splunk, Panther, Sigma) and automating triage with Python
- Hands-on compliance work across GDPR, SOC 2, and ISO 27001
- A low-ego, collaborative generalist who keeps up with the changing threat landscape
Nice to have
- Having been one of the first two security engineers at a quickly growing startup
- IAM or enterprise IT and security software background, including OIDC, SAML, OAuth, and WebAuthn
- Kubernetes and cloud security, ideally on GCP
- A bachelor's in a relevant field helps but is optional