Senior Security Engineer

ActalentOttawa, OntarioOn-siteContractListed 39 minutes ago

Apply now

About this role

Job Title: Expert Security Engineer Vulnerability Prime Job Description Security Engineer owns the cross-product operating model for vulnerability management, including intake, triage, routing, tracking, reporting, remediation oversight, and closure, while driving consistent Secure SDLC practices across multiple product teams. Acting as a strategic connector between security leadership and engineering organizations, this position translates security requirements into actionable development processes, scalable workflows, and audit-ready controls that strengthen the overall security posture. Responsibilities

- Own the cross-product operating model for vulnerability intake, triage, routing, tracking, reporting, remediation oversight, and closure across multiple software products.
- Establish consistent Secure SDLC workflows, artifacts, dashboards, controls, and audit-ready evidence that can be adopted and reused across product teams.
- Design and implement automation and AI-assisted methods for CVE analysis, finding correlation, evidence generation, and workflow enforcement to handle growing vulnerability volumes.
- Coordinate product teams, Security Architects, security program leadership, PSIRT, DevOps, and release leadership when security issues cross organizational boundaries.
- Identify systemic gaps in tools, policies, ownership models, and processes, and drive sustainable improvements rather than repeatedly managing isolated incidents.
- Translate security requirements into product designs, implementation plans, and software features that integrate seamlessly into existing development processes.
- Maintain deep knowledge of assigned products and connect Security Architects and Security Primes with designers, developers, validation teams, DevOps, and release teams.
- Drive implementation of security features, third-party component risk actions, scanning follow-up, threat modeling completion, and secure development practices within engineering teams.
- Assess current security operations and identify opportunities to improve vulnerability management, governance, tooling, compliance evidence generation, and process consistency.
- Develop and promote standardized dashboards, metrics, and reporting to provide visibility into vulnerability status, Secure SDLC adoption, and security posture across products.
- Influence engineering, architecture, systems, and security organizations to adopt improved security processes and frameworks without relying on direct authority.
- Lead and support organization-wide security initiatives from concept through implementation, leveraging existing engineering resources and aligning stakeholders around shared goals.
- Contribute to the definition of organizational security strategies and governance models that support long-term Secure SDLC and vulnerability management maturity.
- Collaborate closely with security leadership, security architects, software engineering leadership, systems leadership, DevOps teams, validation teams, and release management stakeholders to ensure alignment on security priorities and execution.

Essential Skills

- Proven experience embedding security into enterprise software development organizations.
- Demonstrated experience developing and operationalizing Secure SDLC programs across multiple products or teams.
- Experience creating and implementing security processes, frameworks, workflows, and governance models.
- Hands-on experience with threat modeling and integrating it into software development lifecycles.
- Experience with static application security testing (SAST) tools and processes.
- Experience with dynamic application security testing (DAST) tools and processes.
- Experience building, running, or maturing vulnerability management programs.
- Experience leading organization-wide security initiatives that span multiple engineering and security teams.
- Strong stakeholder management skills, with the ability to build consensus and drive alignment across diverse technical and non-technical audiences.
- Strong executive communication skills, including the ability to present complex security topics in clear, concise terms.
- Ability to assess ambiguous technical challenges and develop practical, actionable solutions.
- Experience influencing engineering, architecture, systems, and security organizations without direct reporting authority.
- Familiarity with AI-enabled security and process automation in the context of vulnerability management and Secure SDLC.
- Deep understanding of vulnerability management, application security, threat modeling, security governance, CVEs, vulnerability remediation, and secure development practices.
- Experience with static and dynamic application security testing (SAST and DAST), including interpreting results and driving remediation.

Additional Skills & Qualifications

- Experience with embedded systems, networking products, or telecommunications equipment.
- Experience with cybersecurity standards and frameworks such as ISO, SSDLC, or related security methodologies.
- History in technical leadership, exec engineering, or architecture-focused roles within software organizations.
- Experience working within large software product companies and navigating complex organizational structures.
- Experience modernizing Secure SDLC programs and elevating security maturity across multiple teams.
- Exposure to AI-enabled security operations and the use of AI to enhance security processes.
- Experience with vulnerability analysis automation and integrating automated tooling into development pipelines.
- Experience with security process automation, including workflow orchestration and evidence generation.
- Experience developing security advisory guidance and communicating best practices to engineering teams.
- Experience adapting and implementing industry best practices for security from previous organizations into new environments.

Work Environment The preferred work location is Ottawa, Ontario, with priority given to candidates who are based in Ottawa or are willing to relocate. Remote work may be considered for candidates who demonstrate exceptional expertise and a strong track record of operating effectively within distributed teams. The role is initially structured as a 12-month contract engagement, with the possibility of direct-hire or contract-to-hire arrangements depending on business needs and how the role evolves over time. The position involves extensive collaboration with security leadership, security architects, software engineering leadership, systems leadership, DevOps teams, validation teams, and release management stakeholders, requiring frequent cross-functional communication and coordination. Details regarding onsite requirements, work schedule, reporting structure, workplace language, travel expectations, and hybrid cadence are not specified, allowing for flexibility to align with organizational needs and candidate preferences. This posting is for an existing vacancy. Job Type & Location This is a Contract position based out of Ottawa, ON.
Pay and Benefits
The pay range for this position is $60.00 - $110.00/hr. Individual compensation offered for this position within this range will depend on many factors, including qualifications, skills, relevant experience, job knowledge, geographic location, internal equity, and other pertinent job-related factors.
Workplace Type
This is a hybrid position in Ottawa,ON.

À propos d'Actalent

Actalent est un leader mondial dans les services dingénierie et de sciences ainsi que dans les solutions de talents. Nous aidons des entreprises visionnaires à faire progresser leurs initiatives dingénierie et de science grâce à laccès à des experts spécialisés qui favorisent léchelle, linnovation et la rapidité de mise sur le marché. Avec un réseau de près de 20 000 consultants et 5 000 clients à travers les États-Unis, le Canada, lAsie et lEurope, Actalent dessert de nombreuses entreprises du Fortune 500. Nous sommes fiers dêtre lune des 500 meilleures firmes de conception de lEngineering News-Record (ENR) pour nos services de conception en ingénierie et un lauréat du prix ClearlyRated Best of Staffing® tant pour le service client que pour les talents.

Actalent est un employeur souscrivant au principe de légalité des chances et accepte toutes les candidatures sans tenir compte de la race, du sexe, de lâge, de la couleur, de la religion, des origines nationales, du statut dancien combattant, dun handicap, de lorientation sexuelle, de lidentité sexuelle, des renseignements génétiques ou de toute autre caractéristique protégée par la loi.

Si vous souhaitez faire une demande daccommodement raisonnable, tel que la modification ou lajustement du processus de demande demploi ou dentrevue à cause dun handicap, veuillez envoyer un courriel à [email protected] pour connaître dautres options daccommodement.

Ordonnance sur légalité des chances de San Francisco:
Conformément à lOrdonnance sur légalité des chances de San Francisco, pour tous les postes situés dans la ville et le comté de San Francisco, nous examinerons les candidatures des personnes qualifiées ayant un casier judiciaire ou des antécédents criminels.

Utilisation de lintelligence artificielle (IA):
Nous pouvons utiliser lintelligence artificielle (IA) pour soutenir certaines étapes de notre processus dembauche, notamment la recherche, la présélection et lévaluation des candidatures. LIA aide à analyser les candidatures et les qualifications, mais les décisions finales sont prises par notre équipe de recrutement. En soumettant votre candidature, vous reconnaissez et acceptez que celle-ci puisse être examinée à laide doutils dIA.

About Actalent

Actalent is a global leader in engineering and sciences services and talent solutions. We help visionary companies advance their engineering and science initiatives through access to specialized experts who drive scale, innovation and speed to market. With a network of almost 20,000 consultants and 5,000 clients across the U.S., Canada, Asia and Europe, Actalent serves many of the Fortune 500. We are proud to be an Engineering News-Record (ENR) Top 500 Design Firm for our engineering design services and a ClearlyRated Best of Staffing® winner for both client and talent service.

The company is an equal opportunity employer and will consider all applications without regard to race, sex, age, color, religion, national origin, veteran status, disability, sexual orientation, gender identity, genetic information or any characteristic protected by law.

If you would like to request a reasonable accommodation, such as the modification or adjustment of the job application process or interviewing process due to a disability, please email [email protected] for other accommodation options.

San Francisco Fair Chance Ordinance: Pursuant to the San Francisco Fair Chance Ordinance, for all positions located in the city and county of San Francisco, we will consider for employment qualified applicants with arrest and conviction records.

Use of Artificial Intelligence (AI): We may use Artificial Intelligence (AI) to support parts of our hiring process, including sourcing, screening, and evaluating candidates. AI helps assess applications and qualifications, but final decisions are made by our hiring team. By applying, you acknowledge and agree that your application may be reviewed using AI tools.