SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: CAD 158,000 - 263,000 / annual
Menlo Security is seeking a Principal Security Architect to lead security design and architecture across the Menlo Browser Security Platform, which protects organizations from cyberattacks across web, documents, and email. The platform also includes Menlo Agent Runtime Security (MARS) for protecting AI agents in enterprise environments. This is a senior technical leadership role trusted by Fortune 500 companies and government agencies.
In this role, you will conduct comprehensive security design reviews of both broad product architecture and incremental changes, with particular focus on AWS cloud infrastructure integration. You will design and document enterprise Hardware Security Module (HSM) and Key Management System (KMS) integration and deployment processes. You will assess third-party software and SaaS offerings for security implications, evaluate integration designs and implementations, and oversee both internal and third-party security assessments.
Additional responsibilities include performing in-depth vulnerability impact analysis for both third-party and product vulnerabilities, staying current with emerging technologies (web standards, browser behavior changes) and assessing their product impact, and assisting compliance and sales teams on technical regulatory and RFP questions. You will engage in deep technical conversations with customers on security topics, contribute to patent writing and review, create and review external technical materials (blogs, white papers, presentations), and develop novel security-focused product features.
This role offers the opportunity to shape security strategy at a company protecting critical enterprise and government infrastructure, with exposure to cutting-edge browser security, cryptography, and AI agent security challenges.
REQUIREMENTS:
- Advanced knowledge of applied cryptography (HSMs, TPMs) and Key Management Life Cycle (generation, storage, distribution, backup, rotation, revocation, destruction)
- Deep knowledge of web and browser technologies: Same Origin Policy, XSS, CSRF, HTTP security headers, browser architecture, JavaScript engine internals
- Thorough understanding of network and OS fundamentals: TCP, HTTP, TLS, DNS, firewalls, WAFs, DAC/MAC, sandboxing
- AWS security experience: IAM, Organizations, EC2, VPC
- Familiarity with static and dynamic analysis concepts and tools
- Advanced knowledge of C/C++ with focus on secure coding, plus at least one additional language (Python or JavaScript preferred)
- Willingness to get hands-on to drive results
- Minimum MSc/MEng or equivalent; PhD preferred