SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Salary: CAD 162,000 - 420,000 / annual
Sentry is an application monitoring platform trusted by 200,000+ organizations, helping developers fix errors and performance issues before users notice. The Security Team is responsible for securing Sentry's customers, code, and infrastructure. This is a hands-on security engineering role focused on detection and response within a small, high-trust team operating with broad scope and autonomy.
In this role, you will maintain and improve detection engineering systems, including Sentry's owned detection stack and agentic triage with security response and orchestration automation. You'll perform security investigations and contribute to incident response across both Sentry's infrastructure and customer-impacting incidents. You'll also contribute to identity and access management systems, which are critical to Sentry's security program.
You'll have significant opportunity to grow across multiple security domains—appsec, infrasec, governance, and privacy—working cross-functionally with teams throughout the company. As Sentry expands agentic product capabilities, you'll be at the frontier of new security approaches and challenges, researching and responding to emerging threats relevant to the platform's novel attack surface.
The ideal candidate enjoys operating cross-functionally, gets excited by new security challenges (breaches, exploits, novel architectures, unfamiliar cloud primitives), and loves working in a developer-forward culture. You should reach for automation first, preferring scalable systematic solutions over reactive manual triage. You thrive with ownership and autonomy while valuing mentorship on a small, high-trust team.
Required: 2+ years in detection/response, corporate security, or generalist security engineering; CS degree or equivalent; hands-on experience with alert triage, detection tuning/writing, detection-as-code, log ingestion, incident response, IAM, phishing response, or EDR/SIEM tooling; proficiency in at least one programming language (Python preferred); comfort with agentic development workflows; familiarity with distributed cloud technology (AWS, GCP, Azure, Kubernetes, Docker, Terraform); and experience with corporate SSO/SAML/IAM and defensive security tools.