SlipstreamJobsFresh Startup & VC-Backed Jobs

Senior Security Engineer - Cloud Security

PagerDuty - Toronto, ON, Canada - Hybrid - posted 2026-09-29

Apply on the company site

SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.

Salary: CAD 156,800 - 206,800 / annual

PagerDuty is seeking a Senior Security Engineer to join the Cloud Security team within Security Engineering. This is a preventive, platform-focused role for a strong engineer who will build and operate security-focused systems at scale to protect PagerDuty's multi-account AWS environment and Kubernetes platforms, with deep responsibility across container security and identity & access management. Key responsibilities include: - Harden PagerDuty's AWS and Kubernetes environments against CIS Benchmarks, DISA STIGs, and FedRAMP Moderate baselines across a multi-account, multi-org footprint, proving results through evidence, config-remediation tooling, and KPIs tracking posture, identity, and encryption/PKI health. - Own Kubernetes and container security end-to-end: harden EKS clusters and Istio service mesh against CIS Kubernetes Benchmark and DISA Kubernetes STIG, design and enforce Kubernetes RBAC and least-privilege workload identity (IRSA/pod identity), and drive controls for container supply chain (image provenance, admission control, runtime policy). - Build and operate security-focused platforms, services, and automation at scale using Python/Go, Terraform, and Kubernetes policy-as-code to reduce manual work and enable 30+ engineering teams to move quickly and safely. - Own PKI and encryption standards across the environment: certificate lifecycle and management, KMS-backed key management and rotation, TLS/mTLS (including within Istio mesh), and encryption-at-rest and in-transit requirements. - Design and roll out Service Control Policy (SCP) guardrails and least-privilege IAM/PAM across dozens of accounts and multiple orgs. - Leverage AI to unlock efficiency and velocity: consume agentic tooling in day-to-day work and build lightweight agentic solutions that streamline repetitive security work including posture triage, threat modeling, risk assessment, incident enrichment, compliance-evidence generation, and detection tuning. - Shape detection strategy for Kubernetes/Istio and identity domains: author and tune detections in the SIEM stack, define coverage standards, and conduct threat hunting for container escape, lateral movement, anomalous mesh traffic, and identity/credential abuse. - Participate in on-call rotation, triaging and dispositioning cloud and Kubernetes threat alerts and acting as Incident Commander during incidents. - Partner closely with AppSec and GRC teams to align platform controls with secure-development needs and translate hardening, identity, and encryption work into audit and compliance evidence. - Mentor and guide teammates on platform, identity, and cryptography security practices; contribute to roadmap and annual planning; at the senior end, help draft external and auditor-facing communication and represent the team in cross-team planning. Requirements: - Strong software engineering background with years building and operating production systems at scale; ability to design and ship security-focused platforms, services, and tooling as a developer. Proficiency in Python and/or Go (or similar) and Infrastructure as Code (Terraform). - 5+ years in security engineering with deep, hands-on expertise securing Kubernetes and containerized environments: EKS, Kubernetes RBAC, admission control (OPA/Gatekeeper or Kyverno), network policy, workload identity (IRSA/pod identity), container runtime/image security, and a service mesh such as Istio. - Deep expertise with AWS security services and least-privilege IAM/PAM: IAM family, Organizations/SCPs, Secrets Manager, KMS, GuardDuty, CloudTrail, and Config. - Ability to automate security controls as code (Kubernetes policy-as-code) and inform detection strategy in a modern SIEM (e.g., CrowdStrike NG-SIEM, Splunk), including threat hunting within your domains. - Experience with incident response and on-call; builder's mindset toward AI/agentic tooling to accelerate security work; track record of scoping ambiguous projects and driving them to completion with high ownership. Preferred qualifications: - Hands-on expertise in PKI and cryptography: certificate lifecycle/management, TLS/mTLS, key management and rotation (AWS KMS or similar HSM/KMS), and encryption at rest and in transit. - Hands-on hardening to CIS Benchmarks and DISA STIGs within a FedRAMP (or similar) program; familiarity with NIST CSF, SOC 2, or ISO 27001; experience partnering with AppSec and GRC teams to produce compliance evidence. - Experience building agentic or AI-assisted security automation; familiarity with securing AI/ML or agentic workloads running on cloud and Kubernetes infrastructure. - Cloud-native security tooling such as Wiz (CNAPP/Threats) and CrowdStrike Falcon runtime protection; Azure security exposure (Entra ID, Defender for Cloud) a plus. - Demonstrated mentoring, strong written and verbal communication, and working knowledge of PagerDuty's Incident Management and Process Automation products.

Similar roles