Security Engineer (17-Month Contract)
Contractor
Toronto, ON, Canada
CAD 87,500-108,300 / year
- Innovate with Purpose: Build impactful solutions for customers worldwide.
- Join Excellence: Work in a diverse, collaborative, and innovative team.
- Shape the Future: Lead in redefining revenue optimization.
- Grow Together: Unlock your potential in a supportive environment.
The Opportunity
Varicent is looking for a hands-on Security Engineer to join our Information Security team on a 17-month contract and help strengthen the security of our systems, applications, and cloud environments.
This is a broad security engineering role for someone who enjoys being close to the technology while working across security operations, tooling, vulnerability management, incident response, and risk assessments. You’ll partner with Engineering, Cloud Operations, IT, and business teams to identify risks, improve security controls, and continuously strengthen how we protect our environment.
You’ll also have opportunities to work on emerging areas such as AI security, threat modeling, security automation, and integrating security testing into CI/CD pipelines.
What You’ll Do
Security Engineering & Tooling
Deploy, configure, monitor, and improve security technologies including SIEM, EDR, DLP, WAF, CASB, Secure Web Gateway, email security, and vulnerability scanning tools
Own and improve assigned security tools, including runbooks, workflows, documentation, and operational processes
Lead small-to-medium security initiatives from requirements and design through testing and implementation
Support security technology evaluations and proof-of-concepts
Security Monitoring & Incident Response
Investigate and triage security events across endpoint, cloud, network, application, and email environments
Support incident response investigations, root-cause analysis, escalation, and lessons learned
Identify opportunities to improve detection capabilities and reduce recurring security issues
Vulnerability Management & Security Testing
Support infrastructure, endpoint, and application vulnerability scanning, penetration-testing validation, and AI red-team testing
Validate and prioritize vulnerabilities and partner with technical teams to drive remediation
Coordinate rapid response to high-priority risks and zero-day vulnerabilities
Help integrate SAST, DAST, SCA, and external attack surface management into CI/CD workflows
Identify opportunities to automate repetitive security activities
Risk, Threat Modeling & AI Security
Conduct security risk assessments for internal initiatives, product changes, vendors, and productivity tools
Perform STRIDE-based threat modeling, including assessments of AI-enabled tools and applications
Evaluate AI and Agentic AI security risks and recommend practical mitigations
Support third-party risk assessments and workflows using OneTrust
What You’ll Bring
5+ years of experience in Information Security, Security Engineering, or Security Operations
Bachelor’s degree in Information Security, Computer Science, Computer Engineering, Technology Management, or equivalent practical experience
At least one relevant security certification, such as CISSP, CISA, CCSP, or equivalent
Hands-on experience with security technologies such as SIEM, EDR, WAF, DLP, and vulnerability scanning platforms
Experience securing public cloud environments such as AWS, GCP, or IBM Cloud
Working knowledge of security across operating systems, networks, applications, databases, and cloud environments
Understanding of security frameworks and standards such as NIST CSF and ISO 27001/27002
Familiarity with controls supporting SOC 1, SOC 2, PCI, and HIPAA
Ability to investigate technical issues, document findings clearly, and communicate security risk effectively
Professional proficiency in English
Nice to Have
Experience integrating security scanning, alerting, ticketing, or security gates into CI/CD pipelines
Security automation or scripting experience using Python, PowerShell, or Bash
Hands-on experience with OneTrust
Experience conducting STRIDE threat modeling and security risk assessments
Exposure to AI security, Agentic AI risks, or AI red-team testing
What Success Looks Like
In your first few months, you’ll become familiar with our security environment, tooling, incident response processes, and vulnerability management program while contributing directly to investigations and security assessments.
As you grow into the role, you’ll take ownership of security initiatives, improve vulnerability and risk-management processes, develop threat models for new technologies—including AI-enabled solutions—and identify opportunities for automation.
Over the course of the contract, you’ll help improve security signal quality, strengthen incident response readiness, reduce recurring risks, and become a trusted security partner to our Engineering, Cloud, and IT teams.
Compensation
The expected base salary range for this 17-month contract position is C$87,500–C$108,300, and individuals may also be eligible to participate in our variable compensation program.
Final compensation may vary based on experience, skills, designations, and market conditions.
This posting is for an existing vacancy and is offered as a 17-month contract position.
This hiring process utilizes artificial intelligence tools to assist in candidate screening and assessment. Our AI tools are designed to complement, not replace, human decision-making.