Your career compass awaits
Create a free account to unlock
- ✓ See how you match this role
- ✓ AI resume tailored to this specific job
- ✓ Inside Track Companion — find your insider contact
- ✓ Skills gap analysis and upskill plan
- ✓ Interview prep kit for this role
- ✓ Relocation concierge — salary, tax, cost of living
Free — no credit card required
Confirm Application
Are you applying to ?
We'll track this in your dashboard as Applied.
Senior Security Engineer
ICT
Company shared salary
NA
Market rate
12,000 CAD–20,000 CAD/mo (144,000 CAD–240,000 CAD/yr)
Based on similar roles (title + domain + location).
About the Company
Forma.ai is a Series B startup that's revolutionizing how sales compensation is designed, managed and optimized. We handle billions in annual managed commissions for market leaders like Edmentum, Stryker, and Autodesk. Our growth has been fuelled by our passion for fundamentally changing and shaping how companies use sales intelligence to drive business strategy. We're welcoming equally driven individuals who are excited about creating something big
Responsibilities
- ● Design and implement security controls across Forma's AWS environments, with a focus on IAM, least-privilege access, service identities, and account boundaries.
- ● Embed security requirements into Terraform and other Infrastructure as Code, and improve secrets, certificate, encryption-key, and credential management.
- ● Build automated checks for insecure configurations, excessive permissions, exposed resources, and configuration drift across Kubernetes, containers, serverless workloads, networking, and data services.
- ● Run threat modelling and security architecture reviews for new products, services, APIs, data pipelines, and third-party integrations.
- ● Strengthen tenant isolation, authorization enforcement, and fine-grained data access controls at the schema, table, row, and column level.
- ● Help protect sensitive compensation, financial, customer, and employee data across databases, data warehouses, S3, analytics services, and internal tools, including logging and auditability for sensitive-data access.
- ● Review AI and agentic workflows for data leakage, prompt injection, insecure tool use, and excessive permissions; ensure agents operate strictly within the calling user's permissions; and define secure patterns for approved services such as Amazon Bedrock.
- ● Identify and help remediate application vulnerabilities, and build tooling and reusable libraries that make the secure path the easy one for engineers.
- ● Embed security testing into CI/CD - static analysis, dependency and container scanning, secrets detection, Infrastructure as Code scanning, and dynamic testing - without creating unnecessary friction for developers.
- ● Define practical vulnerability-severity, remediation, exception, and escalation standards, and partner with developers to separate real risk from noise and fix root causes.
- ● Improve software supply-chain security, including build permissions, artifact integrity, dependency governance, and GitHub administration.
- ● Improve security visibility across cloud infrastructure, applications, identities, endpoints, and SaaS systems, and build alerts and detection logic that are worth acting on.
- ● Lead investigations and coordinate incident response efforts.
⚡ Full Resume Sandbox Canvas