Infrastructure & Security Engineer
About Purelend
Purelend is an early‑stage company operating at the frontier of Fin Tech and AI. Our platform handles some of the most sensitive data in a person's life (SINs, bank statements, T4s, NOAs, mortgage applications) on behalf of brokers, lenders, and regulated financial institutions across Canada.
Our AI StanceWe're all in on AI, and not just in the product. Engineering, infrastructure, design, customer support, sales: every function here uses the best AI tooling we can find to maximize quality and throughput on a small team. We're looking for someone who wants to help us push that bet further inside platform and security work too, not someone who's skeptical of it.
The RoleWe're hiring a senior or staff‑level engineer to drive infrastructure and security as a single, coupled discipline, working closely with the CTO. Together you'll shape how we run our services, how we protect customer data, how we prove that protection to lenders and auditors, and how we keep the rest of the team moving fast without compromising any of it.
What You'll Actually Do Cloud InfrastructureYou'll drive how we deploy, scale, and operate every service we ship. We're already on Terraform with a real codebase you'll extend and harden, raising the bar on modules, review, and drift detection, and keeping deploys boring: safe by default, fast to roll forward, fast to roll back.
Data ProtectionThe data we hold matters. You'll drive our encryption posture, key management, secret rotation, tokenization for the most sensitive fields, and the auditability that comes with all of it. When a lender asks “how do you protect a SIN from the moment it enters your system,” you'll be able to answer with a diagram, not a marketing slide.
Identity, Access, and AuthorizationYou'll drive how humans and services get access to data and systems: SSO, MFA enforcement, RBAC and ABAC inside the product, least‑privilege everywhere, and a clean answer to the question “who saw what, when” for any record in the system.
Compliance and Control HygieneOur customers are regulated Canadian financial institutions, including federally regulated Schedule I banks, and we operate accordingly. SOC 2, PIPEDA, vendor risk questionnaires, and lender‑specific controls are part of every enterprise deal, and we run the program in a manner consistent with OSFI's expectations of third‑party technology providers — specifically Guideline B‑13 (Technology and Cyber Risk Management) and Guideline B‑10 (Third‑Party Risk Management).
We're inside our SOC 2 audit window, running the program on Vanta. You'll drive it from here: carrying us through the audit, maturing the program afterwards, and making sure the controls map to real engineering practices so the evidence is a byproduct of how we already work.
You'll work alongside the product engineers on threat models for new features, especially anything touching AI, third‑party integrations, or customer data exports. You'll drive the guardrails: SAST and dependency scanning calibrated to be useful rather than noisy, secrets scanning, dependency review, and a sane vulnerability response process for when something does surface.
Observability and Incident ResponseYou'll drive our logging, tracing, and alerting, keeping it useful for the on‑call engineer instead of noisy enough to be ignored. You'll run the postmortem when something does go wrong, and make sure the same mistake isn't possible twice.
Detection and ResponseYou'll drive the detection capability that catches suspicious activity inside the product (anomalous data exports, credential stuffing attempts, lateral movement) and the runbooks the team uses when something fires.
What You Bring- 7–12 years of experience across infrastructure, platform, or security engineering. You've been the senior or staff engineer accountable for the production environment of a real product. Bonus if some of that experience was at a fintech, payments company, health tech company, or any business where one mistake on the security side ends the business.
- Deep cloud experience on AWS, GCP, or Azure. You can argue why you'd pick one over another for a specific…
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search: