Security Engineer, DevOps
Listed on 2026-06-21
-
IT/Tech
Cybersecurity, Systems Engineer
Salary Range
Salary Range: CA$ to CA$ annually
Curinos empowers financial institutions to put customers at the center of every decision. Our AI-first platform transforms proprietary data, advanced analytics and deep financial services expertise into timely recommendations - delivered right where teams work. The result: confident decisions, stronger customer relationships, and lasting, profitable growth.
Curinos operates under a hybrid modality and has office locations in New York, Chicago, Boston, Toronto, and London.
This role is open to remote candidates based in the Canada, Pacific Standard Time, preferred.
Curinos is looking for an experienced Senior Security Engineer to join our Information & Security team. Operating in an AWS-native environment with select on-premises workloads, this role drives and advances key security capabilities across cloud security posture management, vulnerability management, threat detection and detection engineering, application security, and incident response. The ideal candidate brings deep hands-on experience with modern cloud and security tooling, independent designs and implements solutions for new initiatives, and partners with engineering and operations teams to reduce risk across our hybrid environment.
Working closely with Information Security, IT, and Engineering teams, this role sets priorities within its areas of responsibility, drives remediation to closure, mentors more junior team members, and serves as a subject-matter expert on security issues.
- Run day-to-day security operations and engineering activities across our cloud and hybrid environment, prioritizing work across competing risks based on severity, timelines, and dependencies, and partnering with Information Security, IT, and Engineering teams to identify, drive, and verify remediation while continuously improving detection and response capabilities
- Monitor and respond to findings in AWS Security Hub and Amazon Guard Duty; tune and author detections to improve signal quality and reduce false positives, and define remediation standards that engineering teams can follow
- Independently manage cloud security posture using our CNAPP platform, setting risk prioritization criteria, driving remediation with asset owners, and grouping recurring findings to identify root causes and recommend preventative measures
- Drive the vulnerability management lifecycle using an enterprise platform, performing assessments, applying risk-based prioritization and SLAs, and driving findings to resolution across a mixed asset inventory; coordinate penetration tests and remediation of their results
- Design and embed application security controls within development pipelines, partner with product and platform engineers to design remediation solutions, clearly communicate implications and timing of decisions, and recommend enhancements to code resiliency
- Operate and improve endpoint and network detection and response tooling, develop and tune detections, lead telemetry and threat investigations end to end, and coordinate response
- Lead investigation and response for security incidents, including high-severity events; lead root-cause analysis and drive post-incident corrective actions to completion across the relevant teams.
- Define and report security posture metrics and KPIs; explain complex findings and their implications to technical peers, leaders, and stakeholders outside the team, and respond to targeted technical questions from external audiences such as auditors, clients, and vendors.
- Independently automate security operations using scripting and infrastructure-as-code, developing reusable tooling that improves team efficiency and consistency.
- Stay current with emerging threats, CVEs, and platform changes; evaluate new security tooling and methodologies through proofs-of-concept and recommend adoption where they reduce risk.
- Work cross-functionally with engineering, information technology, and infrastructure teams to consult on security matters and champion secure-by-design practices.
- Mentor and provide technical guidance on security matters to junior team members and advise engineering teams…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).