×
Register Here to Apply for Jobs or Post Jobs. X

Senior Security Engineer

Job in Toronto, Ontario, C6A, Canada
Listing for: Forma
Full Time position
Listed on 2026-08-16
Job specializations:
  • IT/Tech
    Cybersecurity, Information Security & Data Protection, Cloud Computing: Infrastructure & Operations
Salary/Wage Range or Industry Benchmark: 160000 - 190000 CAD Yearly CAD 160000.00 190000.00 YEAR
Job Description & How to Apply Below

About Forma.ai:

Forma.ai is a Series B startup that's revolutionizing how sales compensation is designed, managed and optimized. We handle billions in annual managed commissions for market leaders like Edmentum, Stryker, and Autodesk.

Our growth has been fuelled by our passion for fundamentally changing and shaping how companies use sales intelligence to drive business strategy.

We’re welcoming equally driven individuals who are excited about creating something big!

The Opportunity

As a Senior Security Engineer, you will be a hands‑on technical leader strengthening security across Forma's application, cloud infrastructure, development lifecycle, internal systems, and incident‑response practices.

Security today is shared across Engineering and Dev Ops. You'll work closely with both teams and have real room to shape how Forma approaches security as we grow. Depending on your interests and the needs of the business, the role could develop into a deeper individual‑contributor position or help build a dedicated security team.

You'll work directly with Engineering, Dev Ops, IT, Product, Legal, and Privacy to identify risks, design practical controls, automate security processes, and help teams ship secure and reliable software.

What you'll do Cloud and infrastructure security
  • Design and implement security controls across Forma's AWS environments, with a focus on IAM, least‑privilege access, service identities, and account boundaries.
  • Embed security requirements into Terraform and other Infrastructure as Code, and improve secrets, certificate, encryption‑key, and credential management.
  • Build automated checks for insecure configurations, excessive permissions, exposed resources, and configuration drift across Kubernetes, containers, serverless workloads, networking, and data services.
Application, data, and AI security
  • Run threat modelling and security architecture reviews for new products, services, APIs, data pipelines, and third‑party integrations.
  • Strengthen tenant isolation, authorization enforcement, and fine‑grained data access controls at the schema, table, row, and column level.
  • Help protect sensitive compensation, financial, customer, and employee data across databases, data warehouses, S3, analytics services, and internal tools, including logging and auditability for sensitive‑data access.
  • Review AI and agentic workflows for data leakage, prompt injection, insecure tool use, and excessive permissions; ensure agents operate strictly within the calling user's permissions; and define secure patterns for approved services such as Amazon Bedrock.
  • Identify and help remediate application vulnerabilities, and build tooling and reusable libraries that make the secure path the easy one for engineers.
Dev Sec Ops  and secure delivery
  • Embed security testing into CI/CD — static analysis, dependency and container scanning, secrets detection, Infrastructure as Code scanning, and dynamic testing — without creating unnecessary friction for developers.
  • Define practical vulnerability‑severity, remediation, exception, and escalation standards, and partner with developers to separate real risk from noise and fix root causes.
  • Improve software supply‑chain security, including build permissions, artifact integrity, dependency governance, and Git Hub administration.
Detection, monitoring, and incident response
  • Improve security visibility across cloud infrastructure, applications, identities, endpoints, and SaaS systems, and build alerts and detection logic that are worth acting on.
  • Lead investigations and coordinate containment, remediation, and root‑cause analysis, supported by clear runbooks, ownership, and escalation paths.
  • Run tabletop exercises, and track and communicate security metrics and material risks to technical and business stakeholders.
Identity, governance, and enablement
  • Strengthen SSO, MFA, privileged access, and onboarding, offboarding, and access‑review processes across AWS, Git Hub, Microsoft 365, Entra , production systems, and internal SaaS — automating provisioning, entitlement reviews, and evidence collection where practical.
  • Translate security and compliance requirements into concrete technical controls, and…
Position Requirements
10+ Years work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary