# Senior Security Developer, Vulnerability Management
**Company:** [Wealthsimple Technologies](https://scaleengineer.com/companies/wealthsimple)
Senior Security Developer at Wealthsimple leading the design and development of an AI-assisted vulnerability management platform. This role focuses on building automation-first systems for vulnerability triage, remediation tracking, and integration across security scanners and CI/CD pipelines. You'll work with advanced AI tools and security orchestration platforms to transform manual vulnerability management into a self-running system handling the full lifecycle from discovery through patching.
**Role:** Security Engineer
**Seniority:** Senior
**Locations:** Remote (Canada)
**Remote:** yes
**Salary:** 151200–189000 CAD
[Apply](https://jobs.ashbyhq.com/wealthsimple/b4b935a0-9788-4215-998d-bef83b2c9b72)
Canonical: https://scaleengineer.com/jobs/wealthsimple/senior-security-developer-vulnerability-management
---
## Responsibilities

- Own and Evolve Custom VM Platform: Design, architect, and maintain the custom vulnerability management platform including deployment infrastructure, data models, API integrations, and automation workflows. Shape the platform's growth trajectory as a greenfield opportunity, ensuring scalability and developer-friendly interfaces for security teams.
- Build End-to-End Automation Workflows: Design and implement automation across the complete vulnerability management lifecycle including triage automation, intelligent ticket routing, SLA tracking, ownership resolution, and automated follow-up. Leverage Claude Code and Tracecat to create self-executing workflows that minimize manual intervention.
- Integrate Scanner Data and Enrichment Pipelines: Develop integrations with vulnerability scanners (Tenable, Semgrep, Rapid7) via APIs and maintain data enrichment workflows that transform raw scanner findings into actionable, prioritized tickets. Ensure data quality and context enrichment at each pipeline stage.
- Expand Platform Adoption Across Engineering: Translate the platform from a single-team workflow to an organization-wide solution. Collaborate with engineering teams to bake vulnerability management into existing processes, gather feedback, and iterate on user experience to drive adoption and engagement.
- Build Visibility and Reporting Infrastructure: Create queries, dashboards, and automated reports that provide the security team and leadership with clear visibility into vulnerability posture, metrics, and trends. Enable data-driven decision-making on security priorities and resource allocation.
- Maintain Infrastructure as Code for Patching: Manage patch management for GitHub Actions workflows, ArgoCD configurations, Kubernetes clusters, AMIs, and container images (ECR). Understand and communicate the security implications of infrastructure components and their vulnerability exposure.
- Facilitate Developer-Security Collaboration: Work directly with development teams to address vulnerability disputes, explain findings, verify remediation efforts, and translate security findings into developer-friendly context. Build bridges between security and engineering perspectives on risk and remediation.
- Monitor AI Security Landscape Developments: Stay current on emerging threats including the growing role of AI in vulnerability research and exploitation. Factor threat landscape insights into platform prioritization, feature development, and risk assessment methodologies.

## Requirements

### education

- {"name":"Bachelor's Degree in Computer Science or Related Field","description":"Formal education in computer science, cybersecurity, information security, or related discipline. Equivalent practical experience in security engineering or vulnerability management can substitute for formal education."}

### technical

- {"name":"Vulnerability Management Platform Experience","description":"4+ years of hands-on vulnerability management and/or security engineering experience including scanner integration, triage workflow design, and remediation tracking. Deep familiarity with VM tooling such as Tenable, Semgrep, Rapid7, or comparable SAST/DAST/SCA solutions and ability to build custom integrations via REST APIs."}
- {"name":"AWS and Infrastructure Automation","description":"Production-level AWS experience combined with hands-on familiarity with GitHub Actions, ArgoCD, Kubernetes, AMIs, and container images (ECR or equivalent). Understanding of how infrastructure components carry patch management burden and vulnerability exposure."}
- {"name":"Security Tooling and Protocols","description":"Deep knowledge of vulnerability classes across application and infrastructure layers (XSS, CSRF, code vulnerabilities, container issues), OWASP fundamentals, and SAST/DAST/SCA tooling. Understanding of which scanners belong in CI, production, or network stages and how vulnerabilities translate to production risk."}
- {"name":"API Development and Integration","description":"Proven ability to build production integrations on top of external security tools via APIs. Experience with automation-first development, CLI tools, and workflow orchestration platforms."}
- {"name":"AI-Assisted Development","description":"Active, hands-on experience with AI-assisted development tools such as Claude Code, Cursor, or GitHub Copilot. Demonstrated ability to use these tools as force multipliers for productivity and code quality."}
- {"name":"Package and Dependency Management","description":"Understanding of the distinction between package and library vulnerabilities and where fixes belong in the dependency chain. Knowledge of container security, vulnerability inheritance across layers, and real-world exposure mapping."}

### experience

- {"name":"Vulnerability Management Program Leadership","description":"4+ years working with vulnerability management systems in production environments, including scanner configuration, integration, and maintenance. Experience taking vulnerability findings through triage, ownership assignment, and remediation workflows."}
- {"name":"Security Engineering Background","description":"Background in security engineering or application security with deep understanding of the software development lifecycle end-to-end. Ability to identify where vulnerabilities are introduced in development processes and recognize AI tool hallucinations versus real security findings."}
- {"name":"Platform Development and DevOps","description":"Experience building or evolving security platforms, with attention to user experience, adoption, and developer workflows. Familiarity with CI/CD, deployment pipelines, and infrastructure-as-code principles."}
- {"name":"Risk Assessment and Compliance","description":"Understanding of different compliance programs and vulnerability management controls. Experience making risk acceptance decisions based on actual exposure rather than just CVE scores, with familiarity with vulnerability scoring frameworks (CVSS, EPSS, SSVC)."}

## Skills

### required

- {"name":"Vulnerability Management Systems","description":"Tenable, Semgrep, Rapid7, and comparable vulnerability scanners with API integration experience and practical understanding of scanner output, false positive rates, and remediation workflows."}
- {"name":"Python or Go","description":"Production-level proficiency in Python or Go for building automation, integrations, and CLI tools. Ability to write clean, maintainable code that handles real-world security data processing."}
- {"name":"AWS Cloud Services","description":"Production AWS experience including EC2, Lambda, RDS, S3, and IAM. Understanding of AWS security best practices and how cloud infrastructure relates to vulnerability management."}
- {"name":"GitHub Actions and CI/CD","description":"Hands-on experience with GitHub Actions for workflow automation. Understanding of CI/CD pipeline stages and where security scanning integrates most effectively."}
- {"name":"Kubernetes and Container Security","description":"Practical experience with Kubernetes for orchestration and understanding container security implications including image vulnerability scanning, runtime protection, and patching strategies."}
- {"name":"Security Automation Platforms","description":"Experience with security orchestration and automation (SOAR) platforms or workflow builders. Familiarity with Tracecat, Tines, XSOAR, or similar tools for building automated security responses."}
- {"name":"API Integration and Data Pipeline Design","description":"Proven ability to design and implement robust data pipelines that integrate multiple external APIs, handle error cases, and maintain data consistency across security systems."}
- {"name":"SAST/DAST/SCA Tool Expertise","description":"Hands-on exposure to static application security testing, dynamic application security testing, and software composition analysis tools with understanding of their strengths, limitations, and appropriate deployment contexts."}

### preferred

- {"name":"ArgoCD and GitOps","description":"Experience with ArgoCD or similar GitOps tools for managing infrastructure and deployment configurations, particularly in security contexts."}
- {"name":"Bug Bounty Program Management","description":"Experience running, integrating, or managing bug bounty or responsible disclosure programs through platforms like HackerOne. Understanding of vulnerability disclosure workflows and external researcher integration."}
- {"name":"Fintech or Regulated Industry Security","description":"Prior experience in fintech, financial services, healthcare, or other highly regulated industries where vulnerability management practices are critical and compliance requirements drive security controls."}
- {"name":"Vulnerability Scoring and Prioritization","description":"Familiarity with CVSS, EPSS, SSVC, or proprietary vulnerability prioritization frameworks. Experience translating scoring systems into practical remediation priorities."}
- {"name":"Open Source Security Contributions","description":"Active contributions to open-source security tooling, vulnerability databases, or security automation projects demonstrating commitment to the broader security community."}
- {"name":"Advanced AI-Assisted Development","description":"Deep experience leveraging Claude Code specifically or other advanced AI coding assistants to accelerate development, design automation workflows, and solve complex integration challenges."}
- {"name":"Threat Intelligence Integration","description":"Experience incorporating threat intelligence feeds into vulnerability management workflows or security orchestration systems to enhance prioritization and context."}

## Tech stack

### tools

- {"name":"Tenable Nessus/SecurityCenter","description":"Enterprise vulnerability scanner with API for collecting findings, creating integrations, and managing scanner policies."}
- {"name":"Semgrep","description":"Static analysis tool for code-level vulnerability detection with custom rule development and CI/CD integration capabilities."}
- {"name":"Rapid7 InsightVM","description":"Vulnerability management platform with extensive API capabilities for integration into custom workflows and automated remediation."}
- {"name":"AWS Services (EC2, Lambda, RDS, S3)","description":"Cloud infrastructure for deploying and scaling the vulnerability management platform with appropriate security controls."}
- {"name":"Kubernetes (EKS or Self-Managed)","description":"Container orchestration platform for deploying vulnerability management services and agents across infrastructure."}
- {"name":"ArgoCD","description":"GitOps continuous deployment tool for managing infrastructure configurations and security platform updates declaratively."}
- {"name":"GitHub Actions","description":"CI/CD automation platform for building, testing, and deploying security tooling with integrated vulnerability scanning."}
- {"name":"HackerOne","description":"Bug bounty and responsible disclosure platform for managing external vulnerability submissions and researcher engagement."}

### others

- {"name":"REST APIs","description":"Integration protocol for connecting vulnerability scanners, ticketing systems, deployment platforms, and other security tools into unified workflows."}
- {"name":"Containers and ECR","description":"Docker containers and Amazon ECR for packaging and deploying vulnerability management components with integrated scanning and patching."}
- {"name":"OWASP Fundamentals","description":"Security framework knowledge for understanding vulnerability classes, attack vectors, and remediation strategies across application and infrastructure layers."}
- {"name":"CVSS/EPSS/SSVC Scoring","description":"Vulnerability prioritization frameworks for determining severity, exploitability, and remediation urgency based on standardized metrics."}
- {"name":"Terraform or CloudFormation","description":"Infrastructure-as-code tools for defining cloud infrastructure, security policies, and vulnerability management platform deployment."}

### databases

- {"name":"PostgreSQL or MySQL","description":"Relational databases for storing vulnerability findings, remediation history, SLA tracking, and audit logs with complex querying requirements."}
- {"name":"Elasticsearch or Similar","description":"Search and analytics database for indexing and querying large volumes of vulnerability scan results and security events."}

### languages

- {"name":"Python","description":"Primary language for automation scripts, security tooling integrations, and backend services in the vulnerability management platform."}
- {"name":"Go","description":"Alternative or complementary language for building high-performance CLI tools and services within the security orchestration ecosystem."}
- {"name":"SQL","description":"Required for designing queries, building dashboards, and working with vulnerability data models in relational databases."}
- {"name":"YAML","description":"Configuration language for GitHub Actions workflows, ArgoCD configurations, Kubernetes manifests, and infrastructure-as-code definitions."}

### frameworks

- {"name":"Claude Code","description":"AI-assisted development environment used extensively within Wealthsimple for accelerating development and building automation workflows with code generation support."}
- {"name":"Tracecat","description":"Security orchestration platform used to build automated vulnerability remediation workflows and orchestrate responses across security tools."}
- {"name":"FastAPI or Django","description":"Python web frameworks for building APIs that integrate with vulnerability scanners and expose platform functionality to engineering teams."}
- {"name":"GitHub Actions","description":"Workflow automation platform for CI/CD pipelines, security scanning integration, and automated remediation triggers."}

## Benefits

### benefits

- {"name":"Comprehensive Health and Wellness Coverage","description":"Top-tier health benefits including medical, dental, and vision coverage. Life insurance provided. Unlimited sick days and mental health days per year to support employee wellbeing."}
- {"name":"Retirement and Savings Programs","description":"Long-term group savings plan through Wealthsimple for Business with employer matching contributions, allowing employees to invest with reduced fees."}
- {"name":"Generous Time Off","description":"20 vacation days annually plus 4 wellness days and unlimited sick/mental health days. 90-day work-from-anywhere program allowing remote work outside Canada for up to 90 days per year."}
- {"name":"Equity Compensation","description":"Stock options available as part of competitive compensation package, allowing employees to participate in company growth."}
- {"name":"Diversity and Inclusion Programs","description":"Active employee resource groups including Rainbow (2SLGBTQ+), Women of Wealthsimple, and Black at Wealthsimple. Commitment to building inclusive products and teams."}
- {"name":"Hybrid Work Environment","description":"Hybrid team structure with over 1,500 employees across North America. Flexibility to work in-office and remotely while collaborating with talented, driven teammates."}
- {"name":"Professional Development","description":"Culture of continuous learning with access to tools, resources, and support for evolving skills alongside rapidly changing technology landscape."}

## Compensation

- **max:** 200000
- **min:** 150000
- **currency:** CAD
- **stockOptions:** true

## Interview process

### steps

## Full description
## **Build something people love**

Wealthsimple is Canada’s leading financial innovator. The company offers a full suite of simple, sophisticated financial products across managed investing, do-it-yourself trading, cryptocurrency, tax filing, spending and saving. Wealthsimple currently serves more than 4 million Canadians and holds over $155 billion in assets under administration. The company was founded in 2014 by a team of financial experts and technology entrepreneurs, and is headquartered in Toronto, Canada.

We're proud of what we've built — and we're just getting started. Read our [Culture Manual](https://www.wealthsimple.com/en-ca/culture) and learn more about [how we work](https://www.wealthsimple.com/en-ca/careers).

# **About the Role**  

Most vulnerability management programs are still built around people manually triaging tickets and chasing down owners. We're taking a different approach: a platform that uses AI-assisted tooling to do a lot of that work for us, and this role is where that gets built. We want you to design the automations, integrations, and workflows that take those fundamentals further: less manual ticket routing, more systems that carry a finding through triage, ownership, and remediation on their own.  

The skill set we're after, automation-first thinking, developer-level reasoning, and the ability to build integrations across systems, is what turns a program from manual and reactive into something that runs on its own. That's the job: build the automation and integrations that let our VM tooling handle the load without a person in the loop at every step. We're also building deeper integration with our CRS (Cyber Reasoning System) harness, so a finding can move from triage through automated sandbox validation to a generated fix with less manual handling at each stage.  

**We use AI-assisted development tools heavily and expect you to use them too.**

## In this role, you will have the opportunity to:

* Own and evolve our custom VM platform, working on deployment, integrations, data model, and automation workflows. This is a greenfield opportunity to shape how the platform grows.
* Build automation across the full VM lifecycle: triage, ticket routing, SLA tracking, ownership resolution, and follow-up. We use Claude Code and Tracecat, and you'll be expected to use and extend both meaningfully.
* Take a platform built around one team's workflow to one that fits how the rest of engineering actually works. Get it in front of people, bake it into their existing processes, and make it something teams reach for.
* Integrate scanner data into our VM pipeline and maintain the enrichment workflows that turn raw findings into actionable tickets.
* Build the queries, dashboards, and automated reports that give the team and leadership clear visibility into vulnerability posture.
* Stay current on the threat landscape, especially the growing role of AI in vulnerability research and exploitation, and factor that into how we build and prioritize.
* Help build toward a future where a validated finding gets tested and patched by CRS in a sandbox, and comes back out as a PR, closing the loop with minimal manual work.

## **We are looking for someone who:**

* Is familiar with the software development lifecycle end to end, well enough to recognize where a vulnerability was actually introduced in the process and to tell when an AI tool is hallucinating a finding instead of catching a real one.
* Has 4+ years of hands-on vulnerability management and/or security engineering experience, including scanner integration, triage workflows, and remediation tracking. If vulnerability management isn't explicitly on your resume, you should be able to explain clearly why you understand it anyway.
* Has production AWS experience.
* Has a strong automation-first mindset. You've built things that replace manual processes.
* Has deep familiarity with VM tooling (Tenable, Semgrep, Rapid7, or comparable scanners) and knows how to build integrations on top of them via API.
* Understands the difference between package and library vulnerabilities well enough to know where a fix actually belongs, and understands vulnerability classes across application and infrastructure layers (XSS vs. CSRF, code vs. container issues) well enough to have a real conversation with a developer who disagrees with a finding. Knows which scanners belong at which stage of the pipeline (CI, production, network) and how a vulnerability actually ends up running in production, including in containers. Hands-on exposure to SAST/DAST/SCA tooling and OWASP fundamentals helps here.
* Has hands-on familiarity with GitHub Actions, ArgoCD, Kubernetes, AMIs, and container images (ECR or comparable). You'll need this to help maintain our VM platform, and because each of these carries its own patch management burden since they all run code.
* Understands attack surface and exposure management, including how a basic web app's architecture and traffic flow map to real risk. You'll be making risk acceptance calls, and that requires seeing the actual exposure, not just a CVE score.
* Can translate business and partner needs into solutions. You'll spend real time with developers who don't understand a finding, disagree with it, or say a fix didn't work, and you need to work through that without losing the thread.
* Has a strong understanding of the programs vulnerability management connects to: CI/CD and deployment pipelines, threat intelligence, and bug bounty or responsible disclosure programs. VM doesn't operate in a vacuum, and we want someone who understands the connections that exist today and the ones that should exist but don't yet.
* Is familiar with different compliance programs and vulnerability management controls.
* Is actively using AI-assisted development workflows (Claude Code, Cursor, Copilot, or similar) and treats them as a force multiplier, not a novelty.

## **Nice to have:**

* Experience with security orchestration platforms (Tracecat, Tines, XSOAR, or comparable).
* Experience with bug bounty or responsible disclosure programs like HackerOne.
* Familiarity with vulnerability scoring and prioritization frameworks (CVSS, EPSS, SSVC). This is quick to pick up on the job, so it's weighted lower than the items above.
* Experience in a fintech or regulated-industry environment.
* Open-source security tooling contributions.

## **Why Wealthsimple?**

🌸 Top-tier health benefits and life insurance

📈 Long-term group savings with employer match, through Wealthsimple for Business

🌴 20 vacation days, 4 wellness days, and unlimited sick and mental health days per year

✈️ 90 days away: work outside Canada for up to 90 days per year

👥 Employee resource groups, including Rainbow (2SLGBTQ), Women of WS, and Black at WS

🌎 We are a hybrid team with over 1,500 employees across North America. The people are one of the best parts of working here: you'll collaborate with incredibly talented, curious, and driven teammates who are deeply committed to doing great work.

## **ICYMI**

**Technology & Innovation at Wealthsimple:** We move quickly and build thoughtfully. That means we're always looking for better ways to work — whether that's new tools, AI, or rethinking how we approach a problem. We don't expect you to have all the answers, but we do expect curiosity and a willingness to evolve alongside the products we're building.

**Inclusion Statement:** We're building products for a diverse world, and we need a diverse team to do it well. We strongly encourage applications from everyone, regardless of race, religion, colour, national origin, gender, sexual orientation, age, marital status, or disability status.

**Accessibility Statement:** We're committed to an accessible hiring experience. If you need any accommodations throughout the interview process, please let us know — we'll work with you to make sure you have what you need. We also welcome any feedback on how we can better accommodate candidates with accessibility needs.

**AI in Hiring:** We may use artificial intelligence (AI) tools to support parts of our hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our team but don't replace human judgment – all final hiring decisions are made by people. If you have questions about how your data is used, reach out to us.
