Senior Security Engineer, Security Assurance

7 days ago


Canada ? Grafana Enterprise Full time $165,882 - $199,058
Senior Security Engineer, Security Assurance (Remote, Canada EST) This is a remote position and we are looking for candidates in Canada Eastern timezones. About the team

The Security team advances Grafana's overall security posture through critical initiatives and coordination of large security projects. We build technologies, tools, and processes to enable engineering squads to better develop secure software, protect customer and employee data, deploy systems with appropriate security controls, and securely operate a remote workforce.

We are building a security system that's automated at scale, rigorously data-driven, and built from the ground up with defense-in-depth and self-healing in mind. This system will support a highly autonomous, remote-first, cloud-native organization. We're taking the best of open-source and commercial tooling and making them talk to each other to arrive at some very special outcomes. We also want to open-source as much of our work as possible to security practitioners.

To support our growth and ambitious vision, we embrace agile principles and values, share openly, apply context-driven security mechanisms, default to action, and have an OSS-first mindset. We are a 100% remote company.

For all that, we believe absolutely in agreeing on high-velocity but reasonable expectations and timeframes and giving people the room to do great work in a setting that prioritizes health, happiness, and work-life balance.

Role

The Senior Security Assurance Engineer will collaborate with teams in engineering, security, cloud platforms, information technology, vendor management, and other stakeholders to articulate security policies, implement continuous monitoring, automate workflows, and configure alerts on policy failures.

Ideally, you would be familiar with operating in a cloud-native, remote organization. This is an opportunity to help implement a security strategy and build the underlying platforms and workflows.

You will get to work on expanding the capabilities of our asset intelligence and governance program, security posture monitoring, compliance automation, customer security observability automation, and supplier security monitoring. Think about all the layers to build observability for system uptime, but now extending that to other layers of security that impact confidentiality and integrity (encryption, access control, incident response, etc.).

While deep knowledge of security standards and frameworks is essential for this role, you should also have provable experience automating security posture management, automating repetitive processes, and maximizing the suite of Grafana products to build self-serve security posture observability. You will work alongside other security engineers, full-stack developers, and customer-facing teams.

This is an individual contributor role reporting to the Director of Security Assurance.

Responsibilities

A successful candidate in this role would be able to:

  • Work autonomously to develop, build, and roll out information, cyber, open source, and cloud security governance frameworks.
  • Design, build, launch, and scale the asset intelligence & governance program on Grafana.
  • Establish a cadence for security program reviews, support existing accreditations, and identify strategic maturity opportunities for compliance.
  • Design and deliver monthly technology and security risk management workshops.
  • Build reasonable and self-serve partnerships with cross-functional stakeholders who are decision-makers and contributors to security initiatives.
  • Socialize and provide awareness of policies, standards, processes, and controls with relevant stakeholders.
  • Serve as the security SME to partner with engineering and operations teams on the business continuity and disaster readiness program.
  • Design, build, and manage Security GRC and Disaster Readiness reporting metrics and dashboards.
What you'll bring to the role

This role would be a good fit for you if you:

  • Are comfortable working in a remote-first company and understand the importance of adapting and contextualizing the security controls.
  • Enjoy learning, growing, and supporting others to do the same.
  • Be very comfortable with at least one scripting language and a query language like SQL.
  • Enjoy navigating cloud-native environments and building automated processes for security posture management, compliance engineering, and continuous controls monitoring (indicative platforms and tools include GCP, AWS, Azure, Kubernetes, cloudquery, Grafana, LogicGate, Secureframe, Jira, ServiceNow GRC, , Drata, Vanta).
  • Have some experience working with Platform and Security to scope, operationalize, and scale Business Impact Assessments (BIAs), Business Continuity Management Systems (BCMS), and Disaster Readiness Strategies for cloud-first companies.
  • Know how to define a project plan, milestones, and key performance indicators to determine the effectiveness of your work delivery.
  • Enjoy working on complex solutions – Grafana is a highly technical solution with avid followers who rely on it everyday and care deeply about their workflows.
  • Enjoy working autonomously . While we defer to collaboration and teamwork, you should enjoy taking a problem and autonomously designing the solution, engaging the right stakeholders, and demonstrating the "own it" mindset to run through implementation.
  • Have an interest in Grafana's stack and a desire to contribute to our open-source foundations - We love dogfooding and giving back
  • Are able to communicate clearly in written and spoken English.
  • Can create impact in a pragmatic, structured, simple and quick way.
Education
  • BS/MS degree in engineering, computer science, or information security, or equivalent experience.
  • CISSP, CISA, CISM, and cloud security solutions are a plus.

In Canada, the Base compensation range for this role is CAD 165,882 - CAD 199,058 . Actual compensation may vary based on level, experience, and skillset as assessed in the interview process. Benefits include equity, bonus (if applicable) and other benefits listed here .

*Compensation ranges are country-specific. If you are applying for this role from a different location than listed above, your recruiter will discuss your specific market's defined pay range & benefits at the beginning of the process.

About Grafana Labs: There are more than 20M users of Grafana, the open source visualization tool, around the globe, monitoring everything from beehives to climate change in the Alps. The instantly recognizable dashboards have been spotted everywhere from a NASA launch and Minecraft HQ to Wimbledon and the Tour de France. Grafana Labs also helps more than 3,000 companies -- including Bloomberg, JPMorgan Chase, and eBay -- manage their observability strategies with the Grafana LGTM Stack, which can be run fully managed with Grafana Cloud or self-managed with the Grafana Enterprise Stack , both featuring scalable metrics (Grafana Mimir ), logs (Grafana Loki ), and traces (Grafana Tempo ).

Benefits: For more information about the perks and benefits of working at Grafana, please check out our careers page .

About Grafana Labs: There are more than 20M users of Grafana, the open source visualization tool, around the globe, monitoring everything from beehives to climate change in the Alps. The instantly recognizable dashboards have been spotted everywhere from a NASA launch and Minecraft HQ to Wimbledon and the Tour de France. Grafana Labs also helps more than 3,000 companies -- including Bloomberg, JPMorgan Chase, and eBay -- manage their observability strategies with the Grafana LGTM Stack, which can be run fully managed with Grafana Cloud or self-managed with the Grafana Enterprise Stack , both featuring scalable metrics (Grafana Mimir ), logs (Grafana Loki ), and traces (Grafana Tempo ). Benefits: For more information about the perks and benefits of working at Grafana, please check out our careers page . Equal Opportunity Employer: At Grafana Labs we're building a company where a diverse mix of talented people want to come, stay, and do their best work. We know that our company runs on the hard work and the dedication of our passionate and creative employees. If you're excited about this role but your experience doesn't align perfectly with every qualification in the job description, we encourage you to apply anyways.

We will recruit, train, compensate and promote regardless of race, religion, color, national origin, gender, disability, age, veteran status, and all the other fascinating characteristics that make us different and unique. We believe that equality and diversity builds a strong organization and we're working hard to make sure that's the foundation of our organization as we grow.

For information about how your personal data is used once you've applied to a job, check out our privacy policy .

Do you possess a minimum of 5 years of experience with scripting languages like Python? *
--

Have you had experience using Cloudquery? *
--

Are you currently eligible to work in your country of residence? *
--

Do you now or in the future require visa sponsorship to continue working in your country of residence? *
--

Were you referred to this role by a Grafanista? If so, let us know their name

Anything else you'd like to share with our hiring team?

Diversity & Inclusion Survey

At Grafana Labs, we strive to ensure we grow in a way that represents the world in which we live. To help us learn more about how we can increase diversity in our candidate pool, we invite you to voluntarily provide demographic information in a confidential survey. Providing this information is optional. It will not be used in the hiring process, and has no effect on your opportunity for employment.

By voluntarily providing information and submitting your application, you explicitly consent to the collection of race, ethnicity, gender identity, and disability information and use of this information as described above .

What gender identity do you most closely identify with? (Select one) *
Agender
Genderfluid
Gender non-conforming
Genderqueer
Man
Non-binary
Woman
Not listed
I don't wish to answer
Are you a person of transgender experience? (Select one) *
Yes
No
I don't wish to answer
Which race and ethnicity group or groups do you identify with? (Select one) *
Asian: East Asian
Asian: South Asian
Asian: South East Asian
Asian: Central Asian
Black: African Heritage
Black: Caribbean Heritage
Black: Afro-Latinx Heritage
Indigenous
Latinx or Latin American
North African and West Asian also known as Middle Eastern
Pacific Islander (including Micronesia, Melanesia, and Polynesia)
Traveller or Roma (including Sinti, Irish Traveller)
White: Northern Europe
White: Western Europe
White: Southern Europe
White: Central and Eastern Europe
White: American
White: Australian
Self-describe
I don't wish to answer
Do you have a visible or non-visible disability? *
Yes, visible disability
Yes, non-visible disability
No
I don't wish to answer
#J-18808-Ljbffr

  • Canada Abnormal Security Corporation Full time

    Enterprises of all sizes trust Abnormal Security's cloud products to stop cybercrime. These products are data intensive SaaS applications that depend on reliable, scalable, and secure access to data. This is where our Data Platform team fits in, enabling efficient, reliable and scalable data processing across both realtime and offline processing systems....


  • Canada LZ Security & Service GmbH Full time

    Grammarly team members in this role must be based in the United States, and they must be able to collaborate in person 2 weeks per quarter, traveling if necessary to the hub(s) where the team is based. From instantly creating a first draft to perfecting every message, Grammarly's product offerings help people at 96% of the Fortune 500 get their point...

  • Security Engineer

    7 days ago


    Canada Security Bank & Trust Co. Full time

    The Security Engineer role at Cover Genius involves enhancing the company's security posture through strategizing and implementing security measures, managing employee compliance, and conducting security testing. Knowledge of information security standards is critical, and the role requires familiarity with identity providers such as Okta. Daily...


  • Canada Elastify Full time

    Senior Network Security Engineer (Contract) Elastify is looking for a Senior Network Security Engineer for a remote 6 month contract.Experience with general network management and support: TCP/IP, DNS, firewall, VPN, routing, ingress + egress, network policy, load balancer, SSL certs management, etc Any automation experience Seniority level Mid-Senior...


  • Canada Shopify Full time

    About the roleAs part of the Trust Assurance team, you'll be a key player in engineering and operating the compliance program that governs Shopify's platform and products. The role is ideal for a candidate with senior level technical experience and a strong understanding of information security concepts - ideally developed in a fast-paced,...


  • Canada Shopify Full time

    About the roleAs part of the Trust Assurance team, you'll be a key player in engineering and operating the compliance program that governs Shopify's platform and products. The role is ideal for a candidate with senior level technical experience and a strong understanding of information security concepts - ideally developed in a fast-paced,...


  • Canada LZ Security & Service GmbH Full time

    Elastic is seeking a Senior Security Data Scientist to join their AI-driven Security Solutions team focusing on developing ML models to secure users against emerging threats. The role involves contributing to ML solutions, performing data analysis, and collaborating with various team members to maintain and improve ML models. Essential skills include...


  • Canada Practice Better Full time

    Job Title: Senior Security EngineerLocation: Candidate must be located in Canada or the USA. Our office is located in Toronto, ON, Canada, but the role is remote/hybrid/flexible.Reports to: VP, Engineering, Product, Design, Security and ITPosition Overview:Practice Better is a leading modern health and wellness management platform dedicated to providing...


  • Canada Techedinlabs Full time

    Save this job with your existing LinkedIn profile, or create a new one. Save this job with your existing LinkedIn profile, or create a new one. Your job seeking activity is only visible to you. Email Welcome back Sign in to save Information Security Engineer at Techedin . Explore the opportunity to join us as an Information Security Engineer in Canada....


  • Canada DataVisor Inc. Full time

    DataVisor is the leading AI-powered Fraud and Risk Platform globally. Our innovative solution provides top-notch detection coverage in the industry.Our open SaaS platform allows easy consolidation and enrichment of data, scaling infinitely to combat fraud and money laundering in real-time.Utilizing patented unsupervised machine learning, advanced device...


  • Canada ? Grafana Enterprise Full time $165,882 - $199,058

    Senior Security Engineer, Security Assurance (Remote, Canada EST) This is a remote position and we are looking for candidates in Canada Eastern timezones. The Security team advances Grafana's overall security posture through critical initiatives and coordination of large security projects. We build technologies, tools, and processes to enable engineering...


  • Canada Nomadgao Full time

    May 17, TuneIn is hiring a remote Senior Security Engineer. At TuneIn, we are reinventing radio for a connected world with live sports, up-to-the-minute news, curated music, millions of podcasts, and over 120,000 streaming radio stations—streamed to tens of millions of customers through our mobile and web apps, and our unmatched platform of hundreds of...


  • Canada Armour Security Full time

    Full time | Armour Security and Protection Services Corp | Canada Posted On 03/19/2024 Job Information Security/Law Enforcement Work Experience 1-3 years 22.00 City BURNABY State/Province British Columbia V5X 2M5 Job Description The Field Security Supervisor is an employee who is highly informed of Armour policies and procedures. This employee...


  • Canada Jane Full time $117,100

    Embark on a pivotal journey with Jane as our new Senior Security Engineer for our Cybersecurity team, where your expertise in penetration testing, security tooling, and standards will not only fortify our digital fortress but also transform our security culture. In this vital role, you'll help lead technical initiatives, enlighten our team with your...

  • Security Engineer

    7 days ago


    Canada Jane Full time $146,400

    Embark on a pivotal journey with Jane as our new Staff Security Engineer for our Cybersecurity team, where your profound expertise in penetration testing, security tooling, and standards will not only fortify our digital fortress but also transform our security culture. In this vital role, you'll lead technical initiatives, enlighten our team with your deep...


  • Canada Scotiabank Full time

    Requisition ID: #Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.The TeamScotiabank's Cloud Security Engineering Team is responsible for leading security engineering and cross-functional product teams to accelerate the build of global security services, advance engineering capabilities, and work with...


  • Canada Fireflies Full time

    integrates with all the major video-conferencing platforms including Zoom, Google Meet, Teams, Webex, and more. The Security Engineering Team is at the forefront of protecting and its users by ensuring the security of our infrastructure and data. We are looking for a creative hustler who is not just technically proficient but also a great team player and...


  • Canada Elastify Full time

    Elastify is looking for a Senior Network Engineer for a hybrid 3 month contract with a client in the Greater Toronto Area. Maintain and configure on-premise firewalls (Palo Alto, Juniper) to ensure network security and compliance. Establish and manage secure IPSec tunnels for data transmission between sites. Design and implement efficient routing protocols...


  • Canada CaseWare International Full time

    Caseware is one of Canada's original Fintech companies, having led the global audit and accounting software industry for over 30 years, with more than 500,000 users across 130 countries and available in 16 different languages. While you might not have heard of us (yet) over 36,000 accounting and audit professionals list Caseware as a skill on their LinkedIn...


  • Canada Nomadgao Full time

    Jan 15, BenchSci is hiring a remote Senior Software Security Engineer. ????Location: Canada. We are looking for a SeniorSecurity Engineer to join our growing Security team You will report to the Engineering Manager for Security. You will ensure BenchSci's services are implemented to the highest security standards. You will also analyze the security of...