Staff Security Engineer, Offensive Security

4 weeks ago


Canada Shopify Full time
About the roleCompany Description

About Shopify

Opportunity is not evenly distributed. Shopify puts independence within reach for anyone with a dream to start a business. Since 2006, we've grown to over 10,000 employees and generated over $500 billion in sales for millions of merchants in 175 countries. Every 28 seconds, an entrepreneur on Shopify makes their first sale.

This is life-defining work that directly impacts people's lives as much as it transforms your own. This is putting the power of the few in the hands of the many, is a future with more voices rather than fewer, and is creating more choices instead of an elite option.

About you
Moving at our pace brings a lot of change, complexity, and ambiguity—and a little bit of chaos. Shopifolk thrive on that and are comfortable being uncomfortable. That means Shopify is not the right place for everyone.

Before you apply, consider if you can:

  • Care deeply about what you do and about making commerce better for everyone
  • Excel by seeking professional and personal hypergrowth
  • Keep up with an unrelenting pace (the week, not the quarter)
  • Be resilient and resourceful in face of ambiguity and thrive on (rather than endure) change
  • Bring critical thought and opinion — and embrace differences and disagreement to get shit done and move forward
  • Work digital-first for your daily work
Job Description

As a Staff Security Engineer focusing on Offensive Security, you'll work cross-functionally with our engineering teams to build a comprehensive Offensive Security program.

Our Trust team works every day to create strong defenses that safeguard the trust that merchants place in our platform. As part of this team we need a creative, highly technical, passionate, and resourceful person to help us actively stress our defenses, with exceptional communication and interpersonal skills to drive real improvements from our work.

You'll be responsible for designing and operating red team exercises, researching emerging threats, creating and improving offensive tooling, and collaborating to turn findings into better security.

You will:

  • Design and execute exercises based on emerging threats
  • Research and leverage novel attack techniques
  • Automate and develop tooling for offensive security operations
  • Generate clear and concise intelligence from offensive exercises
  • Collaborate with other teams to enhance our defenses, detections and response
  • Be accountable for the technical leadership of this workstream
  • Provide technical mentorship to others on the team
Qualifications
  • Be a constant learner, developing a deep understanding of technology across Shopify
  • Demonstrate skills and experience in designing and executing red team scenarios
  • Possess the technical expertise necessary to independently leverage exploits
  • Use strong communication skills to effectively convey findings and discuss solutions
  • Have the skills necessary (for example, proficiency in a scripting language) to develop effective tooling
  • Quickly and effectively take initiatives from an idea, through executing and extracting value.
  • Constantly looking for ways to elevate the team's capabilities through experience, skills, and mentorship.

It would be great if you had experience with some of:

  • Mac OS endpoint security configuration and tooling
  • Infrastructure security in cloud environments, such as GCP
  • Corporate SaaS platforms such as Okta, Google, Github, or others
  • Innovative and next generation social engineering techniques
  • Developing or deploying security testing tools
  • Common web application vulnerabilities such as XSS and CSRF


  • Canada Jane Full time $146,400

    Embark on a pivotal journey with Jane as our new Staff Security Engineer for our Cybersecurity team, where your profound expertise in penetration testing, security tooling, and standards will not only fortify our digital fortress but also transform our security culture. In this vital role, you'll lead technical initiatives, enlighten our team with your deep...


  • Canada Kroll Full time

    In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate...


  • Canada Kroll Full time

    In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate...

  • Security Engineer

    1 week ago


    Canada Jane Full time $146,400

    Embark on a pivotal journey with Jane as our new Staff Security Engineer for our Cybersecurity team, where your profound expertise in penetration testing, security tooling, and standards will not only fortify our digital fortress but also transform our security culture. In this vital role, you'll lead technical initiatives, enlighten our team with your deep...


  • Canada Kroll Full time

    In a world of disruption and increasingly complex business challenges, our professionals bring truth into focus with the Kroll Lens. Our sharp analytical skills, paired with the latest technology, allow us to give our clients clarity—not just answers—in all areas of business. We embrace diverse backgrounds and global perspectives, and we cultivate...

  • Security Engineer

    1 week ago


    Canada Security Bank & Trust Co. Full time

    The Security Engineer role at Cover Genius involves enhancing the company's security posture through strategizing and implementing security measures, managing employee compliance, and conducting security testing. Knowledge of information security standards is critical, and the role requires familiarity with identity providers such as Okta. Daily...

  • Security Engineer

    1 week ago


    Canada CaseWare Full time

    About the Job: Caseware is the leading global software provider for CPAs, auditors, risk, and governance professionals, and has been a key player in the audit and accounting software industry for over 30 years. They are looking for an experienced Security Engineer to join their team and enhance their cybersecurity posture through automation strategies. If...


  • Canada LZ Security & Service GmbH Full time

    Grammarly team members in this role must be based in the United States, and they must be able to collaborate in person 2 weeks per quarter, traveling if necessary to the hub(s) where the team is based. From instantly creating a first draft to perfecting every message, Grammarly's product offerings help people at 96% of the Fortune 500 get their point...


  • Canada Abnormal Security Corporation Full time

    About the Role Enterprises of all sizes trust Abnormal Security's cloud products to stop cybercrime. These products are data intensive SaaS applications that depend on reliable, scalable, and secure access to data. This is where our Data Platform team fits in, offering scalable storage systems (Postgresql, OpenSearch, Redis, Kafka, RocksDB), as well as...


  • Canada CaseWare International Full time

    Caseware is one of Canada's original Fintech companies, having led the global audit and accounting software industry for over 30 years, with more than 500,000 users across 130 countries and available in 16 different languages. While you might not have heard of us (yet) over 36,000 accounting and audit professionals list Caseware as a skill on their LinkedIn...


  • Canada Armour Security Full time

    Full time | Armour Security and Protection Services Corp | Canada Posted On 03/19/2024 Job Information Security/Law Enforcement Work Experience 1-3 years 22.00 City BURNABY State/Province British Columbia V5X 2M5 Job Description The Field Security Supervisor is an employee who is highly informed of Armour policies and procedures. This employee...


  • Canada Abnormal Security Corporation Full time

    Enterprises of all sizes trust Abnormal Security's cloud products to stop cybercrime. These products are data intensive SaaS applications that depend on reliable, scalable, and secure access to data. This is where our Data Platform team fits in, enabling efficient, reliable and scalable data processing across both realtime and offline processing systems....

  • Security Engineer

    1 week ago


    Canada NewPage Solutions Full time

    Who Are We? NewPage is a digital health solutions company. We devote ourselves to advancing the quality of life by enhancing the health and optimizing the longevity of people. We do this by, passionately buildingfuturistic technologies for global organizations across the healthcare ecosystem. We partake at everystage from problem definition, strategy &...


  • Canada CaseWare International Full time

    Caseware is one of Canada's original Fintech companies, having led the global audit and accounting software industry for over 30 years, with more than 500,000 users across 130 countries and available in 16 different languages. While you might not have heard of us (yet) over 36,000 accounting and audit professionals list Caseware as a skill on their LinkedIn...


  • Canada Paragon Security Full time

    **Why Paragon?** **Benefits**: Unionized Group benefits includes: - Medical Insurance - Life Insurance - Dental Insurance - Vision Insurance. - Paid On-site training and additional training according to site requirements. - Yearly uniform allowance - Paid Sick Days - Employee incentive programs - Peer recognition programs. **Position Overview**: - **...


  • Canada Paragon Security Full time

    Why Paragon?Benefits:Unionized Group benefits includes: Medical Insurance Life Insurance Dental Insurance Vision Insurance. Paid Onsite training and additional training according to site requirements. Yearly uniform allowance Paid Sick Days Employee incentive programs Peer recognition programs.Position Overview:- Position: Full Time, Permanent Security...


  • Canada Identigate Security Services Inc. Full time

    Identigate Security Services Inc., a leader in security solutions, is dedicated to the safety and well-being of our clients. Specializing in providing exceptional security services tailored to the unique needs of each client.Position: Security Supervisor - Condominium Building ConciergeLocation: Mississauga, ONJob Description:In the role of Security...


  • Canada Identigate Security Services Inc. Full time

    Identigate Security Services Inc., a leader in security solutions, is dedicated to the safety and well-being of our clients. Specializing in providing exceptional security services tailored to the unique needs of each client. Security Supervisor - Condominium Building Concierge In the role of Security Supervisor, you will maintain a secure and welcoming...


  • Canada Identigate Security Services Inc. Full time

    Identigate Security Services Inc., a reputable company specializing in security solutions, is deeply committed to ensuring the safety and well-being of our valued clients.Position:Security Supervisor - Condominium Building ConciergeLocation: Mississauga, ONRole Overview:As a Security Supervisor, you will play a crucial role in maintaining a secure and...


  • Canada Jane Full time $117,100

    Embark on a pivotal journey with Jane as our new Senior Security Engineer for our Cybersecurity team, where your expertise in penetration testing, security tooling, and standards will not only fortify our digital fortress but also transform our security culture. In this vital role, you'll help lead technical initiatives, enlighten our team with your...