Director, Security Engineering

2 days ago


Remote Canada Vancouver BC or Toronto ON Pantheon Systems Full time $176,000 - $264,000 per year

About Pantheon

Pantheon WebOps Platform powers the open web, running more than 300,000 sites in the cloud for customers including Google, Princeton, Salesloft, and Doctors Without Borders. Every day, thousands of developers and marketers create, iterate, and scale WordPress and Drupal sites to reach billions of people globally. Pantheon's multitenant, container-based platform enables organizations to manage all of their websites from a single dashboard. Organizations, including Clorox and the United Nations, drive results through accelerated development and real-time publishing using Pantheon's collaborative workflows.

The Role

Pantheon is looking for a Director to join our Security team. We're expanding an impressive and growing platform that powers hundreds of thousands of websites, millions of containerized resources, billions of monthly page views, and development tools that professional website developers use.

As the Security Engineering Director, you will play a pivotal role in ensuring the security of the Pantheon Platform, safeguarding the thousands of websites hosted on Pantheon to create a safe and secure digital environment. This position holds paramount importance within the Security Organization, as you will collaborate closely with leaders across our Product and Engineering, Legal, and Governance, Risk, and Compliance teams. By leading initiatives in application and platform security, you will contribute directly to the reliability and resilience of our services, fostering a robust security culture within our engineering teams. This role is not only about fortifying our defenses but also about championing innovation, implementing best practices, and staying ahead of emerging threats to uphold Pantheon's commitment to excellence in digital security. This leader will ensure all application and platform security initiatives support and strengthen our ongoing compliance with standards like PCI-DSS Level 2 and SOC2 (Security, Confidentiality, and Reliability), directly impacting our trustworthiness with customers. Join us in this exciting opportunity to shape the future of secure web hosting and make a lasting impact on the digital experiences of our diverse user base.

What you Need to Succeed
  • Manage a high-performing team of security engineers, fostering a positive and collaborative environment
  • Responsible for managing the security engineering budget and the selection, deployment, and operation of security tools (like SAST/DAST, IAST, Cloud Security Posture Management - CSPM)
  • Collaborate with the Governance, Risk, and Compliance (GRC) team to translate regulatory requirements (like PCI-DSS and SOC2) into actionable engineering requirements and control implementation.
  • Develop and implement the company's security vision and roadmap, including a strong emphasis on "Shift Left" principles.
  • Perform security reviews to identify security issues and risks, and develop mitigation plans
  • Advise and consult with internal customers on risk assessment, threat modeling, code review, and vulnerability remediation
  • Drive the adoption of secure coding practices across the engineering organization through training, workshops, and mentorship.
  • In conjunction with Security Operations, investigate, respond, and communicate security incidents promptly and effectively, minimizing potential harm and ensuring swift resolution.
  • Partner with other engineering teams to integrate security considerations into their product roadmaps, design decisions, and development processes.
  • Identify and recruit talented security champions across various teams to serve as ambassadors and advocates for security best practices.
  • Stay current with the latest security threats, trends, and technologies, and actively explore innovative solutions for mitigating emerging risks.
  • Develop and deliver security training and outreach to internal development teams
  • Communicate effectively with stakeholders across all levels of the organization, providing clear and concise updates on security posture and initiatives.
What you Bring to the Table
  • 10+ years of experience in information security or a related field.
  • Excellent leadership skills and teamwork skills.
  • Industry-leading security certification, such as CISSP, CISM, or CSSLP.
  • Deep experience with major cloud platforms (e.g., AWS, GCP, Azure), including Infrastructure as Code (IaC) security (e.g., Terraform, CloudFormation)
  • Significant experience and detailed technical knowledge in multiple areas: security engineering, web encryption protocols, and application security.
  • Proven experience translating ISO 27001 or NIST controls into practical, engineering-focused security requirements.
  • Detailed knowledge of application and platform security vulnerabilities and remediation techniques
  • Proven experience leading and managing a team of security engineers.
  • Good understanding of "Shift Left" and Security by Design.
  • Extensive knowledge of web application security, common vulnerabilities, and relevant security tools.
  • Experience with secure coding practices and software development lifecycle (SDLC) integration.
  • Excellent communication, collaboration, and problem-solving skills.
  • Ability to work independently and prioritize effectively in a fast-paced environment.
  • Strong passion for security and a desire to create a secure and resilient technology ecosystem.
  • Experience with Cloud Security Posture Management (CSPM) and Cloud Workload Protection Platform (CWPP) tools (e.g., Wiz) is a strong plus.


What We Offer

We have all the usual perks and benefits but what we can really offer you is a fantastic work environment powered by an amazing team.

  • Industry competitive compensation and equity plan
  • Paid Time Off (PTO), Paid Sick Leave (PSL) and 11 Paid Company Holidays
  • Full medical coverage (Extended health care, dental, vision)
  • Top-of-line equipment
  • Monthly allowance for wellness, reading and access to LinkedIn Learning for continued development
  • Events and activities both team-based and company wide that inspire, educate and cultivate

Pantheon is an equal opportunity action employer and we welcome applications from all backgrounds regardless of race, color, religion, sex, national origin, ancestry, age, marital status, sexual orientation, gender identity, veteran status, disability, or any other classification protected by law. Pantheon complies with federal and local disability laws and makes reasonable accommodations for applicants and employees with disabilities. If you need a reasonable accommodation due to a disability for any part of the interview process, please contact Pursuant to local and federal regulations, Pantheon will consider qualified applicants with arrest and conviction records for employment.

The Canadian base salary range for this role is 176,000 CAD - 264,000 CAD. This position also offers a performance bonus dependent on company performance. Our salary ranges are determined by role, level, and location. 

Visa sponsorship is not available at this time. 

To review the Employee and Applicant's Privacy Policy, click here.




  • , BC, Canada S&P Global Full time

    Director Cloud Engineering - Security & IAM About The RoleGrade Level (for internal use):13Director Cloud Engineering – Security & IAMThe Team: S&P Dow Jones Indices is seeking a Director, Cloud Engineering to join our Infrastructure Engineering team as a pivotal member, responsible for managing Identity and Access Management across Cloud and co-located...


  • , , Canada Pantheon Full time

    About Pantheon Pantheon WebOps Platform powers the open web, running more than 300,000 sites in the cloud for customers including Google, Princeton, Salesloft, and Doctors Without Borders. Every day, thousands of developers and marketers create, iterate, and scale WordPress and Drupal sites to reach billions of people globally. Pantheon’s multitenant,...


  • Vancouver, Canada Pantheon Full time

    About Pantheon Pantheon WebOps Platform powers the open web, running more than 300,000 sites in the cloud for customers including Google, Princeton, Salesloft, and Doctors Without Borders. Every day, thousands of developers and marketers create, iterate, and scale WordPress and Drupal sites to reach billions of people globally. Pantheon’s multitenant,...


  • Toronto, ON, Canada S&P Global Full time €125,000 - €210,000

    Director Cloud Engineering – Security & IAM The Team: S&P Dow Jones Indices is seeking a Director, Cloud Engineering to join our Infrastructure Engineering team as a pivotal member, responsible for managing Identity and Access Management across Cloud and co-located infrastructure. This role demands a seasoned engineer who excels in both independent work...


  • , , Canada McKesson’s Corporate Full time

    Sr. Director, Network Security Engineering page is loaded## Sr. Director, Network Security Engineeringremote type: Fully Remotelocations: CAN, ON, Remotetime type: Full timeposted on: Posted Todayjob requisition id: JR McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights,...


  • , , Canada Pantheon Full time

    A leading web operations platform in Canada is seeking a Security Engineering Director to oversee the security of its services. This role includes managing a team, developing security strategies, and ensuring compliance with standards like PCI-DSS and SOC2. The ideal candidate will have over 10 years of experience in information security, industry...


  • Remote, Canada Vanta Full time $150,000 - $250,000 per year

    LocationRemote - CanadaEmployment TypeFull timeLocation TypeRemoteDepartmentEngineeringAt Vanta, our mission is to help businesses earn and prove trust.We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have...


  • Remote - Canada Vanta Full time $200,000 - $250,000 per year

    At Vanta, our mission is to help businesses earn and prove trust. We believe that security should be monitored and verified continuously, and we empower companies to practice better security and prove it with ease. Vanta has a kind and talented team, and while some have prior security experience, many have been successful at Vanta without it. As the...


  • Vancouver, Canada Pantheon Full time

    A leading web operations platform is seeking a Security Engineering Director to ensure the security of their platform. This role involves managing a high-performing team, developing security strategies, and collaborating with various departments. Candidates should have over 10 years of experience in information security, leadership skills, and relevant...


  • Vancouver, Canada Pantheon Full time

    A leading web operations platform is seeking a Security Engineering Director to ensure the security of their platform. This role involves managing a high-performing team, developing security strategies, and collaborating with various departments. Candidates should have over 10 years of experience in information security, leadership skills, and relevant...