Security Engineer

4 days ago

, Canada League Full-time

About League

League is one of the fastest-growing technology companies in Canada and the leading healthcare experience platform. Getting healthcare is often the easy part — finishing it is where things fall apart: people book the appointment and skip the follow-up, fill the prescription and stop taking it, get the referral and never make the call. That gap costs health plans and health systems money, and it costs people their health. League closes that gap — identifying what each person needs to do next, clearing what’s in their way, and getting it done, for the 70 million+ people whose care already runs through our platform. Health plans and health systems trust us to do this at scale. Organizations like Manulife, SCAN, Geisinger, and Medibank on the payer side, and Baptist and Shoppers Drug Mart on the provider side.

Position Summary

League's security engineering team is responsible for scaling security across the development lifecycle. We believe in security by design and follow a paved-road philosophy: we build or buy tooling that integrates into our platform so it is easier for engineers to do the right thing than the wrong thing. Security is everyone's responsibility, and security engineering is how we make it possible for engineers to ship high-quality code to production several times a day with security built in. This role is an intermediate security engineer who splits their time between engagement work and engineering work. On the engagement side you will run security reviews for new product work, contribute to technical deep dives on existing systems, assess vendors before they are approved for use, and review third-party vendors that handle League customer data. On the engineering side you will write code and engage with tooling and systems: automation that removes manual review steps, checks that run in our pipelines, and tooling that makes findings easier to route, track and close. League ships AI-enabled features and our engineers work with AI-assisted development tooling daily. Reviewing those systems, and reasoning about the security of code and fixes that AI produces, is a standing part of this role rather than a specialty. You will bring some experience with threat modeling and cloud architecture to meaningfully contribute to secure design practices, while senior engineers and architects own the broader security strategy. You think in systems and processes, which is how you will find the second-order, long-term fix rather than the quick, most immediate one. You share what you learn, and you can explain risk clearly to a software engineer and to infrastructure leadership in the same week. We welcome new ideas and encourage diverse experience, in every meaning of the word
- if you have a unique background, deep interests in a niche topic of security or engineering, or some experience that brings new approaches to security and engineering, this is a strength that we welcome on the team. While this summary outlines the main job responsibilities, it is by no means exhaustive
- we are a fast-moving organization, and change can happen quickly here, especially when it raises the bar of security for League and our customers. So, bring your ideas, your unique insights, and challenge the norm. We will be better for it.

What You will do

  • Conduct security reviews of product features, integrations, and platform changes, documenting resulting security requirements
  • Participate in threat modeling exercises to identify risks in system design and data flow
  • Perform security assessments of applications, APIs, and cloud configuration, and provide remediation guidance engineering teams can act on
  • Review AI-enabled product features for prompt injection, excessive agency and unintended exposure of member data
  • Triage and score security findings, and drive remediation with the owning teams
  • Own the configuration, tuning, and triage workflow for security tooling
  • Automate manual review efforts and embed security checks into the SDLC
  • Build training materials and documentation on secure coding practices and common vulnerabilities; regularly share knowledge with peers
  • Support League’s shift left by contributing reusable security controls to our paved road so that common vulnerabilities are prevented by default
  • Contribute to the development and maintenance of League’s security standards and internal documentation.
  • Conduct security reviews of third‑party vendors that process or store League data, and support customer security assurance requests
  • Support SOC2TypeII, HITRUST, HIPAA, and PHIPA control design, testing, and evidence gathering in partnership with the Privacy and Compliance team.
  • Communicate risk findings clearly to different audiences, adapting language and level of detail for engineers versus leadership.

What You Bring