Senior Security Engineer, Security Assurance

4 weeks ago


Canada Grafana Labs Full time

The Security team advances Grafana’s overall security posture through critical initiatives and coordination of large security projects. We build technologies, tools, and processes to enable engineering squads to better develop secure software, protect customer and employee data, deploy systems with appropriate security controls, and securely operate a remote workforce. We are building a security system that’s automated at scale, rigorously data-driven, and built from the ground up with defense-in-depth and self-healing in mind. This system will support a highly autonomous, remote-first, cloud-native organization. We’re taking the best of open-source and commercial tooling and making them talk to each other to arrive at some very special outcomes. We also want to open-source as much of our work as possible to security practitioners. To support our growth and ambitious vision, we embrace agile principles and values, share openly, apply context-driven security mechanisms, default to action, and have an OSS-first mindset. We are a 100% remote company. For all that, we believe absolutely in agreeing on high-velocity but reasonable expectations and timeframes and giving people the room to do great work in a setting that prioritizes health, happiness, and work-life balance. Role The Senior Security Assurance Engineer will collaborate across all of Grafana with a wide range of teams in engineering, security, cloud platforms, information technology, vendor management, and other stakeholders to articulate security policies, implement continuous monitoring, automate workflows, and configure alerts on policy failures. A deep knowledge of security standards and frameworks (ISO, FedRAMP, PCI-DSS, etc) is essential for this role, you should also have provable experience automating security posture management, automating repetitive processes, and maximizing the suite of Grafana products to build self-serve security posture observability. You will work alongside other security engineers, full-stack developers, and customer-facing teams. Ideally, you would be familiar with operating in a cloud-native, remote organization. This is an opportunity to help implement a security strategy and build the underlying platforms and workflows. You will get to work on expanding the capabilities of our asset intelligence and governance program, security posture monitoring, compliance automation, customer security observability automation, and supplier security monitoring. Think about all the layers to build observability for system uptime, but now extending that to other layers of security that impact confidentiality and integrity (encryption, access control, incident response, etc.). While deep knowledge of security standards and frameworks is essential for this role, you should also have provable experience automating security posture management, automating repetitive processes, and maximizing the suite of Grafana products to build self-serve security posture observability. You will work alongside other security engineers, full-stack developers, and customer-facing teams. This is an individual contributor role reporting to the Sr. Manager/Director of Security Assurance. Responsibilities Work autonomously to develop, build, and roll out information, cyber, open source, and cloud security governance frameworks. Design, build, launch, and scale the asset intelligence & governance program on Grafana. Establish a cadence for security program reviews, support existing accreditations, and identify strategic maturity opportunities for compliance. Design and deliver monthly technology and security risk management workshops. Build reasonable and self-serve partnerships with cross-functional stakeholders who are decision-makers and contributors to security initiatives. Socialize and provide awareness of policies, standards, processes, and controls with relevant stakeholders. Serve as the security SME to partner with engineering and operations teams on the business continuity and disaster readiness program. Design, build, and manage Security GRC and Disaster Readiness reporting metrics and dashboards. What you’ll bring to the role Are comfortable working in a remote-first company and understand the importance of adapting and contextualizing the security controls. Enjoy learning, growing, and supporting others to do the same. Be very comfortable with at least one scripting language and a query language like SQL. Enjoy navigating cloud-native environments and building automated processes for security posture management, compliance engineering, and continuous controls monitoring (platforms and tools include GCP, AWS, Azure, Kubernetes, cloudquery, Grafana, LogicGate, Secureframe, Jira, ServiceNow GRC, anecdotes.ai, Drata, Vanta). Have some experience working with Platform and Security to scope, operationalize, and scale Business Impact Assessments (BIAs), Business Continuity Management Systems (BCMS), and Disaster Readiness Strategies for cloud-first companies. Know how to define a project plan, milestones, and KPIs to determine work effectiveness. Enjoy working on complex solutions – Grafana is highly technical with avid followers relying on it daily. Enjoy working autonomously, designing solutions, engaging stakeholders, and demonstrating an “own it” mindset. Have an interest in Grafana’s stack and contributing to open-source foundations. Can communicate clearly in English. Can create impact in a pragmatic, structured, simple, and quick way. Have a “team first” mindset. Education BS / MS in engineering, computer science, or information security, or equivalent experience. CISSP, CISA, CISM, and cloud security solutions are a plus. In Canada, the base salary range is CAD 165,882 - CAD 199,058. Actual compensation varies based on experience and skills. Benefits include equity, bonus, and other listed benefits. Compensation ranges are country-specific; recruiters will discuss specifics for other locations. #J-18808-Ljbffr



  • , , Canada Transmit Security Full time

    Join to apply for the Senior Sales Engineer - Canada role at Transmit Security Join to apply for the Senior Sales Engineer - Canada role at Transmit Security Get AI-powered advice on this job and more exclusive features. Transmit Security is a cross-channel identity and orchestration platform designed to simplify, accelerate, and reduce the cost of...


  • Vancouver, British Columbia, VCG, Canada D3 Security Management Systems Full time $65,000 - $100,000 per year

    Cyber Security EngineerLocation: Greater Vancouver area candidates onlyThe Opportunity:D3 Security is transforming SecOps with Morpheus, our AI-driven Autonomous Security Operations Center (ASOC) platform. Morpheus automates Tier 1–3 analyst work with unmatched precision, processing millions of alerts in real time and empowering security teams to respond...


  • , , Canada Qualified Full time

    Join to apply for the Senior Security Engineer role at Qualified Qualified is the Agentic Marketing Platform for B2B companies. With Piper the AI SDR Agent, Qualified offers a whole new way to grow inbound pipeline. Piper operates across both the website and email, working to engage website visitors, capture leads, and convert buyers into pipeline around the...


  • , , Canada Samsara Full time

    Overview Senior Security Engineer - Security Automation at Samsara. This role focuses on building, operating, and maintaining Samsara’s core security infrastructure and the automations that power it. You will mentor a global team of engineers and leverage low-code and cloud automation to scale security engineering. Responsibilities Provide significant...


  • , , Canada Abnormal Security Full time

    A leading cybersecurity firm in Canada is seeking a Staff Machine Learning Engineer to enhance its Attack Detection team's capabilities. This role involves architecting advanced ML systems, driving technical roadmaps, and mentorship. The ideal candidate has extensive experience in machine learning applications and a solid understanding of deep learning...


  • Markham, Ontario, LR L, Canada Spotter Security Full time $60,000 - $100,000 per year

    Basic detailsJob Title: Senior Security Systems TechnicianLocation: Markham, Ontario Type: Full-time, PermanentExperience: 5+ yearsSpotter Security is growing, and we need another Senior Security System Technician that will bring more leadership and skill to our technical team. This role is perfect for someone that has over 5 years experience installing...


  • , , Canada Webflow Full time

    Senior Security Engineer, Cloud Security Argentina Remote At Webflow, our mission is to bring development superpowers to everyone. As the pioneer of the Website Experience Platform (WXP), we’re redefining how teams Build, Manage, and Optimize for the web — combining visual development, powerful CMS, AI-driven personalization, and seamless hosting in a...

  • Security Officers

    1 week ago


    Holyrood, Newfoundland and Labrador, Canada Paladin Security Full time $40,000 - $80,000 per year

    OverviewPaladin Security: Making the World a Safer and Friendlier Place because we CARE The Paladin Difference starts with our people; we're the best because we hire the best. We believe in promoting from within, respecting people and their differences, providing high quality service and always having fun If you think you have what it takes to join our team,...


  • , , Canada 1Password Full time

    1Password is growing faster than ever. We’ve surpassed $400M in ARR and we’re continuing to accelerate, earning a spot on the Forbes Cloud 100 for four years in a row and teaming up with iconic partners like Oracle, Red Bull Racing and the Utah Mammoth. About 1Password At 1Password, we’re building the foundation for a safe, productive digital future....

  • Security Guard

    2 days ago


    McLennon, Alberta, Canada Paladin Security Full time US$40,000 - US$60,000 per year

    Overview Job Skills / RequirementsJob Description As a key member of a nation leading Security Company, the Security Officer will:  -Apply their decision-making and strong communication skills to all duties and responsibilities relating to Security and Safety -Ensure that the Safety and Emergency Procedures are followed -Follow Post Orders for each site...