Skip to content

Jobgether

Principal Security Architect

Compensation
158K–263K CAD / yr
From job posting
Location
CA
Arrangement
Remote
Employment type
Full-time
Level
Principal
Posted
29 September 2026 (yesterday)

Checked yesterdayApplications go to the employer, never to RoleSprint

About this role

Accountabilities: • Conduct security design reviews covering broad product architecture, individual product changes, cloud infrastructure, and AWS integrations.

• Perform security-focused code reviews and identify potential weaknesses, vulnerabilities, and secure coding improvements.

• Design and document processes for integrating and deploying enterprise Hardware Security Modules and key management solutions.

• Assess third-party software, SaaS providers, and external technologies from a security and architectural perspective.

• Review the design and implementation of integrations with third-party software and SaaS platforms, identifying security risks and recommending appropriate controls.

• Oversee internal and external security assessments and coordinate technical follow-up on identified findings.

• Perform in-depth analysis of vulnerabilities, assessing the potential impact of both third-party and product-specific security issues.

• Monitor emerging technologies, web standards, and browser behavior changes and assess their potential impact on products and security architecture.

• Support compliance and sales teams with technical security expertise related to regulations, customer requirements, RFPs, and security questionnaires.

• Participate in detailed technical discussions with customers regarding security architecture, controls, vulnerabilities, and product capabilities.

• Contribute to patent development through technical invention documentation, review, and collaboration with relevant teams.

• Create and review technical materials for external audiences, including security blogs, white papers, presentations, and other technical content.

• Collaborate with engineering and R&D teams to develop innovative product features and capabilities within the security domain.

• Maintain a strong awareness of evolving cybersecurity threats, technologies, standards, and best practices.

Requirements:

• Advanced knowledge of applied cryptography, including technologies such as Hardware Security Modules (HSMs) and Trusted Platform Modules (TPMs).

• Strong understanding of the complete key management lifecycle, including key generation, storage, distribution, backup, rotation, revocation, and destruction.

• Deep expertise in web and browser security technologies, including the Same-Origin Policy, XSS, CSRF, HTTP security headers, browser architecture, and JavaScript engine internals.

• Thorough understanding of networking and operating-system fundamentals, including TCP, HTTP, TLS, DNS, firewalls, WAFs, discretionary and mandatory access controls, and sandboxing.

• Strong AWS security experience, including IAM, AWS Organizations, EC2, VPC, and related cloud security capabilities.

• Familiarity with static and dynamic application analysis concepts, methodologies, and tools.

• Advanced proficiency in C/C++, particularly secure coding practices, along with strong experience in at least one additional programming language, preferably Python or JavaScript.

• Demonstrated ability to investigate complex technical security problems hands-on and take ownership of finding practical solutions.

• Strong architectural thinking and the ability to evaluate security implications across products, infrastructure, integrations, and emerging technologies.

• Excellent communication skills and the ability to explain complex security concepts to engineering teams, customers, executives, compliance teams, and other non-specialist audiences.

• Ability to collaborate effectively across technical and business functions and contribute to high-impact security decisions.

• Master's degree in computer science, engineering, cybersecurity, or a related discipline, or equivalent experience; a PhD is preferred.

• A proactive, ownership-oriented approach with a willingness to work hands-on when required to solve challenging security problems.

Benefits:

• Competitive base salary of approximately CAD $158,000–$263,000 annually.

• Actual compensation may vary based on factors such as experience, knowledge, skills, abilities, and location.

• Eligibility for stock-based compensation grants based on company and individual performance.

• Remote-first work environment for employees based in Canada.

• Opportunity to work on complex security challenges spanning cloud infrastructure, browser technologies, cryptography, networking, and emerging technologies.

• Exposure to enterprise customers and large-scale security environments.

• Opportunities to contribute to security innovation, technical publications, patents, and new product capabilities.

• Collaborative environment emphasizing ownership, direct communication, cross-functional teamwork, technical excellence, and customer-focused outcomes.

• Equal opportunity employment environment focused on merit, competence, performance, and business needs.

How Jobgether works: We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether?

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

#LI-CL1

Work location

  • CA

Related jobs

Ready to make a decision?

This role is either worth your time or it isn’t.

Analyze the posting against your experience, see the gaps clearly, and build the right materials only if the opportunity makes sense.

Nothing is submitted automatically. You choose what happens next.

About this listing

Published on Lever under the board identifier Jobgether, which is the name the employer’s own job board carries. RoleSprint has not verified the company’s registered or trading name, so it is shown exactly as published rather than tidied up.

RoleSprint is not the employer and not a recruiter. Applications are made on the employer’s own site and never reach us; what RoleSprint does is help you decide whether a role is worth your time and prepare for it if it is.

Published 29 September 2026, last checked yesterday. A posting stops being advertised here 90 days after the employer published it, and one the employer takes down is marked closed rather than quietly removed.

More searches like this one

Browse all current openings

No credit card requiredStart free