Security Engineer

League
Toronto
Workplace: OnsiteFull timeCAD 122,800 - 150,000 annuallyFunction: CybersecurityExperience: 2+ yearsSkills: ["Systems thinking","Risk communication","Knowledge sharing","Judgment","Self-driven"]

Own application and product security at the intermediate level by running security reviews, participating in threat modeling, and assessing APIs and cloud configurations. Build and tune security tooling that removes manual review steps, triage and drive remediation of findings, and embed security checks into the SDLC. Review AI-enabled features for prompt injection and unintended data exposure, communicate risk clearly to engineers and leadership, and support SOC 2/HITRUST/HIPAA/PIPA control work.

Loading

Loading job details...

Preparing the role view and application actions.

FursaFursa
League
League
1 day ago

Security Engineer

✓ Verified Job

Canonical indexed version, validated from employer's careers page.

Source: Company careers pageValidated by: Fursa AI
Last checked: 11 hours agoStatus: Live

Job Summary

Own application and product security at the intermediate level by running security reviews, participating in threat modeling, and assessing APIs and cloud configurations. Build and tune security tooling that removes manual review steps, triage and drive remediation of findings, and embed security checks into the SDLC. Review AI-enabled features for prompt injection and unintended data exposure, communicate risk clearly to engineers and leadership, and support SOC 2/HITRUST/HIPAA/PIPA control work.
Location: Toronto
Workplace: Onsite
Employment Type: Full time
Job Function: Cybersecurity
Seniority: Mid level

Key Responsibilities

  • •Conduct security reviews of product features, integrations, and platform changes and document resulting security requirements.
  • •Participate in threat modeling to identify risks in system design and data flow.
  • •Perform security assessments of applications, APIs, and cloud configuration and provide remediation guidance engineering teams can act on.
  • •Review AI-enabled product features for prompt injection, excessive agency, and unintended exposure of member data.
  • •Triage and score security findings, drive remediation with owning teams, and own configuration/tuning and triage workflows for security tooling.

Pay and Benefits

Salary: CAD 122,800 - 150,000 annually

Key Requirements

  • •2+ years of professional experience in application or product security, or in software engineering with substantial security responsibility.
  • •Ability to identify access control and tenant isolation failures, as well as business logic flaws.
  • •Working knowledge of authentication and authorization, including OAuth 2.0 / OIDC, session/token handling, and role/attribute-based access control.
  • •Familiarity with CI/CD and software supply chain security, including pipeline testing, dependency management, and secrets handling.
  • •Solid working knowledge of common application vulnerabilities (e.g., OWASP Top 10) and mitigations, including AI/LLM application security (prompt injection and agentic tool-use risk).
Experience:2+ yearsApplication securityProduct securityHealthcare
Skills:Systems thinkingRisk communicationKnowledge sharingJudgmentSelf-driven
Certifications:SOC 2 Type IIHITRUSTHIPAAPHIPA
Languages:English
Tech Stack:PythonGoOAuth 2.0OIDCCI/CDSoftware supply chain securityOWASP Top 10SDLCAILLMsGCP

Company Brief

League
Provides a digital health and benefits platform that connects employers, employees, and healthcare providers to manage benefits, wellness, and virtual care through an integrated consumer-facing experience.
Industry: HealthTech
Company Size: Large (251 to 1,000 employees)
Growth: Scaleup
Headquarters: Toronto, Canada
Founded: 2014
WebsiteLinkedIn