Wealthsimple
Senior Security Developer, Vulnerability Management
Remote role where the employee must remain based in a particular country.
Canada only
Employer listed it 3 weeks ago Β· Added yesterday
Been open since 3 weeks ago, still being checked, but it has been live a while.
Salary
$151,200 to $189,000
Location
Canada only
Timezone
US East
Contract
Full-time
Experience
Senior
Category
Software
Published by the employer
Remote flexibility
Work from home
This is a remote role, but the employee must be based in Canada. It is work from home rather than work from anywhere.
What the employer says
- Source listing states candidate location: "Remote (Canada), Remote"
What Nomaders makes of it
- Residency required in Canada
- Payroll and tax are likely handled in that country only
The quotes above are the employer's own words; the reading is ours. Always check the original listing and employment terms before working from another country.
About the role
Build something people love
Wealthsimple is Canadaβs leading financial innovator. The company offers a full suite of simple, sophisticated financial products across managed investing, do-it-yourself trading, cryptocurrency, tax filing, spending and saving. Wealthsimple currently serves more than 4 million Canadians and holds over $155 billion in assets under administration. The company was founded in 2014 by a team of financial experts and technology entrepreneurs, and is headquartered in Toronto, Canada.
We're proud of what we've built β and we're just getting started. Read our Culture Manual and learn more about how we work .
About the Role
Most vulnerability management programs are still built around people manually triaging tickets and chasing down owners. We're taking a different approach: a platform that uses AI-assisted tooling to do a lot of that work for us, and this role is where that gets built. We want you to design the automations, integrations, and workflows that take those fundamentals further: less manual ticket routing, more systems that carry a finding through triage, ownership, and remediation on their own.
The skill set we're after, automation-first thinking, developer-level reasoning, and the ability to build integrations across systems, is what turns a program from manual and reactive into something that runs on its own. That's the job: build the automation and integrations that let our VM tooling handle the load without a person in the loop at every step. We're also building deeper integration with our CRS (Cyber Reasoning System) harness, so a finding can move from triage through automated sandbox validation to a generated fix with less manual handling at each stage.
We use AI-assisted development tools heavily and expect you to use them too.
In this role, you will have the opportunity to:
Own and evolve our custom VM platform, working on deployment, integrations, data model, and automation workflows. This is a greenfield opportunity to shape how the platform grows.
Build automation across the full VM lifecycle: triage, ticket routing, SLA tracking, ownership resolution, and follow-up. We use Claude Code and Tracecat, and you'll be expected to use and extend both meaningfully.
Take a platform built around one team's workflow to one that fits how the rest of engineering actually works. Get it in front of people, bake it into their existing processes, and make it something teams reach for.
Integrate scanner data into our VM pipeline and maintain the enrichment workflows that turn raw findings into actionable tickets.
Build the queries, dashboards, and automated reports that give the team and leadership clear visibility into vulnerability posture.
Stay current on the threat landscape, especially the growing role of AI in vulnerability research and exploitation, and factor that into how we build and prioritize.
Help build toward a future where a validated finding gets tested and patched by CRS in a sandbox, and comes back out as a PR, closing the loop with minimal manual work.
We are looking for someone who:
Is familiar with the software development lifecycle end to end, well enough to recognize where a vulnerability was actually introduced in the process and to tell when an AI tool is hallucinating a finding instead of catching a real one.
Has 4+ years of hands-on vulnerability management and/or security engineering experience, including scanner integration, triage workflows, and remediation tracking. If vulnerability management isn't explicitly on your resume, you should be able to explain clearly why you understand it anyway.
Has production AWS experience.
Has a strong automation-first mindset. You've built things that replace manual processes.
Has deep familiarity with VM tooling (Tenable, Semgrep, Rapid7, or comparable scanners) and knows how to build integrations on top of them via API.
Understands the difference between package and library vulnerabilities well enough to know where a fix actually belongs, and understands vulnerability classes across application and infrastructure layers (XSS vs. CSRF, code vs. container issues) well enough to have a real conversation with a developer who disagrees with a finding. Knows which scanners belong at which stage of the pipeline (CI, production, network) and how a vulnerability actually ends up running in production, including in containers. Hands-on exposure to SAST/DAST/SCA tooling and OWASP fundamentals helps here.
Has hands-on familiarity with GitHub Actions, ArgoCD, Kubernetes, AMIs, and container images (ECR or comparable). You'll need this to help maintain our VM platform, and because each of these carries its own patch management burden since they all run code.
Understands attack surface and exposure management, including how a basic web app's architecture and traffic flow map to real risk. You'll be making risk acceptance calls, and that requires seeing the actual exposure, not just a CVE score.
Requirements
The employer hasn't listed requirements separately, they're described in the role summary above and on the original listing.
Benefits
- Β·π Long-term group savings with employer match, through Wealthsimple for Business
- Β·π΄ 20 vacation days, 4 wellness days, and unlimited sick and mental health days per year
- Β·βοΈ 90 days away: work outside Canada for up to 90 days per year
- Β·π₯ Employee resource groups, including Rainbow (2SLGBTQ), Women of WS, and Black at WS
How to apply
- 1Check the flexibility label above, work from home, matches where you plan to live and work.
- 2Tailor your CV to the role at Wealthsimple, mentioning your remote working experience and working hours (US East).
- 3Apply directly on the employer's careers page using the button below. Nomaders never handles your application.
Found 1d ago. Last checked 23 Sept. Always confirm the details on the original posting, salary and location can change after publication.
Listing sourced from Company boards.
Similar roles
Other open software roles with comparable remote rules.
Free to apply, no account needed.
$151,200 to $189,000 Β· You'll be taken to the employer's careers page.