Skip to content
← Back to job listings

Senior Security Engineer

Lime · Canada

External listingfull-time6 days ago

About The Role

Join Lime, a fast-paced and remote-first company, as a Senior Security Engineer. In this role, you will be an embedded security partner to our engineering organization, directly contributing to the security of Lime's software, APIs, mobile applications, and connected vehicle platforms. You will report to the Director of Security Engineering and play a key role in building and maturing our product security program. Responsibilities include application security and secure development, security tooling and automation, security architecture and design reviews, bug bounty and external programs, incident response, cross-functional partnership and mentorship, and staying ahead of the threat landscape.

  • Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features, APIs, mobile applications, and backend services.
  • Develop and maintain scalable security tools and pipelines to automate vulnerability detection, dependency scanning, and security testing across the software development lifecycle.
  • Contribute to security architecture reviews for new product platforms and features, evaluating authentication and authorization designs, API security posture, and data handling practices.
  • We're a fast-paced, lean, and remote-first company, so we're looking for someone who thrives in an evolving environment, is a proactive problem-solver, and is passionate about building scalable and pragmatic security solutions for software-connected physical products
  • Vulnerability management tooling and processes
  • Ability to participate in a shared on-call rotation supporting production systems, including occasional after-hours, weekend, and holiday coverage, with responsibility for responding to critical alerts, coordinating escalations to restore service, and documenting issues to help prevent recurrence
  • Technical Depth: Demonstrated expertise across core product and application security domains, including:
  • Secure development practices and SDLC security integration (SAST, DAST, SCA, secrets management)
  • Authentication and authorization patterns (OAuth, OIDC, RBAC)
  • Experience: 5+ years of experience in a dedicated product security, application security, or security engineering role, with a strong track record of hands-on technical contribution across the software development lifecycle
  • Experience with detection engineering, security monitoring, or building detection-as-code (DaC) pipelines for product or application security threats (SIEM, log analysis, alert tuning)
  • Problem-Solver: Strong analytical skills with the ability to triage ambiguous security signals, identify meaningful risk, and propose pragmatic mitigations that teams can act on — without over-engineering or adding unnecessary friction
  • Education & Certifications: Bachelor's degree in Computer Science, Cybersecurity, or a related field preferred but not required. Relevant certifications such as OSCP, CSSLP, GWEB, or equivalent are a plus
  • Cloud security fundamentals (AWS, GCP) and container/infrastructure security
  • Mobile security (iOS, Android) and API security
  • Communication: Clear written and verbal communicator who can translate complex technical security risks into actionable guidance for both engineering peers and non-technical stakeholders
  • Exposure to regulatory frameworks relevant to connected products, such as EU CRA, UNECE WP.29, or OWASP MASVS
  • Experience operating or contributing to a vulnerability disclosure or bug bounty program
  • Team Player: Comfortable operating in a lean, remote-first, high-trust environment. Able to independently drive work forward while collaborating across engineering, product, and security teams
  • Familiarity with IoT, connected hardware, or vehicle/firmware security in a product security context
  • Not sure if you meet all the qualifications? If this role excites you we encourage you to apply. Explore all opportunities on our career page

This is an external listing. JobSpring does not represent or verify the employer. Report this listing