Skip to content
← Back to job listings

Senior Enterprise Security Engineer

Thumbtack · Canada

External listingfull-timeabout 1 month ago

About The Role

Join Thumbtack, a company dedicated to helping small business owners thrive. As a Senior Enterprise Security Engineer, you will play a crucial role in shaping system design, guiding architectural decisions, and evolving Thumbtack's security posture. You will focus on improving AI-adjacent security, hardening IAM, and providing broader security engineering support across the enterprise. You will also lead cross-functional security initiatives, mentor engineers, and support security incident response. Enjoy a virtual-first working model, generous benefits, and a mission-driven environment.

  • Deliver high-quality security assessments and threat models for AI tools and systems, ensuring adherence to enterprise security principles.
  • Design and validate technical guardrails and reusable patterns that keep AI usage safe, spanning AI behavior and connectivity.
  • Lead cross-functional security initiatives end-to-end, partnering with various stakeholders to surface risk early and support scalable adoption of secure patterns.
  • Strong experience securing modern, cloud-native systems (AWS and/or GCP) and familiarity with core control domains such as audit logging, encryption, access control, data retention, and incident response
  • Experience developing threat models and proposing technical guardrails for AI tooling and agentic systems, including non-human identities, tool/permission scoping, and safe defaults for agent behavior
  • 6+ years of experience in security engineering, enterprise security, application security, cloud security, or a related field
  • Strong sense of ownership and accountability, balancing hands-on technical execution with the ability to mentor others, raise standards, and drive measurable improvements in enterprise security
  • Excellent written and verbal communication skills, with the ability to influence without authority and translate technical risk into clear requirements and actionable guidance for both technical and non-technical audiences
  • Strong experience evaluating risk and conducting security design and architecture reviews across enterprise applications, SaaS platforms, integrations, and internally developed systems, including evaluating data flows, third-party integrations, trust boundaries, automation platforms, AI-connected workflows, and emerging integration patterns such as MCP
  • Deep expertise in modern enterprise security disciplines: authentication and authorization (SSO, OAuth/OIDC, SAML, federation, SCIM), API security and token handling, secrets management, least-privilege design, SaaS security and posture management

This is an external listing. JobSpring does not represent or verify the employer. Report this listing