← Back to job listings
TH
Senior Enterprise Security Engineer
Thumbtack · Canada
About The Role
Join Thumbtack, a company dedicated to helping small business owners thrive. As a Senior Enterprise Security Engineer, you will play a crucial role in shaping system design, guiding architectural decisions, and evolving Thumbtack's security posture. You will focus on improving AI-adjacent security, hardening IAM, and providing broader security engineering support across the enterprise. You will also lead cross-functional security initiatives, mentor engineers, and support security incident response. Enjoy a virtual-first working model, generous benefits, and a mission-driven environment.
- Deliver high-quality security assessments and threat models for AI tools and systems, ensuring adherence to enterprise security principles.
- Design and validate technical guardrails and reusable patterns that keep AI usage safe, spanning AI behavior and connectivity.
- Lead cross-functional security initiatives end-to-end, partnering with various stakeholders to surface risk early and support scalable adoption of secure patterns.
- Strong experience securing modern, cloud-native systems (AWS and/or GCP) and familiarity with core control domains such as audit logging, encryption, access control, data retention, and incident response
- Experience developing threat models and proposing technical guardrails for AI tooling and agentic systems, including non-human identities, tool/permission scoping, and safe defaults for agent behavior
- 6+ years of experience in security engineering, enterprise security, application security, cloud security, or a related field
- Strong sense of ownership and accountability, balancing hands-on technical execution with the ability to mentor others, raise standards, and drive measurable improvements in enterprise security
- Excellent written and verbal communication skills, with the ability to influence without authority and translate technical risk into clear requirements and actionable guidance for both technical and non-technical audiences
- Strong experience evaluating risk and conducting security design and architecture reviews across enterprise applications, SaaS platforms, integrations, and internally developed systems, including evaluating data flows, third-party integrations, trust boundaries, automation platforms, AI-connected workflows, and emerging integration patterns such as MCP
- Deep expertise in modern enterprise security disciplines: authentication and authorization (SSO, OAuth/OIDC, SAML, federation, SCIM), API security and token handling, secrets management, least-privilege design, SaaS security and posture management
This is an external listing. JobSpring does not represent or verify the employer. Report this listing
JobSpring