Wattpad

Wattpad

Wattpad is a leading social storytelling platform connecting millions of users through original stories. Discover, share, and create stories you love on Wattpad, where storytelling is redefined.

Internet Software & Services
51-250
Founded 2006
$158M raised

Description

  • Design, implement, and monitor security controls for cloud infrastructure to balance protection with scalability.
  • Influence technical direction by introducing secure development practices, threat modeling, and security standards across Engineering & Data teams.
  • Build security automation workflows and guardrails (infrastructure-as-code and CI/CD) to allow teams to ship code safely and quickly.
  • Lead incident response, root-cause analysis, and remediation of security incidents and vulnerabilities.
  • Assist teams with access management, compliance controls, and risk governance (including SOC 2/ISO 27001 requirements).
  • Build and mature the application security program, triage findings from the Vulnerability Disclosure Program, and partner with engineering on remediation.
  • Collaborate with engineers to implement security best practices and raise the organization-wide security posture.
  • Develop observability and detection use cases in SIEM/monitoring platforms and tune alerts to support threat detection and investigations.

Requirements

  • 5+ years of experience in SecOps, Cloud Security, DevSecOps, or a similar security-focused role.
  • Hands-on AWS security experience with Security Hub, GuardDuty, Inspector, WAF, and IAM policy management.
  • Experience with SIEM/observability platforms such as Datadog or Splunk (query development, alert tuning, incident investigation).
  • Proficiency with infrastructure-as-code security (Terraform, CloudFormation) and automation using Python, GitHub Actions, Bash, or PowerShell.
  • Experience securing containerized environments and Kubernetes (EKS preferred) and securing CI/CD pipelines (GitHub Actions strongly preferred).
  • Familiarity with MITRE ATT&CK and D3FEND frameworks and understanding of enterprise and cloud network security architecture and controls.
  • SOC 2 and/or ISO 27001 compliance experience and exposure to access management and risk governance.
  • Self-starter comfortable with ambiguity with strong written and verbal communication and a balanced collaborative/deep-focus working style.
  • Preferred: experience building application security programs, working with DLP solutions, VDP/bug-bounty platforms (HackerOne/Bugcrowd), threat modeling (STRIDE/PASTA), JIT access, SOAR, cloud security certifications (AWS Security Specialty, CCSP), or offensive security experience (OSCP, GPEN, CEH).

Benefits

  • Base salary range CAD 110,000–150,000.
  • Full suite of benefits including top industry health benefits (vision and dental).
  • Annual health/wellness spending account.
  • Retirement contributions: RRSP (Canada) and 401(k) (USA).
  • Generous vacation and maternity/parental leave top-up program.
  • Corporate gym membership discounts for you and your family.
  • Flexible work: remote-first with opportunity to work from the downtown Toronto office periodically and work from almost anywhere for part of the year.
  • Company winter break shutdown.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Head of Corporate Engineering

Databricks 1K-5K IT Services

Databricks is hiring a Head of Corporate Engineering to lead global enterprise engineering and operations, building and scaling secure cloud infrastructure, identity and access, endpoints, collaboration and engineering tools to enable developer velocity and enterprise compliance.

Agile AWS Azure Confluence GCP GitHub JIRA macOS
1 month ago

Incident Response Security Engineer

ClickHouse 51-250 IT Services

Security practitioner role at ClickHouse focused on scaling incident detection and response capabilities, driving adoption of security processes and tooling, and protecting the company’s cloud and product infrastructure for customer-facing services.

AWS Azure ClickHouse GCP Penetration Testing Python SIEM
1 month ago

Senior Security Engineer - Vulnerability Management

Samsara 1K-5K IT Services

Senior Security Engineer at Samsara responsible for deploying, operating, and improving the company’s Vulnerability Management program to reduce software vulnerabilities and protect customer-facing infrastructure.

AWS CI/CD DevSecOps Go Python Serverless Terraform
1 month ago

Junior DevSecOps Engineer - Contingent

ARETUM Construction & Engineering

Junior DevSecOps Engineer at Aretum supporting a federal client to operate, automate, and secure cloud-based systems and CI/CD pipelines to enable reliable, compliant deployments.

Agile Ansible AWS AWS CDK Azure Chef CI/CD Docker Encryption Git GitLab CI Grafana JIRA Kubernetes Linux LXC Prometheus Puppet SaltStack Scrum Serverless Terraform
1 month ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers