
501 - 1000 employees
Founded 2018
💼 Consulting
🛡️ Insurance
💳 Fintech
💰 $80M Series C - Nesto on 2022-12
Consulting • Insurance • Fintech
nesto is a Canadian online mortgage lender and brokerage that provides mortgages, renewals, refinances and HELOCs through an AI-powered, technology-first platform. The company offers rate comparisons, calculators, educational guides and access to licensed mortgage advisors across provinces, emphasizing low upfront rates, streamlined digital applications, and transparent mortgage advice for consumers. nesto combines digital tools with in-house mortgage experts to simplify home financing for Canadian borrowers.
🔥 0 minutes ago
🇨🇦 Canada – Remote
⏰ Full Time
🟡 Mid-level
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
👻 Ghost score 10%
🗣️🇫🇷 French Required
Improve your chances of getting an interview by checking your resume score before you apply.

501 - 1000 employees
Founded 2018
💼 Consulting
🛡️ Insurance
💳 Fintech
💰 $80M Series C - Nesto on 2022-12
Consulting • Insurance • Fintech
nesto is a Canadian online mortgage lender and brokerage that provides mortgages, renewals, refinances and HELOCs through an AI-powered, technology-first platform. The company offers rate comparisons, calculators, educational guides and access to licensed mortgage advisors across provinces, emphasizing low upfront rates, streamlined digital applications, and transparent mortgage advice for consumers. nesto combines digital tools with in-house mortgage experts to simplify home financing for Canadian borrowers.
• Design, implement, and maintain cloud security solutions to protect cloud-based systems and applications. • Implement and maintain robust security controls for cloud infrastructure and applications. • Identify, remediate, and validate security issues across the cloud infrastructure. • Conduct architecture and design reviews from a security perspective and provide actionable requirements and recommendations. • Collaborate with security leadership, compliance, development, and engineering teams to execute security strategies. • Build, deploy, and manage security tools such as WAFs, IDS/IPS, workload protection, GCP Security Command Center, and Azure Security Center. • Propose and contribute to security and compliance improvements for CI/CD pipelines and deployment processes. • Automate infrastructure provisioning and deployment using IaC tools such as Terraform or Pulumi. • Design and operate scalable processes for provisioning cloud access and maintaining the principle of least privilege. • Participate in incident detection and response by improving observability and alerting and supporting the incident response team. • Self-organize and independently prioritize activities. • Support audits and first-party security questionnaires. • Lead and oversee security assessments and threat modeling exercises. • Implement security controls within Kubernetes. • Build DevSecOps tools and integrations.
• 5+ years of experience working on an infrastructure- and/or security-focused team. • 5+ years of development experience, ideally with Go and TypeScript/JavaScript. • Knowledge of common web application vulnerabilities and the OWASP Top 10 framework. • Ability to analyze and act on DAST and SAST tool results (e.g., Tenable, Snyk). • Strong understanding of DevSecOps principles and familiarity with CI/CD pipelines (GitHub Actions, Argo CD, Azure DevOps) for conducting automated security testing. • Experience deploying and customizing security tools, including vulnerability scanners, static analyzers, web application firewalls (WAFs), intrusion detection/prevention systems (IDS/IPS), and endpoint security monitoring. • In-depth understanding of cloud and network security, including extensive knowledge of Kubernetes. • Experience with GCP, specifically one or more of the following services: Security Command Center, GKE, Cloud IDS, Cloud Armor, and Secret Manager. • Experience with Azure, specifically one or more of the following services: Security Center, Azure PaaS App Services, VMs, Azure SQL, Front Door, and Key Vault. • Experience writing infrastructure as code using tools such as Terraform, Pulumi, and Helm. • Knowledge of common security frameworks and benchmarks such as CIS, NIST, and MITRE ATT&CK. • Understanding of identity and access management (IAM) principles and cloud-native IAM solutions. • Passion for continuous learning and knowledge sharing. • Bilingual in English and French.
• Employee mortgage program: exclusive preferred rates. • Comprehensive health coverage: premium extended coverage (health, dental, and vision), with 100% prescription drug coverage. • Access to a group RRSP/DPSP retirement savings plan with competitive employer matching contributions. • Telemedicine and family support, including supplemental maternity and parental leave programs. • Flexible workplace: fully remote or from one of our offices (Montreal, Quebec City, Toronto, and more).
Apply Now🕒 3 days ago
Product Security Engineer using frontier AI to discover vulnerabilities and red-team AI systems at Coinbase. Building offensive security tooling and automating vulnerability response workflows.
🇨🇦 Canada – Remote
💵 $154k / year
💰 $21.4M Post-IPO Equity on 2022-11
⏰ Full Time
🟡 Mid-level
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🕒 5 days ago
Senior Security Engineer securing hardware, firmware, and IoT systems for Motive’s AI-powered fleet management platform. Building secure-by-default components, threat models, and device security processes.
🕒 5 days ago
Senior Security Engineer securing Motive’s connected fleet hardware and embedded systems. Building secure-by-default architecture, threat models, and controls across IoT devices and cloud infrastructure.
🕒 5 days ago
Senior Security Engineer advancing AppSec, DevSecOps, and AI tooling at Super.com, a company helping customers maximize travel and everyday life. Leading offensive security, secure design, and developer enablement.
🇨🇦 Canada – Remote
💵 CA$128k - CA$173k / year
💰 $60M Series C - Super.com on 2023-04
⏰ Full Time
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🕒 5 days ago
Senior Azure security architect supporting Hitachi Solutions, a global Microsoft solutions integrator. Securing, designing, and advising on clients’ Azure infrastructure and environments.