Jobs.ca
Jobs.ca
Language
Homebase logo

Staff Security Engineer

Homebase18 days ago
Remote
Toronto
Staff

Top Benefits

Medical, dental, and vision insurance
Paid parental leave
Generous paid time off

About the role

Who you are

  • 10+ years of progressive experience in Application Security or Security Engineering, with demonstrated impact at the Staff or Principal level
  • Deep software engineering experience in production environments, you write code, build tools, and think like an engineer first
  • A proven track record of leading architectural changes and complex cross-team initiatives that reduced security risk at scale
  • Hands-on experience securing AI-native applications, including LLM integrations, model pipelines, or ML infrastructure
  • Strong expertise in web application security, cloud-native security (AWS), and modern DevSecOps practices
  • Proficiency in languages and frameworks relevant to our stack: Ruby, Python, React, and Rails
  • Experience designing and implementing modern vulnerability management systems and embedding security tooling within CI/CD pipelines
  • Exceptional ability to evaluate security trade-offs, make pragmatic risk-informed decisions, and communicate them clearly to technical and non-technical stakeholders
  • Demonstrated curiosity about emerging AI capabilities, with a track record of leveraging new tools to enhance security operations and productivity
  • Experience defining application security strategy and maturity roadmaps for a high-growth, product-driven company
  • A background in building AI-powered security tools or detection systems
  • Speaking experience at security conferences, meetups, or community events
  • Experience with threat modeling frameworks adapted for AI/ML systems
  • Experience comes in many forms—so if you're excited about this role, even if you don’t meet 100% of the qualifications, we encourage you to apply!

What the job involves

  • We’re looking for a hands-on Staff Security Engineer to own and shape Homebase’s Application Security domain
  • This is a technical leadership role at the E5 level—you’ll define the multi-quarter strategy for how we secure our products, set architectural direction, and pioneer new capabilities that keep pace with our rapid growth
  • Homebase’s product suite spans scheduling, payroll, time tracking, HR, team communication, and a growing ecosystem of AI-powered features
  • That breadth creates fascinating security challenges, from protecting sensitive workforce and financial data to securing the AI models and pipelines that are becoming central to our product experience
  • You’ll be the recognized expert our engineering organization turns to for application security decisions
  • You’ll work at the intersection of security, product, and engineering, partnering with engineering leaders to embed security into architecture from the ground up, while building the platforms and tooling that let developers ship safely at speed
  • Define and execute Homebase’s multi-quarter Application Security roadmap, aligning security initiatives with business objectives and company OKRs
  • Architect secure-by-default patterns, frameworks, and paved roads that developers adopt naturally, removing entire classes of vulnerabilities before they reach production
  • Evaluate emerging security technologies and make build-versus-buy decisions that shape the security platform
  • Drive security and product trade-off decisions at the architectural level, balancing protection with velocity
  • Influence company-wide engineering practices and security investments through data-driven recommendations
  • Lead threat modeling and security architecture reviews for AI-powered features, model training pipelines, and LLM integrations
  • Design and implement security controls specific to AI/ML systems, including prompt injection defenses, model input validation, output filtering, and data pipeline integrity
  • Create AI-powered vulnerability detection and security automation that multiplies the team’s effectiveness
  • Partner with AI engineering teams to establish secure development patterns for model deployment and inference infrastructure
  • Stay ahead of the evolving AI threat landscape and translate emerging risks into practical engineering guidance
  • Build and maintain security tooling and automation that integrates seamlessly into CI/CD pipelines, enabling continuous security validation at scale
  • Own the vulnerability management program: design modern systems for detection, prioritization, tracking, and remediation of security debt across the product portfolio
  • Own the bug bounty and responsible disclosure program, turning external researcher findings into systemic improvements
  • Embed security into the full software development lifecycle through scalable guardrails, automated testing frameworks, and developer-facing documentation
  • Partner with senior leaders across Engineering, Product, and Infrastructure to improve Homebase’s overall security posture
  • Pioneer a security partnership program, mentoring engineers across the organization, and driving a culture of shared security ownership
  • Provide expert guidance during security incidents and lead post-incident analysis to drive systemic improvements
  • Curate and author security guidance, patterns, and training content that raises the security bar organization-wide
  • Influence security decisions at the department and company level; shape how Homebase invests in security capabilities

The application process

  • Meet the Talent Acquisition team, Ryan H
  • Meet the Hiring Manager, Ali F
  • Participate in Technical Interviews
  • Meet the VP of Engineering, Andrea C
  • Background Check + Offer Stage
  • Welcome to the team, Homie

Benefits

  • Stock Options
  • Paid parental leave
  • Generous paid time off options
  • Offsites, customer days & social events
  • Work from Anywhere Month
  • Medical, dental, and vision insurance
  • 401(k) matching program
  • Pre-tax commuter benefits
  • Snacks + lunch on us at hub offices
  • MasterClass at Work for ongoing learning
  • Group health benefits coverage
  • Group RRSP with employer match + TFSA
  • Snacks + lunch on us at hub offices
  • MasterClass at Work for ongoing learning

About Homebase

Software Development
5001-10,000

Our mission is to make small business teams unstoppable.

Homebase is the everything app for hourly teams, with employee scheduling, time clocks, payroll, team communication, and HR. More than 100,000 small (but mighty) businesses rely on Homebase to make work radically easy and superpower their teams.

Best Time Clock 2023 - The Motley Fool Best Scheduling 2023 - Investopedia Best HR & Employee App 2023 - The Webby Awards Best employee communication tool ever! - Theresa Fouquette, Owner, Bliss Small Batch Creamery

America's Best Startup Employers 2024 - Forbes

Similar jobs you might like