
About The Role
Product Security works day-to-day with the developers building the software that 70,000+ clinics use to book, chart, and bill. Security at Jane is seen as a true partnership with developers. The engineers who do well here can take complex insights, make them digestible for busy teams, and focus on fixing root causes rather than repeatedly addressing symptoms.
We need a staff-level engineer who can identify themes tying together security insights and work with product teams to improve secure software development at the architecture level. Our roadmap includes updates to our development lifecycle and GitHub workflows, private package repositories, maturing SCA tooling, and establishing a security champions program. You'll lead several of these projects outright.
We also lean into AI on this team—both in internal workflows and in the product. We are automating reporting and reminders, and taking the next step toward AI-assisted vulnerability analysis and code-level draft fixes.
What Impact We're Looking For You To Make
- Turn recurring AppSec findings into architectural fixes by spotting common themes across vulnerabilities and partnering with product teams to design them out.
- Lead product security projects end-to-end, including private package repositories, maturing SCA tooling, and updating development lifecycles and GitHub workflows.
- Build AI into security workflows, moving from automated reminders and reporting to AI-assisted vulnerability analysis and draft fixes.
- Champion secure development across Jane by building trusted relationships with developers, explaining risk in plain language, and helping long-tenured teams adopt new practices without friction.
- Own security initiatives, represent Product Security in cross-functional groups, and mentor teammates as the team's most senior hands-on engineer.
What Experience We Need
- Staff-level application security experience, including owning security initiatives end-to-end and working directly with development teams.
- A real development background. Ruby on Rails is ideal; Python, Java, or C# with a willingness to work in a Rails codebase works as well.
- Experience finding systemic vulnerability patterns and driving architectural fixes with engineering teams.
- Strong relationship skills with developers and stakeholders, communicating risk clearly and empathetically.
- Hands-on experimentation with AI in security workflows (automation, AI feature security, or draft fix integrations).
Compensation & Benefits
- Annual Salary Range: $158,400 – $247,500 CAD (Most hires join around the $188,100 CAD milestone depending on experience).
- Comprehensive benefits package included.
Timezone overlap
UTC-8–-4
Open to
NA
Sign in to track applications and earn points.