
About Shakepay
Since 2015, Shakepay has been on a mission to help Canadians build long-term wealth through Bitcoin. Over the past few years, we've expanded beyond buying and selling Bitcoin to offer a growing suite of everyday financial products—including the Shakepay Card, direct deposit, bill payments, and Interac e-Transfer. Today, more than 1.5 million Canadians use Shakepay to grow their Bitcoin savings.
We’re regulated as an investment dealer across all Canadian provinces and territories, backed by renowned venture capitalists with $44M in funding.
About the Security Team
Security at Shakepay is a company-wide responsibility supported by a high-impact team focused on protecting our customers, systems, and data while enabling product velocity and business growth.
The Security team works across application and product security, cloud and infrastructure security, enterprise security, security tooling, incident response, and emerging areas such as AI security. We work closely with Engineering, Platform, Risk, Compliance, and Product to build pragmatic controls and scalable security capabilities.
About the Role
We’re looking for a Staff Security Engineer to help safeguard Shakepay’s infrastructure, products, and customer data while leveling up our AI platform, security capabilities, and observability.
In this role, you’ll be a hands-on technical contributor across multiple security domains (application, product, infrastructure, enterprise, observability). You will partner closely with engineering teams to design and implement scalable security solutions that balance risk reduction, customer experience, and product growth.
You’ll be expected to work in an AI-forward way—using AI tools, agents, and automation to scale your impact across security engineering, observability, testing, detection, and response.
What You'll Be Doing
- Design and drive security solutions across multiple domains, including product, internal applications, infrastructure, enterprise systems, and observability.
- Conduct threat modeling for existing systems and new product initiatives.
- Partner with engineering teams to embed security into development and delivery workflows.
- Build, tune, and automate security alerts, detections, observability, and response workflows using AI and automated agents.
- Participate in and help lead incident response as part of the on-call rotation.
- Support governance, compliance, and regulatory efforts (SOC 2, ISO 27001, PCI, etc.).
- Mentor engineers and share security best practices across the organization.
- Help shape security priorities and technical direction while building strong relationships with internal stakeholders and external security vendors.
What We're Looking For
- 8+ years of experience in security engineering, software engineering, or a related technical discipline, with meaningful experience in security.
- Strong technical depth in one or more security domains with the ability to operate across adjacent domains.
- Advanced, hands-on experience using AI tools, agents, and automation to increase the scale and effectiveness of security engineering work.
- Experience working in cloud environments (AWS preferred).
- Hands-on experience with incident response and on-call rotations.
- Strong communication skills, technical judgment, and a clear sense of ownership.
Bonus Points
- Experience working in fintech, crypto, or other regulated environments.
- Exposure to product security and influencing product design.
- Experience with AI-assisted security testing, offensive security, vulnerability research, detection engineering, or security observability.
- Knowledge of Bitcoin and excitement to learn more.
- Comfort using Git/GitHub for collaboration and process management.
Perks & Benefits
- Equity: Stock options as part of your total compensation package.
- Performance Reviews: Quarterly performance and salary assessments.
- AI Budget: Generous AI token budget.
- Health & Wellness: Comprehensive health and dental coverage, plus health and wellness spending accounts.
- Remote-First: Work from anywhere in Canada, with optional access to office spaces in Montreal and Toronto.
- Learning & Growth: $2,000 annual budget for courses, certifications, and training.
- Vacation: 20 days of paid vacation per year, plus a $1,000 bonus if you use all your vacation time.
- Parental Leave: Parental leave top-up to 100% of your salary for 18 weeks.
- Offsites: Quarterly team-specific or company-wide offsites to connect in person.
Timezone overlap
UTC-8–-4
Open to
NA
Sign in to track applications and earn points.