HimalayasHimalayas logo
PantheonPA

Staff Security Engineer

We're building the world's best WebOps platform. Pantheon empowers marketing and development teams to take control of their websites, while giving them the agility to win in the dynamic world of digital marketing. We power over 700,000 sites and are trusted by thousands of marketing and development teams around the world - and we're just getting started.

Pantheon

Employee count: 501-1000

Salary: 176k-220k CAD

Canada only

Stay safe on Himalayas

Never send money to companies. Jobs on Himalayas will never require payment from applicants.

About Pantheon

Pantheon WebOps Platform powers the open web, running more than 300,000 sites in the cloud for customers including Google, Princeton, Salesloft and Doctors Without Borders. Every day, thousands of developers and marketers create, iterate, and scale WordPress and Drupal sites to reach billions of people globally. Pantheon’s multitenant, container-based platform enables organizations to manage all of their websites from a single dashboard. Organizations including Clorox and the United Nations drive results through accelerated development and real-time publishing using Pantheon’s collaborative workflows.

The Role

Pantheon’s Security Engineering team is responsible for safeguarding, auditing, and testing the security of Pantheon's entire platform. Our Security Engineering team aims to create a comprehensive and multi-dimensional approach to application security, with a focus on Security by Design in agile software development and cloud native environments.

We are seeking a passionate, driven, and experienced application security engineer to join our growing team. The Staff Security Engineer is a key strategic and technical role within the Application Security team.

Our mission is to safeguard, audit, and test the security of the entire cloud hosting platform in these core areas:

  • Security by Design: Implement “Security by Design” within agile software development and cloud-native environments.
  • Support and Mentorship: Act as a Subject Matter Experts (SMEs), mentoring, coaching, and supporting all security engineering efforts across the organization.
  • Standard Setting: Define, organize, and implement application security policy, process, standards, and guidelines.
  • Application Security Performance: Helping engineering teams design and build high-performing, secure applications by mitigating security issues in a risk-based manner.

What You Will Do

  • Policy Definition: Define, document, and champion processes and practices for a secure Software Development Life Cycle (SDLC).
  • Security Culture: Be a driving force in establishing a strong security culture within platform engineering teams.
  • Proactive Security: Lead Threat Modeling as a core principle for the Secure by Design strategy.
  • Secure Design Reviews: Conduct Secure Code and Architecture Design Reviews, including threat modeling and technology/risk-based assessments.
  • Automation: Automate application security testing and controls, integrating them directly into the CI/CD pipelines.
  • Tooling: Responsible for the deployment, operation, and tuning of security tools (SAST, DAST, IAST, and CSPM), with a focus on platforms like CodeQL and Wiz.io.
  • Vulnerability Management: Partner with engineering to effectively prioritize and remediate identified vulnerabilities.
  • Supply Chain & Testing: Manage tools for Software Composition Analysis (SCA) to ensure supply chain security. Coordinate internal and external Penetration Testing activities with the Security Operations team.

What You Need to Succeed

  • Problem-Solving: Ability to bring standardization to inconsistent internal practices and transition to industry best practices.
  • Communication: Strong communication skills essential for partnering with engineering teams.
  • Commitment: Demonstrated commitment to teamwork, professionalism, and authenticity, fostering trust and accountability.
  • Grit: Understanding that establishing security best practices is a marathon requiring persistence across many stakeholders.

What You Bring to the Table

  • Overall Experience: Minimum of 10+ years of overall experience, with at least 5+ years dedicated to Application Security.
  • Development Practices: Deep, hands-on experience in Secure by Design development practices, including guiding Secure Architecture and System Design.
  • Cloud Proficiency: Extensive experience securing production systems in Cloud environments (e.g., AWS, Azure, GCP).
  • Coding Proficiency: Ability to build maintainable components in Go or Python.
  • CI/CD Fundamentals: Hands-on experience with jenkins/cloud pipelines/ circleci (bonus points for experience with reusable workflows).
  • Cloud & Infrastructure: Experience working with containerization (e.g., Docker, OCI), Terraform, and Kubernetes (K8s).
  • Tooling: Proven ability to build, select, and implement application security tools, and integrate them into CI/CD pipelines.
  • Education: Bachelor's degree in Computer Science or equivalent practical experience.

What We Offer

We have all the usual perks and benefits but what we can really offer you is a fantastic work environment powered by an amazing team.

  • Industry competitive compensation and equity plan
  • Paid Time Off (PTO), Paid Sick Leave (PSL) and 11 Paid Company Holidays
  • Full medical coverage (Extended health care, dental, vision)
  • Top-of-line equipment
  • In-office workspace (Vancouver, BC Canada)
  • Monthly allowance for wellness, reading and access to LinkedIn Learning for continued development
  • Events and activities both team-based and company wide that inspire, educate and cultivate

Pantheon is an equal opportunity employer and we welcome applications from all backgrounds regardless of race, color, religion, sex, national origin, ancestry, age, marital status, sexual orientation, gender identity, veteran status, disability, or any other classification protected by law. Pantheon complies with federal and local disability laws and makes reasonable accommodations for applicants and employees with disabilities. If you need a reasonable accommodation due to a disability for any part of the interview process, please contact talent@pantheon.io. Pursuant to local and federal regulations, Pantheon will consider qualified applicants with arrest and conviction records for employment.

Visa Sponsorship is not available at this time.

To review the Employee and Applicant's Privacy Policy, click here.

The Canadian base salary range for this position is 176,000 to 220,000 CAD per year per year. Our salary ranges are determined by role, level, and location. At Pantheon, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case.

About the job

Apply before

Posted on

Job type

Full Time

Experience level

Senior

Salary

Salary: 176k-220k CAD

Location requirements

Hiring timezones

Canada +/- 0 hours

About Pantheon

Learn more about Pantheon and their company culture.

View company profile

Our mission is to make the web a first-class platform that delivers results. We’re building the world’s best WebOps (Website Operations) Platform— one that empowers marketing and development teams to take control of their websites, while giving them the agility to win in the dynamic world of digital marketing. With Pantheon, marketers and developers deliver results by iterating quickly, learning, and experimenting with their websites in the same way they do with virtually every other tool in their martech and development stacks.

Pantheon powers over 300,000 sites and is trusted by thousands of marketing and development teams around the world. We’re just getting started.

Our Values

Pantheon’s values are the compass that guides our behaviors and decisions. These values connect us and empower us to do our best work.

  • Trust: Our mission stems from trusting our employees to do the right thing and create positive change at work. Trust clears the path for experimentation and creativity, which yield innovation and growth.

  • Teamwork: WebOps is a team sport - Pantheon leans heavily on this team mentality for everything we do, knowing that when we work together effectively, we show up in the best possible way for our customers and company.

  • Customers First: Customers sit at the heart of everything we do. We strive to provide the best possible environment for extraordinary digital work—work that teams can be truly, extravagantly proud of.

  • Passion: Pantheors work at the intersection of ambition and humility. Our curiosity is boundless and we’re always eager to find new solutions. We truly care - about our company, about our product, about our customers, about our community.

What Our Employees Are Saying

Pantheon is a "We not Me" culture. We empower, support, and connect with each other in a collaborative, thoughtful and inclusive culture.

Thanks to Pantheor's reviews over the years, we’ve been lucky to be named a great place to work and a top software company.

Employee benefits

Learn about the employee benefits and perks provided at Pantheon.

View benefits

Monthly book allowance

One of the many ways we enable our teams to take control of their development is to take advantage of our books allowance.

Monthly gym allowance

One of the many ways we enable our teams to take control of their wellness is to take advantage of our gym membership allowance.

Mental health coverage

To enhance employee experience, we provide a range of benefits that holistically support your physical, emotional, and financial wellbeing.

Flexible time off

We encourage work/life balance. Take time off when you need it, and return ready to make magic on the internet when you're ready and refreshed.

View Pantheon's employee benefits
Claim this profilePantheon logoPA

Pantheon

Company size

501-1000 employees

Founded in

2010

Chief executive officer

Zack Rosen

View company profile

Similar remote jobs

Here are other jobs you might want to apply for.

View all remote jobs

17 remote jobs at Pantheon

Explore the variety of open remote roles at Pantheon, offering flexible work options across multiple disciplines and skill levels.

View all jobs at Pantheon

Remote companies like Pantheon

Find your next opportunity by exploring profiles of companies that are similar to Pantheon. Compare culture, benefits, and job openings on Himalayas.

View all companies

Find your dream job

Sign up now and join over 100,000 remote workers who receive personalized job alerts, curated job matches, and more for free!

Sign up
Himalayas profile for an example user named Frankie Sullivan