Senior Security Engineer @Lime
All Others
Salary cad 120,000 - 1..
Remote Location
Employment Type full-time
Posted 2mths ago

[Hiring] Senior Security Engineer @Lime

2mths ago - Lime is hiring a remote Senior Security Engineer. πŸ’Έ Salary: cad 120,000 - 165,000 per year πŸ“Location: Canada

Role Description

Lime is seeking an experienced Senior Security Engineer to join our Product Security team. In this role, you'll be an embedded security partner to our engineering organization, directly contributing to the security of Lime's software, APIs, mobile applications, and connected vehicle platforms across the full product lifecycle. You will report to the Director of Security Engineering and play a key role in building and maturing our product security program across a broad set of disciplines:

  • Secure development and vulnerability management
  • Application security assessments
  • Detection engineering
  • Threat modeling

This is a remote position with a requirement for candidates to reside in Canada to maintain effective collaboration across teams.

What You'll Do

  • Application Security & Secure Development: Partner with engineering teams to perform security reviews, threat modeling, and risk assessments for product features, APIs, mobile applications, and backend services. Provide actionable and risk-calibrated guidance that helps Lime ship securely without slowing down.
  • Security Tooling & Automation: Develop and maintain scalable security tools and pipelines to automate vulnerability detection, dependency scanning, and security testing across the software development lifecycle. Contribute to and extend our security pipeline and CI/CD security gates (SAST, DAST, SCA, secrets management).
  • Security Architecture & Design Reviews: Contribute to security architecture reviews for new product platforms and features. Evaluate authentication and authorization designs, API security posture, and data handling practices to ensure risks are identified and addressed early.
  • Bug Bounty & External Programs: Support the operations of our BugCrowd bug bounty program, including triage, researcher communication, remediation coordination, and internal validation of reported findings.
  • Incident Response: Serve as a product security point of contact for security incidents affecting Lime's applications and services. Contribute to investigation, root-cause analysis, corrective action, and post-incident improvement.
  • Cross-functional Partnership & Mentorship: Work closely with Software, Platform, Mobile, and Infrastructure engineering teams to embed security into development workflows. Share knowledge, drive security-by-default practices, and mentor engineers and peers on product security fundamentals.
  • Stay Ahead of the Threat Landscape: Continuously evaluate emerging threats, vulnerabilities, and regulatory requirements (including EU CRA) relevant to Lime's product and infrastructure stack. Bring proactive recommendations to the team.
  • Participate in the team's on-call rotation, responding to incidents, troubleshooting issues, and contributing to root cause analysis and service reliability improvements.
  • Respond to and troubleshoot production issues, outages, and critical alerts during assigned on-call shifts.
  • Escalate incidents as needed and collaborate with team members to restore service.
  • Document issues and contribute to improvements that reduce recurring incidents.
  • Be available to provide occasional after-hours, weekend, and holiday support while on call.

Qualifications

  • 5+ years of experience in a dedicated product security, application security, or security engineering role, with a strong track record of hands-on technical contribution across the software development lifecycle.
  • Demonstrated expertise across core product and application security domains, including:
    • Experience with detection engineering, security monitoring, or building detection-as-code (DaC) pipelines for product or application security threats (SIEM, log analysis, alert tuning).
    • Familiarity with IoT, connected hardware, or vehicle/firmware security in a product security context.
    • Experience operating or contributing to a vulnerability disclosure or bug bounty program.
    • Exposure to regulatory frameworks relevant to connected products, such as EU CRA, UNECE WP.29, or OWASP MASVS.
    • Mobile security (iOS, Android) and API security.
    • Secure development practices and SDLC security integration (SAST, DAST, SCA, secrets management).
    • Vulnerability management tooling and processes.
    • Cloud security fundamentals (AWS, GCP) and container/infrastructure security.
    • Authentication and authorization patterns (OAuth, OIDC, RBAC).
  • Strong analytical skills with the ability to triage ambiguous security signals, identify meaningful risk, and propose pragmatic mitigations that teams can act on β€” without over-engineering or adding unnecessary friction.
  • Clear written and verbal communicator who can translate complex technical security risks into actionable guidance for both engineering peers and non-technical stakeholders.
  • Comfortable operating in a lean, remote-first, high-trust environment. Able to independently drive work forward while collaborating across engineering, product, and security teams.
  • Bachelor's degree in Computer Science, Cybersecurity, or a related field preferred but not required. Relevant certifications such as OSCP, CSSLP, GWEB, or equivalent are a plus.

Requirements

  • Ability to participate in a shared on-call rotation supporting production systems, including occasional after-hours, weekend, and holiday coverage, with responsibility for responding to critical alerts, coordinating escalations to restore service, and documenting issues to help prevent recurrence.

Benefits

  • The base salary range listed reflects what Lime reasonably expects to offer for this role, with the final base salary determined by objective factors such as the candidate’s location and relevant skills and experience.
  • Depending on the position, the total compensation package may also include discretionary annual performance bonus opportunities and equity, subject to applicable plan terms and eligibility requirements.

Company Description

Lime is proud to be an Equal Opportunity Employer. We believe different perspectives help us grow and achieve more. That’s why we’re dedicated to building and developing a team that reflects a wider range of backgrounds, abilities, identities, and experiences. If you require a reasonable accommodation during the application or hiring process, please email [email protected] for assistance.

Before You Apply
️
remote Be aware of the location restriction for this remote position: Canada
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Senior Security Engineer @Lime
All Others
Salary cad 120,000 - 1..
Remote Location
Employment Type full-time
Posted 2mths ago
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
️
remote Be aware of the location restriction for this remote position: Canada
β€Ό Beware of scams! When applying for jobs, you should NEVER have to pay anything. Learn more.
Apply for this position
Did not apply βœ“
Applied βœ“
Sent Follow-Up βœ“
Interview Scheduled βœ“
Interview Completed βœ“
Offer Accepted βœ“
Offer Declined βœ“
Application Denied βœ“
Unlock 125,000+ Remote Jobs
Γ—
Apply to the best remote jobs
before everyone else

Access 125,000+ vetted remote jobs and get daily alerts.

4.9 β˜…β˜…β˜…β˜…β˜… from 500+ reviews

⚑ 126,870+ remote jobs, refreshed hourly

πŸ”” Real-time alerts: Apply first, direct to employer

πŸ›‘οΈ Vetted companies, no scams, true remote only

Unlock All Jobs Now

Maybe later