← Back to results

Senior Security Engineer - Cloud Security

Join PagerDuty as a Senior Security Engineer to enhance cloud security across AWS and Kubernetes environments.

Location
Toronto, Ontario, Canada
Compensation
CA$156.8k–CA$206.8k/yr
Level
senior
Type
full time · Hybrid

Posted by employer 1 day ago

First seen on Joblaze 8 hours ago

Last verified on the company career page 8 hours ago

What you'll build

  • Harden AWS and Kubernetes environments
  • Own Kubernetes and container security
  • Build and operate security-focused platforms
  • Own PKI and encryption standards
  • Shape detection strategy for Kubernetes and identity

Must have

  • 5+ years in security engineering
  • Strong software engineering background
  • Proficiency in Python and/or Go
  • Deep expertise with AWS security services
  • Ability to automate security controls as code

Nice to have

  • Hands-on expertise in PKI and cryptography
  • Experience building agentic or AI-assisted security automation
  • Familiarity with securing AI/ML workloads
  • Experience with CIS Benchmarks and DISA STIGs
  • Exposure to Azure security

Practical constraints

  • Work 2 days a week from the Toronto office

AI in the day-to-day

We lean hard into AI to move faster, using and building agentic solutions to streamline security processes.

Requirements

Experience
5+ years

Not disclosed in this posting: visa sponsorship.

Benefits

Flexible work arrangements Comprehensive benefits package Paid Parental Leave Company equity Paid Volunteer Time Off Competitive salary

Joblaze summary

In the role of Senior Security Engineer for Cloud Security at PagerDuty, the individual will focus on building and maintaining security systems to safeguard the company's AWS and Kubernetes environments. Key skills include proficiency in Python or Go, Terraform, and a strong background in securing containerized applications and identity management. This position is ideal for experienced security engineers with a solid understanding of cloud security practices and a proactive approach to incident response. The team operates in a fast-paced environment, leveraging AI to enhance security processes and support over 30 engineering teams.

Joblaze insights

  • Listed today — first seen on Joblaze October 1, 2026. Last confirmed on PagerDuty's careers page October 1, 2026.
  • This exact title is also open at 1 other location at PagerDuty: Atlanta.
  • Starts above 67% of 18 comparable senior security roles in Canada we track (median $106,653 across 10 companies).

Quick facts

Is the Senior Security Engineer - Cloud Security role remote?
It's hybrid — PagerDuty expects some on-site time in Toronto, Ontario, Canada.
What's the salary range?
PagerDuty lists CAD 156,800–CAD 206,800 for this role.
How much experience is required?
At least 5 years of relevant experience for this Senior Security Engineer - Cloud Security role.
Where is the role based?
PagerDuty is hiring for this position in Toronto, Ontario, Canada.
What's the tech stack?
Joblaze extracted these technologies from the posting: AWS, CloudTrail, Go, GuardDuty, Istio, Kubernetes.
What seniority level is this role?
PagerDuty targets senior candidates for this position.
Is this full-time or contract?
Full-time for this Senior Security Engineer - Cloud Security role at PagerDuty.

From the original posting

PagerDuty, Inc. (NYSE: PD) is the global leader in AI-first digital operations. By automatically detecting, diagnosing, and remediating issues, the PagerDuty Platform orchestrates AI agents and automated workflows with context from over 750 integrations. Trusted by approximately two-thirds of the Fortune 100 and nearly half of the Fortune 500, PagerDuty is the industry standard for organizations scaling resilient, autonomous operations. Notable customers include Chipotle, Cloudflare, Docusign, Fox, Nvidia, Salesforce, Spotify, Zoom and more. We are growing rapidly and hiring top talent with leading AI skills across engineering, sales, product, marketing, and beyond as we build the leading digital operations platform.

Senior Security Engineer — Cloud Security (Platform Engineering, Kubernetes & Identity)

PagerDuty is seeking a Senior Security Engineer to join our Cloud Security team, part of Security Engineering within the CTO organization. This is a preventive, platform-focused role for a strong engineer: you'll build and operate security-focused systems at scale to protect PagerDuty's multi-account AWS environment and the Kubernetes platforms running on it, with deep responsibility across container security and identity & access management (and, ideally, cryptography and key management). You'll harden the platform, design least-privilege identity and workload identity, and — because we're a lean team without a dedicated SOC — you'll shape detection strategy for the domains you own (Kubernetes and identity) and hunt during incidents. We lean hard into AI to move faster, so you'll both use and build agentic solutions to streamline how the team hardens, threat models, assesses risk, and operates. You'll partner with 30+ engineering teams to unblock them securely, and since we own and operate what we build, your controls ship as code, get validated against real usage, and roll out without disrupting engineering — including across our FedRAMP footprint.

**This role will be require to work 2 days week from our Toronto, Ontario office**

What you'll do

  • Harden PagerDuty's AWS and Kubernetes environments against CIS Benchmarks, DISA STIGs, and FedRAMP Moderate (Class C) baselines across a multi-account, multi-org footprint — proving results through evidence, config-remediation tooling, and KPIs that track posture, identity, and encryption/PKI health so we know where we stand and where the gaps are.
  • Own Kubernetes and container security end to end — harden EKS clusters and the Istio service mesh against the CIS Kubernetes Benchmark, DISA Kubernetes STIG, and NSA/CISA Kubernetes hardening guidance, design and enforce Kubernetes RBAC and least-privilege workload identity (IRSA/pod identity), and drive controls for the container supply chain (image provenance, admission control, runtime policy).
  • Build and operate security-focused platforms, services, and automation at scale — using Python/Go, Terraform, and Kubernetes policy-as-code — that reduce manual work and let 30+ engineering teams move quickly and safely.
  • Own PKI and encryption standards across the environment — certificate lifecycle and management, KMS-backed key management and rotation, TLS/mTLS (including within the Istio mesh), and encryption-at-rest and in-transit requirements — and define the standards other teams build against.
  • Design and roll out Service Control Policy (SCP) guardrails and least-privilege IAM/PAM across dozens of accounts and multiple orgs.
  • Lean into AI to unlock efficiency and velocity — consume agentic tooling in day-to-day work and build lightweight agentic solutions that streamline repetitive security work: posture triage, threat modeling, risk assessment, incident enrichment and investigation, compliance-evidence generation, and detection tuning.
  • Shape detection strategy for the domains you own — Kubernetes/Istio and identity — authoring and tuning detections in our SIEM stack, defining what "good" coverage looks like for these domains, and threat hunting for container escape, lateral movement, anomalous mesh traffic, and identity or credential abuse.
  • Participate in the team's on-call rotation, triaging and dispositioning cloud and Kubernetes threat alerts and acting as Incident Commander during incidents — driving containment, blast-radius/exposure analysis, and post-incident review.
  • Partner closely with our AppSec and GRC teams — aligning platform controls with secure-development needs and translating hardening, identity, and encryption work into audit and compliance evidence.

Additional responsibilities

  • Mentor and guide teammates on platform, identity, and cryptography security practices, and contribute to roadmap and annual planning. At the senior end of this role, you'll help draft external- and auditor-facing communication and represent the team in cross-team planning.

Basic qualifications

  • Strong software engineering background — years building and operating production systems at scale, with the ability to design and ship security-focused platforms, services, and tooling as a developer (not just configure them). Proficiency in Python and/or Go (or similar) and Infrastructure as Code (Terraform).
  • 5+ years in security engineering with deep, hands-on expertise securing Kubernetes and containerized environments — EKS, Kubernetes RBAC, admission control (e.g., OPA/Gatekeeper or Kyverno), network policy, workload identity (IRSA/pod identity), container runtime/image security, and a service mesh such as Istio.
  • Deep expertise with AWS security services and least-privilege IAM/PAM — IAM family, Organizations/SCPs, Secrets Manager, KMS, GuardDuty, CloudTrail, and Config.
  • Ability to automate security controls as code (Kubernetes policy-as-code) and inform detection strategy in a modern SIEM (e.g., CrowdStrike NG-SIEM, Splunk), including threat hunting within your domains.
  • Experience with incident response and on-call, a builder's mindset toward AI/agentic tooling to accelerate security work, and a track record of scoping ambiguous projects and driving them to completion with high ownership.

Preferred qualifications

  • Hands-on expertise in PKI and cryptography — certificate lifecycle/management, TLS/mTLS, key management and rotation (AWS KMS or similar HSM/KMS), and encryption at rest and in transit.
  • Hands-on hardening to CIS Benchmarks and DISA STIGs within a FedRAMP (or similar) program; familiarity with NIST CSF, SOC 2, or ISO 27001; and experience partnering with AppSec and GRC teams to produce compliance evidence.
  • Experience building agentic or AI-assisted security automation, and familiarity with securing AI/ML or agentic workloads running on cloud and Kubernetes infrastructure.
  • Cloud-native security tooling such as Wiz (CNAPP/Threats) and CrowdStrike Falcon runtime protection; Azure security exposure (Entra ID, Defender for Cloud) a plus.
  • Demonstrated mentoring, strong written and verbal communication, and working knowledge of PagerDuty's Incident Management and Process Automation products.

The base salary range for this position is 156,800 - 206,800 CAD. This role may also be eligible for bonus, commission, equity, and/or benefits.

Hesitant to apply?

PagerDuty uses the E-Verify employment verification program.

Standard company text repeated across PagerDuty's postings is omitted here.

Similar positions

PagerDuty
PagerDuty
Principal Product Manager - Platform Security
PagerDuty · Atlanta; San Francisco; Toronto
PagerDuty
Senior AI/ML Engineer
PagerDuty · Lisbon
PagerDuty
Senior Developer Advocate
PagerDuty · Toronto
PagerDuty
Senior Front- End Engineer
PagerDuty · Lisbon