Security Engineer
- Company
- Relay
- Location
- Toronto, CA
- Work type
- Full Time · Hybrid
- Posted
- 2026-09-15
Job description
Relay is entering an exciting new chapter of growth, and we're looking for a Security Engineer to join the purple team in our security organization. This is a rare early-career opportunity to work across both offensive and defensive security with the mentorship and support to grow quickly.
As a Security Engineer on Relay's purple team, you'll help design and run exercises that test our defenses, surface vulnerabilities, and drive real improvements. You'll work closely with senior security engineers who will coach you through the harder problems, and you'll take increasing ownership of your own workstreams as you build depth.
What You’ll Be Doing
Help plan and run security simulations, and contribute to the security awareness program that comes out of them
Review how sensitive customer and financial data is accessed in Relay's admin dashboards, and help implement improvements
Contribute to strengthening security for our developer environments, including tooling, packages, and access to production
Work alongside delivery, IT, and business teams to turn test findings into tangible fixes, and follow them through to done
Develop and manage Cyber Awareness exercises, including internal phishing attacks
Research emerging threats (e.g. AI misuse, supply chain risks, identity and access challenges, Shadow IT) and help the team figure out what they mean in Relay's context
Share what you find in a way that educates and drives action, building your voice in Relay's security culture
Who You Are
You have roughly 2–4 years of experience in security, or in an adjacent technical role (IT, infrastructure, software engineering, SOC) with meaningful security exposure
You have a solid grasp of security fundamentals: how systems get attacked, how they get defended, and why. You may have gone deep on one side and be eager to learn the other
You can script (Python, Bash, PowerShell, JavaScript, etc.) well enough to automate a task, pull apart data, or build a small tool, and you're comfortable getting better at it
You're comfortable working in cloud and developer environments (AWS, GCP, or Azure; GitHub, CI/CD) and can find your way around them
You're motivated by closing the loop. You don't just want to identify vulnerabilities, you want to see them fixed
You're curious, pragmatic, and collaborative; you ask questions early, you say when you're stuck, and exploring new threats gives you energy
You can explain a technical finding to someone who isn't in security without losing them
You thrive in fast paced environments and embrace change
You have hands-on experience with adversary simulation, detection engineering, penetration testing, incident response, or vulnerability management
You understand authentication and access protocols (SSO, OAuth, SAML, OpenID Connect) or have worked with zero trust principles
You have used tools across the security stack, from SIEM, IPS, WAF and EDR to vulnerability scanners and security automation platforms
Bonus Points
You have experience with cloud IAM, networking, or containerized systems like Docker or Kubernetes
You have participated in purple, red, or blue team rituals
You have experience in fintech, SaaS, or scaling tech companies
You have public security contributions, CTF participation, a home lab, bug bounties, talks, research, or OSS tooling