← Back to jobs

Security Engineer

Company
Relay
Location
Toronto, CA
Work type
Full Time · Hybrid
Posted
2026-09-15

Job description

Relay is entering an exciting new chapter of growth, and we're looking for a Security Engineer to join the purple team in our security organization. This is a rare early-career opportunity to work across both offensive and defensive security with the mentorship and support to grow quickly.

As a Security Engineer on Relay's purple team, you'll help design and run exercises that test our defenses, surface vulnerabilities, and drive real improvements. You'll work closely with senior security engineers who will coach you through the harder problems, and you'll take increasing ownership of your own workstreams as you build depth.

What You’ll Be Doing
Help plan and run security simulations, and contribute to the security awareness program that comes out of them

Review how sensitive customer and financial data is accessed in Relay's admin dashboards, and help implement improvements

Contribute to strengthening security for our developer environments, including tooling, packages, and access to production

Work alongside delivery, IT, and business teams to turn test findings into tangible fixes, and follow them through to done

Develop and manage Cyber Awareness exercises, including internal phishing attacks

Research emerging threats (e.g. AI misuse, supply chain risks, identity and access challenges, Shadow IT) and help the team figure out what they mean in Relay's context

Share what you find in a way that educates and drives action, building your voice in Relay's security culture

Who You Are
You have roughly 2–4 years of experience in security, or in an adjacent technical role (IT, infrastructure, software engineering, SOC) with meaningful security exposure

You have a solid grasp of security fundamentals: how systems get attacked, how they get defended, and why. You may have gone deep on one side and be eager to learn the other

You can script (Python, Bash, PowerShell, JavaScript, etc.) well enough to automate a task, pull apart data, or build a small tool, and you're comfortable getting better at it

You're comfortable working in cloud and developer environments (AWS, GCP, or Azure; GitHub, CI/CD) and can find your way around them

You're motivated by closing the loop. You don't just want to identify vulnerabilities, you want to see them fixed

You're curious, pragmatic, and collaborative; you ask questions early, you say when you're stuck, and exploring new threats gives you energy

You can explain a technical finding to someone who isn't in security without losing them

You thrive in fast paced environments and embrace change

You have hands-on experience with adversary simulation, detection engineering, penetration testing, incident response, or vulnerability management

You understand authentication and access protocols (SSO, OAuth, SAML, OpenID Connect) or have worked with zero trust principles

You have used tools across the security stack, from SIEM, IPS, WAF and EDR to vulnerability scanners and security automation platforms

Bonus Points
You have experience with cloud IAM, networking, or containerized systems like Docker or Kubernetes

You have participated in purple, red, or blue team rituals

You have experience in fintech, SaaS, or scaling tech companies

You have public security contributions, CTF participation, a home lab, bug bounties, talks, research, or OSS tooling

Original source