Senior Security Engineer - Cloud Security

Posted Yesterday
Easy Apply
Be an Early Applicant
Toronto, ON, CAN
Hybrid
157K-207K Annually
Senior level
Artificial Intelligence • Cloud • Information Technology • Machine Learning • Software • Big Data Analytics • Automation
Empowering teams of all kinds to do the critical work that moves business forward through the PagerDuty Operations Cloud
The Role
Build and operate cloud security platforms protecting PagerDuty’s AWS and Kubernetes environments. Harden EKS, Istio, containers, IAM, PKI, and encryption; automate controls with Python, Go, Terraform, and policy-as-code. Shape detections, threat hunting, incident response, and compliance evidence across FedRAMP environments. Partner with engineering, AppSec, and GRC teams, develop AI-assisted security automation, participate in on-call, mentor teammates, and lead security initiatives.
Summary Generated by Built In

PagerDuty, Inc. (NYSE: PD) is the global leader in AI-first digital operations. By automatically detecting, diagnosing, and remediating issues, the PagerDuty Platform orchestrates AI agents and automated workflows with context from over 750 integrations. Trusted by approximately two-thirds of the Fortune 100 and nearly half of the Fortune 500, PagerDuty is the industry standard for organizations scaling resilient, autonomous operations. Notable customers include Chipotle, Cloudflare, Docusign, Fox, Nvidia, Salesforce, Spotify, Zoom and more. We are growing rapidly and hiring top talent with leading AI skills across engineering, sales, product, marketing, and beyond as we build the leading digital operations platform.


Senior Security Engineer — Cloud Security (Platform Engineering, Kubernetes & Identity)

PagerDuty is seeking a Senior Security Engineer to join our Cloud Security team, part of Security Engineering within the CTO organization. This is a preventive, platform-focused role for a strong engineer: you'll build and operate security-focused systems at scale to protect PagerDuty's multi-account AWS environment and the Kubernetes platforms running on it, with deep responsibility across container security and identity & access management (and, ideally, cryptography and key management). You'll harden the platform, design least-privilege identity and workload identity, and — because we're a lean team without a dedicated SOC — you'll shape detection strategy for the domains you own (Kubernetes and identity) and hunt during incidents. We lean hard into AI to move faster, so you'll both use and build agentic solutions to streamline how the team hardens, threat models, assesses risk, and operates. You'll partner with 30+ engineering teams to unblock them securely, and since we own and operate what we build, your controls ship as code, get validated against real usage, and roll out without disrupting engineering — including across our FedRAMP footprint.

**This role will be require to work 2 days week from our Toronto, Ontario office**

What you'll do
  • Harden PagerDuty's AWS and Kubernetes environments against CIS Benchmarks, DISA STIGs, and FedRAMP Moderate (Class C) baselines across a multi-account, multi-org footprint — proving results through evidence, config-remediation tooling, and KPIs that track posture, identity, and encryption/PKI health so we know where we stand and where the gaps are.
  • Own Kubernetes and container security end to end — harden EKS clusters and the Istio service mesh against the CIS Kubernetes Benchmark, DISA Kubernetes STIG, and NSA/CISA Kubernetes hardening guidance, design and enforce Kubernetes RBAC and least-privilege workload identity (IRSA/pod identity), and drive controls for the container supply chain (image provenance, admission control, runtime policy).
  • Build and operate security-focused platforms, services, and automation at scale — using Python/Go, Terraform, and Kubernetes policy-as-code — that reduce manual work and let 30+ engineering teams move quickly and safely.
  • Own PKI and encryption standards across the environment — certificate lifecycle and management, KMS-backed key management and rotation, TLS/mTLS (including within the Istio mesh), and encryption-at-rest and in-transit requirements — and define the standards other teams build against.
  • Design and roll out Service Control Policy (SCP) guardrails and least-privilege IAM/PAM across dozens of accounts and multiple orgs.
  • Lean into AI to unlock efficiency and velocity — consume agentic tooling in day-to-day work and build lightweight agentic solutions that streamline repetitive security work: posture triage, threat modeling, risk assessment, incident enrichment and investigation, compliance-evidence generation, and detection tuning.
  • Shape detection strategy for the domains you own — Kubernetes/Istio and identity — authoring and tuning detections in our SIEM stack, defining what "good" coverage looks like for these domains, and threat hunting for container escape, lateral movement, anomalous mesh traffic, and identity or credential abuse.
  • Participate in the team's on-call rotation, triaging and dispositioning cloud and Kubernetes threat alerts and acting as Incident Commander during incidents — driving containment, blast-radius/exposure analysis, and post-incident review.
  • Partner closely with our AppSec and GRC teams — aligning platform controls with secure-development needs and translating hardening, identity, and encryption work into audit and compliance evidence.
Additional responsibilities
  • Mentor and guide teammates on platform, identity, and cryptography security practices, and contribute to roadmap and annual planning. At the senior end of this role, you'll help draft external- and auditor-facing communication and represent the team in cross-team planning.
Basic qualifications
  • Strong software engineering background — years building and operating production systems at scale, with the ability to design and ship security-focused platforms, services, and tooling as a developer (not just configure them). Proficiency in Python and/or Go (or similar) and Infrastructure as Code (Terraform).
  • 5+ years in security engineering with deep, hands-on expertise securing Kubernetes and containerized environments — EKS, Kubernetes RBAC, admission control (e.g., OPA/Gatekeeper or Kyverno), network policy, workload identity (IRSA/pod identity), container runtime/image security, and a service mesh such as Istio.
  • Deep expertise with AWS security services and least-privilege IAM/PAM — IAM family, Organizations/SCPs, Secrets Manager, KMS, GuardDuty, CloudTrail, and Config.
  • Ability to automate security controls as code (Kubernetes policy-as-code) and inform detection strategy in a modern SIEM (e.g., CrowdStrike NG-SIEM, Splunk), including threat hunting within your domains.
  • Experience with incident response and on-call, a builder's mindset toward AI/agentic tooling to accelerate security work, and a track record of scoping ambiguous projects and driving them to completion with high ownership.
Preferred qualifications
  • Hands-on expertise in PKI and cryptography — certificate lifecycle/management, TLS/mTLS, key management and rotation (AWS KMS or similar HSM/KMS), and encryption at rest and in transit.
  • Hands-on hardening to CIS Benchmarks and DISA STIGs within a FedRAMP (or similar) program; familiarity with NIST CSF, SOC 2, or ISO 27001; and experience partnering with AppSec and GRC teams to produce compliance evidence.
  • Experience building agentic or AI-assisted security automation, and familiarity with securing AI/ML or agentic workloads running on cloud and Kubernetes infrastructure.
  • Cloud-native security tooling such as Wiz (CNAPP/Threats) and CrowdStrike Falcon runtime protection; Azure security exposure (Entra ID, Defender for Cloud) a plus.
  • Demonstrated mentoring, strong written and verbal communication, and working knowledge of PagerDuty's Incident Management and Process Automation products.

The base salary range for this position is 156,800 - 206,800 CAD. This role may also be eligible for bonus, commission, equity, and/or benefits.

Our base salary ranges are determined by role, level, and location. The range, which is subject to change based on primary work location, reflects the minimum and maximum base salary we expect to pay newly hired employees for the position. Within the range, we determine pay for an individual based on a number of factors including market location, job-related knowledge, skills/competencies and experience.

Your recruiter can share more about the specific offerings for this role, as well as the salary range for your primary work location during the hiring process.

Hesitant to apply?

We encourage you to submit your resume even if you don't meet every requirement. We value potential and consider each candidate's full professional story. Whether you're exploring a career change or taking your next step, we look forward to reviewing your application. If this just isn’t the right role or time - sign up for job alerts!

Where we work

PagerDuty operates a hybrid work model with offices in 8 major cities: Atlanta, Lisbon, London, San Francisco, Santiago, Sydney, Tokyo, and Toronto. While we offer flexibility within our established locations, we cannot employ candidates residing in:

Location restrictions:
Australia: Northern Territory, Queensland, South Australia, Tasmania, Western Australia
Canada: Alberta, Manitoba, Newfoundland, Northwest Territories, Nunavut, PEI, Quebec, Saskatchewan, Yukon
United States: Alaska, Hawaii, Iowa, Louisiana, Mississippi, Nebraska, New Mexico, Oklahoma, Rhode Island, South Dakota, West Virginia, Wyoming
Candidates must reside in an eligible location, which vary by role.

How we work

Our values guide how we support customers, collaborate with colleagues, develop products, and foster a culture of belonging. They define not just our actions, but what it means to be Dutonian.

People Leaders at PagerDuty are responsible for creating high performance environments that drive accountability. PagerDuty has four key dimensions that define our Leadership Impact: Lead Self, Lead the Team, Lead the Business, and Lead the Future. Each dimension has three associated competencies to give leaders a shared language for guiding their development, career, promotion, and succession planning discussions. Our Manager Expectations serve as a practical guide for managers to understand their responsibilities, prioritize their efforts, and drive engagement and performance.

What we offer

As a global organization, our total rewards approach is competitive with industry standards and aligned with local laws and regulations. Learn more, including country-specific offerings, on our benefits site.

Your package may include:

  • Competitive salary
  • Comprehensive benefits package 
  • Flexible work arrangements
  • Company equity*
  • ESPP (Employee Stock Purchase Program)*
  • Retirement or pension plan*
  • Generous paid vacation time
  • Paid holidays and sick leave
  • Dutonian Wellness Days & HibernationDuty - companywide paid days off in addition to PTO
  • Paid parental leave: 22 weeks for pregnant parent, 12 weeks for non-pregnant parent (some countries have longer leave standards and we comply with local laws)*
  • Paid volunteer time off: 20 hours per year
  • Company-wide hack weeks
  • Mental wellness programs

*Eligibility may vary by role, region, and tenure

About PagerDuty

PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management. The PagerDuty Operations Cloud is an AI-powered platform that empowers business resilience and drives operational efficiency for enterprises. With a generative AI assistant at its core, PagerDuty empowers teams to detect and resolve issues in real time, orchestrate complex workflows, and drive continuous improvement across their digital operations. Trusted by nearly half of both the Fortune 500 and the Forbes AI 50, as well as approximately two-thirds of the Fortune 100, PagerDuty is essential for delivering always-on digital experiences to modern businesses

PagerDuty is Great Place to Work-certified™, a Fortune Best Workplace for Millennials, a Fortune Best Medium Workplace, a Fortune Best Workplace in Technology, and a top rated product on TrustRadius and G2. 

Go behind-the-scenes on our careers site and @pagerduty on Instagram.

Additional Information

PagerDuty is an equal opportunity employer. PagerDuty does not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, parental status, veteran status, or disability status. Your privacy is important to us. By submitting an application, you confirm that you have read and understand PagerDuty's Privacy Policy.

PagerDuty is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application process. Should you require accommodation, please email [email protected] and we will work with you to meet your accessibility needs.

PagerDuty uses the E-Verify employment verification program.

Skills Required

  • Strong software engineering background building and operating production systems at scale
  • Proficiency in Python and/or Go or similar programming languages
  • Experience with Infrastructure as Code, particularly Terraform
  • 5+ years of experience in security engineering
  • Deep hands-on expertise securing Kubernetes and containerized environments
  • Experience with Amazon EKS, Kubernetes RBAC, admission control, network policy, workload identity, container runtime/image security, and Istio or another service mesh
  • Deep expertise with AWS security services and least-privilege IAM/PAM
  • Experience automating security controls as code and informing detection strategy in a modern SIEM
  • Experience with incident response and on-call responsibilities
  • Experience scoping ambiguous projects and driving them to completion with high ownership
  • Hands-on expertise in PKI and cryptography, including certificate lifecycle management, TLS/mTLS, key management, and encryption
  • Experience hardening systems to CIS Benchmarks and DISA STIGs within a FedRAMP or similar program
  • Familiarity with NIST CSF, SOC 2, or ISO 27001
  • Experience partnering with AppSec and GRC teams to produce compliance evidence
  • Experience building agentic or AI-assisted security automation
  • Familiarity with securing AI/ML or agentic workloads on cloud and Kubernetes infrastructure
  • Experience with Wiz and CrowdStrike Falcon runtime protection
  • Azure security exposure, including Entra ID and Defender for Cloud
  • Demonstrated mentoring and strong written and verbal communication
  • Working knowledge of PagerDuty Incident Management and Process Automation products

What the Team is Saying

Jen
Suzan
Kyle
Anne
Hannah
Jhanae
Ben
Alan
Kurt
Evelyn Bassett
Caroline Hood
Dormain Drewitz
Mandi Walls
Kurt
Karen
Vince
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
Atlanta, GA
1,200 Employees
Year Founded: 2009

What We Do

PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management, enabling customers to achieve operational efficiency at scale with the PagerDuty Operations Cloud. The PagerDuty Operations Cloud combines AIOps, Automation, Customer Service Operations and Incident Management with a powerful generative AI assistant to create a flexible, resilient and scalable platform to increase innovation velocity, grow revenue, reduce cost, and mitigate the risk of operational failure. Half of the Fortune 500 and nearly 70% of the Fortune 100 rely on PagerDuty as essential infrastructure for the modern enterprise. PagerDuty is Great Place to Work-certified™, a Fortune Best Workplace for Millennials, a Fortune Best Medium Workplace, a Fortune Best Workplace in Technology, and a top rated product on TrustRadius and G2. Go behind-the-scenes at careers.pagerduty.com and @pagerduty on Instagram.

Why Work With Us

PagerDuty offers a hybrid, flexible environment where ambition thrives. We champion innovation, learning, and growth through our core values: Champion the Customer, Take the Lead, Run Together, Ack & Own, and Bring Your Self. Join us!

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

PagerDuty Offices

Hybrid Workspace

Employees engage in a combination of remote and on-site work.

We offer a hybrid, flexible workplace, while also providing ample opportunities for connection in-person and virtually with your colleagues.

Typical time on-site: 1 days a week
Company Office Image
Atlanta, GA
Company Office Image
Lisbon, PT
Company Office Image
London, GB
Company Office Image
San Francisco, CA
Company Office Image
Santiago, CL
Company Office Image
Sydney, NSW
Company Office Image
Tokyo, JP
Company Office Image
Toronto, Ontario
Learn more

Similar Jobs

PagerDuty Logo PagerDuty

Senior Engineer

Artificial Intelligence • Cloud • Information Technology • Machine Learning • Software • Big Data Analytics • Automation
Easy Apply
Hybrid
Toronto, ON, CAN
1200 Employees
125K-175K Annually

PagerDuty Logo PagerDuty

Consultant

Artificial Intelligence • Cloud • Information Technology • Machine Learning • Software • Big Data Analytics • Automation
Easy Apply
Hybrid
Toronto, ON, CAN
1200 Employees
144K-197K Annually

PagerDuty Logo PagerDuty

Account Manager

Artificial Intelligence • Cloud • Information Technology • Machine Learning • Software • Big Data Analytics • Automation
Easy Apply
Hybrid
Toronto, ON, CAN
1200 Employees
105K-127K Annually

PagerDuty Logo PagerDuty

Senior Principal Industry Analyst Relations

Artificial Intelligence • Cloud • Information Technology • Machine Learning • Software • Big Data Analytics • Automation
Easy Apply
Hybrid
Toronto, ON, CAN
1200 Employees
153K-231K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account