Staff Security Engineer

Posted Yesterday
Be an Early Applicant
Hiring Remotely in Ontario, ON, CAN
Remote
160K-200K Annually
Senior level
Fintech • Financial Services
A trusted source of fast, flexible funding for US small businesses.
The Role
Design and own Forward's security technology architecture across AppSec, SecOps, and GRC. Integrate and automate security tooling into cloud, CI/CD, identity, and SaaS ecosystems. Build detection and logging foundations, lead evaluations and rollouts, mentor security engineers, support incident response, and align architecture to compliance frameworks (SOC 2, ISO 27001, NIST).
Summary Generated by Built In

Forward Financing is a financial technology company based in Boston, Massachusetts with team members throughout the United States, Dominican Republic, and Canada. The company is on a mission to unlock the capital that fuels small businesses across America. Recognized as a Best Place to Work by Built In Boston and certified as a Great Place To Work®, Forward is investing in its employees, technology, and customer experience – with long-term success in mind every step of the way.

As a Staff Security Engineer, you’ll own the technical architecture of Forward’s security program at a pivotal moment in our growth. Rather than running a single tool or living inside one team, you’ll be the connective technical layer across our Application Security (AppSec), Security Operations (SecOps), and Governance, Risk, and Compliance (GRC) functions – making sure our security technology works together, scales, and fits naturally into how the rest of the company builds and operates. Reporting directly to the Head of Security, you’ll set the technical direction for how we design, evaluate, and integrate security platforms, and you’ll mentor engineers across all three functions along the way.

In this role you will:

  • Own the end-to-end architecture of Forward’s security technology stack – the platforms, tooling, data pipelines, and integrations that power AppSec, SecOps, and GRC – and make sure it works cleanly with the broader Engineering, IT, and Infrastructure ecosystem.

  • Set the technical direction for how we evaluate, integrate, standardize, and retire security tools, defining the reference architectures and standards the department builds on.

  • Act as the shared technical foundation for all three security functions: helping developers build security testing into how software ships, giving the operations team clean and reliable data to detect and investigate threats, and giving the compliance team the evidence and reporting they need to prove that controls are working.

  • Partner with Engineering, IT, and Infrastructure to build security into shared platforms – cloud (AWS), identity, CI/CD, endpoints, and SaaS – so security is native rather than bolted on.

  • Lead the evaluation, proof-of-concept, and rollout of new security technologies; consolidate overlapping tools and reduce operational toil with defensible build-versus-buy recommendations.

  • Use infrastructure-as-code and detection-as-code to make security configurations, platform hardening, and cloud-native controls automated, versioned, and repeatable.

  • Architect our centralized logging and detection data foundation (SIEM and supporting pipelines) so a single high-quality data source serves detection, investigation, and audit needs.

  • Architect the technical underpinnings of our identity governance and role-based access control programs, plus the automation that keeps access defensible as we grow.

  • Keep the security architecture aligned to frameworks like CIS Controls, ISO 27001, SOC 2, and NIST, so it stays defensible and auditable.

  • Provide senior technical support during major incidents, and turn lessons learned into lasting architectural improvements.

  • Grow the bar for the whole department – mentoring and technically guiding engineers across AppSec, SecOps, and GRC on design quality, secure defaults, and engineering practices.

Why you should apply:

  • Own the architecture: This is a high-visibility, high-impact role at a pivotal moment for Forward’s security program. You’ll have the mandate and support to shape the tools, standards, and technical direction that the entire department is built on.

  • Mission driven company: Forward is a trusted source of fast, flexible funding for small businesses that have often been underserved by traditional financing options. When you join the team, you will help ensure all small businesses have access to the financial support they need to succeed.

  • Flexibility is a top priority: Our employees are empowered to choose where they want to work (whether that’s from home, in the office, or a combination of both) with flexible hours.

Role Requirements:
  • Typically 7 or more years in security engineering, security architecture, detection engineering, or security operations, including designing systems that span multiple security domains.

  • Demonstrated experience owning or heavily shaping the architecture of a security technology stack – how platforms, data, and controls fit together – not just operating a single tool.

  • Deep, hands-on cloud security expertise (AWS required; GCP or Azure a plus), including control plane monitoring, IAM, network architecture, and infrastructure log analysis.

  • A track record of integrating security tooling and controls into broader Engineering and IT ecosystems (CI/CD, identity, endpoints, and SaaS).

  • Fluency across at least two of the three domains this role serves – AppSec, SecOps, and GRC – with enough literacy in the third to design for it.

  • Experience with infrastructure-as-code and/or detection-as-code (e.g., Terraform and CI/CD pipelines for security configurations and detection logic).

  • Working knowledge of security frameworks such as CIS Controls, ISO 27001, SOC 2, and NIST, and how architecture maps to control and audit requirements.

  • Experience with modern programming languages such as Ruby, Python, or Go, sufficient to build automation and integrations.

  • Ability to communicate risk and technical direction crisply to engineers and executives alike.

  • Typically has a Bachelor’s Degree in Computer Science, Physics, or an equivalent technical degree, or equivalent industry experience.

It would be nice if you also had:
  • Prior DevOps or software engineering experience.

  • Experience securing containerized and microservices workloads deployed in production on orchestration platforms such as Kubernetes.

  • Hands-on experience managing multiple AWS environments (VPCs, firewalls, IAM, GuardDuty, CloudTrail, WAF).

  • A history of running proof-of-concept evaluations and leading tool consolidation efforts.

  • Experience with SIEM and detection platforms such as Chronicle, Splunk, Panther, or open-source equivalents.

  • A red-plus-blue-team mindset and familiarity with adversary TTPs (MITRE ATT&CK).

  • Background in fintech or another regulated environment

Compensation:

Annual Targeted Salary: $160,000-$200,000 CAD

Annual Target Bonus: 12%

At Forward Financing, we're committed to fair and transparent compensation. We believe in providing a compensation package that recognizes your skills, experience, and the unique value you bring to our team. We take a market-based approach to pay, regularly reviewing benchmark data to ensure our compensation remains competitive, equitable, and aligned with our performance-driven culture.

 

Final offers are determined by a variety of factors, including the candidate's qualifications, relevant experience, specific skills, and internal equity. This approach ensures that our compensation is competitive and equitable. Your recruiter will provide specific details on the expected base and variable earnings as it pertains to this specific role. This position is to fill an existing vacancy.

Total Rewards:

Additionally, we offer a comprehensive total rewards package, including but not limited to: medical, dental, vision, a flexible time-off policy, paid parental leave, RRSP match, wellness reimbursement, volunteering days, annual professional development budget, and charitable donation match.

 

Forward is proud to be a remote-first company, keeping workplace flexibility a top priority for our employees. As a business, we are focused on impact; we are more concerned with your contributions to the success of the company than where you get your work done. To help facilitate in-person collaboration, employees are welcome to work from one of our premiere office locations.

 

When we aren’t collaborating to drive business and support our customers, we’re finding virtual and in-person ways to get to know our colleagues, celebrate team wins, and have fun together!

Skills Required

  • 7+ years in security engineering, security architecture, detection engineering, or security operations
  • Experience owning or heavily shaping the architecture of a security technology stack
  • Deep, hands-on cloud security expertise (AWS required) including IAM, control plane monitoring, network architecture, and infrastructure log analysis
  • Track record integrating security tooling and controls into CI/CD, identity, endpoints, and SaaS ecosystems
  • Fluency across at least two of AppSec, SecOps, and GRC, with literacy in the third
  • Experience with infrastructure-as-code and/or detection-as-code (e.g., Terraform and CI/CD pipelines for security configurations and detection logic)
  • Working knowledge of security frameworks such as CIS Controls, ISO 27001, SOC 2, and NIST and how architecture maps to control and audit requirements
  • Experience with modern programming languages sufficient to build automation and integrations (Ruby, Python, or Go)
  • Ability to communicate risk and technical direction clearly to engineers and executives
  • Bachelor's degree in Computer Science, Physics, or equivalent technical degree or equivalent industry experience
  • Provide senior technical support during major incidents and convert lessons learned into architectural improvements

What the Team is Saying

Jason
Kenia
Lauren
Ernesto
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Boston, MA
529 Employees
Year Founded: 2012

What We Do

Forward Financing is a financial technology company based in Boston, Massachusetts with team members throughout the United States, Dominican Republic, and Canada. The company is on a mission to unlock the capital that fuels small businesses across America. Forward has been recognized as a Best Place to Work by Built In and is certified as a Great Place To Work.® We’re investing in our employees, technology, and customer experience – with long-term success in mind every step of the way. Want to learn more? Visit: forwardfinancing.com/careers

Why Work With Us

We’re building a place where our people want to run to work every day. Here, you’ll be with colleagues who work together towards shared goals and challenge you to bring your best; you’ll work with leaders who support your professional growth and want to see you succeed.

Gallery

Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery
Gallery

Forward Financing Offices

Remote Workspace

Employees work remotely.

Our Employee Choice policy allows most team members to choose if they’d like to be fully remote, work in our Boston headquarters, the office in the DR, or a hybrid combination.

Typical time on-site: None
HQBoston, MA
Santiago, DO
Learn more

Similar Jobs

Remote
Ontario, ON, CAN
529 Employees

Forward Financing Logo Forward Financing

Senior Data Analyst

Fintech • Financial Services
Remote
2 Locations
529 Employees
114K-144K Annually
Remote
2 Locations
529 Employees

Forward Financing Logo Forward Financing

Lead Data Scientist

Fintech • Financial Services
Remote
2 Locations
529 Employees
160K-220K Annually

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account