Demo

Principal Product Security Researcher

Jobgether
Canada, KY Full Time
POSTED ON 6/4/2026
AVAILABLE BEFORE 8/3/2026

This position is posted by Jobgether on behalf of a partner company. We are currently looking for a Principal Product Security Researcher in Canada.

This role sits at the forefront of cloud-native product security and software supply chain defense, combining deep technical research with hands-on engineering impact. You will work across complex distributed systems to identify emerging threats, model risks, and design scalable security controls that protect production-grade infrastructure and open-source software supply chains. The position requires strong systems thinking, as you will embed security directly into CI/CD pipelines, Kubernetes environments, and cloud platforms rather than applying it as a final checkpoint. You will influence engineering teams by translating advanced security research into practical, production-ready safeguards. This is a highly technical, individual-contributor role with staff-level scope, offering broad visibility across product and platform engineering. The environment values autonomy, depth of expertise, and the ability to turn security research into actionable system improvements at scale.

\n


Accountabilities:
  • Lead advanced security research focused on cloud-native systems, software supply chains, and production infrastructure risks.
  • Design and implement secure CI/CD pipelines with embedded controls such as signing, provenance tracking, SBOM generation, and automated security gates.
  • Identify, analyze, and mitigate emerging threat vectors across distributed systems and translate findings into engineering solutions.
  • Conduct security architecture reviews and threat modeling for Kubernetes-based workloads across multi-cloud environments (AWS and GCP).
  • Harden containerized workloads, Kubernetes clusters, IAM configurations, and cloud infrastructure to minimize attack surfaces.
  • Define and promote baseline security standards across identity, network, workload, and secrets management domains.
  • Evaluate and operationalize CNAPP/CSPM and related tooling to ensure continuous visibility into cloud and product risk.
  • Partner with engineering teams to integrate security best practices into development workflows and platform systems.
  • Drive cross-functional security improvements through research insights, technical leadership, and hands-on implementation.

Requirements:

  • 7 years of experience in software engineering, security engineering, or a hybrid role with significant hands-on security responsibility.
  • Strong programming skills in Go or Python with experience building, reviewing, and debugging production systems.
  • Deep expertise in Kubernetes security, including cluster hardening, RBAC, network policies, and admission controllers.
  • Extensive experience with AWS and/or GCP, including IAM, workload identity, secrets management, and security services.
  • Proven experience designing and securing CI/CD pipelines using modern tools (e.g., GitHub Actions, Cloud Build, Tekton).
  • Strong knowledge of container security practices, including image hardening, runtime security, and minimal base images.
  • Hands-on experience with software supply chain security frameworks such as SLSA, Sigstore, Cosign, and SBOM generation.
  • Solid understanding of security frameworks including OWASP and NIST, with ability to apply them pragmatically in production environments.
  • Experience with threat modeling, security research, or offensive security practices (e.g., bug bounty, CTFs, penetration testing).
  • Strong communication skills with the ability to influence engineering decisions and explain complex security concepts clearly.
  • Bonus: experience with policy-as-code tools, open-source security contributions, or hardened container ecosystems.

Benefits:

  • Competitive compensation aligned with senior security engineering and research market benchmarks in Canada.
  • Equity participation in a high-growth, venture-backed technology company.
  • Comprehensive health, dental, and vision coverage for employees and dependents.
  • Flexible, remote-first work environment with global collaboration opportunities.
  • Generous flexible time off to support rest and long-term performance.
  • Paid parental leave supporting family and caregiving needs.
  • Home office and remote work stipends to support setup and productivity.
  • Opportunity to work on cutting-edge problems in software supply chain and cloud-native security at global scale.


\n

How Jobgether works:

We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.

We appreciate your interest and wish you the best!

 Why Apply Through Jobgether? 

 

Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.

 

 

#LI-CL1

Salary.com Estimation for Principal Product Security Researcher in Canada, KY
$124,107 to $146,147
If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Principal Product Security Researcher?

Sign up to receive alerts about other jobs on the Principal Product Security Researcher career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$98,763 - $126,233
Income Estimation: 
$116,330 - $143,011
Income Estimation: 
$113,077 - $147,784
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$164,835 - $201,088
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Employees: Get a Salary Increase
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at Jobgether

  • Jobgether Canada, KY
  • This position is posted by Jobgether on behalf of a partner company. We are currently looking for a Digital Marketing Manager in Canada. This role sits at ... more
  • 1 Day Ago

  • Jobgether Canada, KY
  • This position is posted by Jobgether on behalf of a partner company. We are currently looking for a Senior Product Manager in Canada. This role sits at the... more
  • 1 Day Ago

  • Jobgether Canada, KY
  • This position is posted by Jobgether on behalf of a partner company. We are currently looking for a Senior Data Engineer in Canada. This role is a high-imp... more
  • 1 Day Ago

  • Jobgether Canada, KY
  • This position is posted by Jobgether on behalf of a partner company. We are currently looking for a Marketing Analyst in Canada. You will join a global, da... more
  • 1 Day Ago


Not the job you're looking for? Here are some other Principal Product Security Researcher jobs in the Canada, KY area that may be a better fit.

  • Jobgether Canada, KY
  • This position is posted by Jobgether on behalf of a partner company. We are currently looking for a Principal Product Manager in Canada . In this role, you... more
  • 1 Day Ago

  • referralsuseonly Canada, KY
  • Elastic, the Search AI Company, enables everyone to find the answers they need in real time, using all their data, at scale — unleashing the potential of b... more
  • 15 Days Ago

AI Assistant is available now!

Feel free to start your new journey!