Security Cloud Engineer
Treasure Data:
At Treasure Data, we’re on a mission to radically simplify how companies use data and AI to create connected customer experiences. Our intelligent customer data platform (CDP) drives revenue growth and operational efficiency across the enterprise to deliver powerful business outcomes.
We are thrilled that Forrester has recognized Treasure Data as a Leader in The Forrester Wave™: Customer Data Platforms For B2C. It's an honor to be acknowledged for our efforts in advancing the CDP industry with cutting-edge AI and real-time capabilities.
Furthermore, Treasure Data employees are enthusiastic, data-driven, and customer-obsessed. We are a team of drivers—self-starters who take initiative, anticipate needs, and proactively jump in to solve problems. Our actions reflect our values of honesty, reliability, openness, and humility.
Your Role:
Treasure Data is building an AI-native customer data platform with agent-centric products and a growing ecosystem of connected services. The next massive challenge is securing the multi-agent ecosystems built on top of commoditized frontier models. This role exists to stay ahead of that curve, designing security architecture embedded in the tooling and platform defaults so the safe path is the only path. You will approach the work by designing solutions that best serve our customers, ruthlessly utilizing force multipliers to reduce engineering toil, and freeing the team to focus on frontier architecture. You will be joining a small, senior, high-trust team dedicated to solving complex problems, engaging in tight feedback loops with SRE, Cloud Governance, Product Security, and Trust & Assurance teams.
Responsibilities:
Design-Time Threat Modeling: Collaborate alongside product and platform engineers to map new agent types, multi-agent workflows, and AI toolkits while architecture is still fluid to shape trust boundaries and threat models at design time.
Agentic Security Primitives: Define the primitives necessary to make systems safe at enterprise scale, addressing unsolved problems regarding delegation models, multi-agent trust chains, data minimization in RAG workflows, and identity boundaries across customer-built agents.
Architectural Hardening: Own outcomes for complex security areas, ranging from hardening Kubernetes or AWS Bedrock controls to designing trust boundaries for MCP integrations and tackling zero-day risks.
Golden Path Engineering: Design policy-as-code and CI/CD controls for agent-assisted workflows to engineer secure defaults that act as velocity multipliers, enabling flawless engineering movement without routing around security.
Structural Improvements: Lead the effort to detection, respond, and mutate architecture following control failures to turn incidents into structural improvements that prevent recurrence.
Knowledge Codification: Maintain the security playbook for next-generation paradigms by producing opinionated guides, reference repositories, and posture telemetry that compounds over time.
Job Requirements:
A minimum of 5 years of experience in security engineering and architecture at a senior level, with a track record of operating from first principles and building security for systems without established playbooks.
Possess a deep understanding of cloud-native architecture at the identity, networking, and data-protection levels (specifically AWS or equivalent).
Proficiency in writing production-grade Python, Terraform, or TypeScript to prototype controls, script policy checks, and review AI-generated code.
Demonstrated default to leverage, preferring automation by systems or agents over repeatable human tasks.
Ability to earn trust through rigorous logic and influence rather than authoritative mandate.
Physical Requirements:
Working out of our Vancouver, BC office according to our “Global Hybrid Working Policy.”
Travel Requirements:
n/a
Perks and Benefits (CAN):
Our benefit package showcases our culture of care and empathy with
Competitive compensation packages
Restricted Stock Units (RSU)
Paid vacation and sick time
Paid volunteer and mental health days
Up to 26 weeks paid parental leave including a post-partum night nurse
16 Company holidays (includes 2 floating holidays)
RRSP with 6% company match
Employer provided Supplemental medical, dental, disability & life coverage
Comprehensive support and access to care for everyone, everywhere through Carrot - our global reproductive health and family-building benefit
Our Dedication to You:
We value and promote diversity, equity, inclusion, and belonging in all aspects of our business and at all levels. Success comes from acknowledging, welcoming, and incorporating diverse perspectives.
Diverse representation alone is not the desired outcome. We also strive to create an inclusive culture that encourages growth, ownership of your role, and achieving innovation in new and unique ways. Your voice will be heard, and we will help amplify it.
Agencies and Recruiters:
We cannot consider your candidate(s) without a contract in place. Any resumes received without having an active agreement will be considered gratis referrals to us. Thank you for your understanding and cooperation!
- Department
- IT & Security
- Locations
- Vancouver, BC, Canada
- Remote status
- Hybrid
- Yearly salary
- CAD111,000 - CAD175,000
- Employment type
- Full-time
- Employment level
- Professionals
About Treasure Data
Treasure Data is the Intelligent Customer Data Platform (CDP) built for enterprise scale and powered by AI. Recognized as a Leader by Forrester and IDC, Treasure Data empowers the world’s largest and most innovative companies to deliver hyper-personalized customer experiences at scale that increase revenue, reduce costs, and build trust.
Through unique capabilities such as the Diamond Record, AI Agent Foundry, and AI Decisioning with Real-Time Personalization, Treasure Data enables marketing and CX teams to personalize cross-channel engagement in real-time, optimize marketing spend while increasing ROI, and drive customer lifetime value through more intelligent retention and loyalty.