Security Engineer at League Inc. | CA | Rezi

Security Engineer at League Inc.

Security Engineer

League Inc. · CA

Yesterday

Security Engineer

League Inc. · CA

a day ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

League's security engineering team is responsible for scaling security across the development lifecycle, believing in security by design and following a paved-road philosophy. This role is an intermediate security engineer who splits their time between engagement work (security reviews, technical deep dives, vendor assessments) and engineering work (automation, pipeline checks, tooling). The role involves reviewing AI-enabled features and AI-assisted development tooling, requiring a systems and processes mindset to find long-term fixes. We welcome diverse experience and new ideas to challenge the norm and raise the bar of security.

Responsibilities

  • Conduct security reviews of product features, integrations, and platform changes, documenting resulting security requirements
  • Participate in threat modeling exercises to identify risks in system design and data flow
  • Perform security assessments of applications, APIs, and cloud configuration, and provide remediation guidance engineering teams can act on
  • Review AI-enabled product features for prompt injection, excessive agency and unintended exposure of member data
  • Triage and score security findings, and drive remediation with the owning teams
  • Own the configuration, tuning, and triage workflow for security tooling
  • Automate manual review efforts and embed security checks into the SDLC
  • Build training materials and documentation on secure coding practices and common vulnerabilities; regularly share knowledge with peers
  • Support League’s shift left by contributing reusable security controls to our paved road so that common vulnerabilities are prevented by default
  • Contribute to the development and maintenance of League’s security standards and internal documentation.
  • Conduct security reviews of third-party vendors that process or store League data, and support customer security assurance requests.
  • Support SOC 2 Type II, HITRUST, HIPAA, and PHIPA control design, testing, and evidence gathering in partnership with the Privacy and Compliance team.
  • Communicate risk findings clearly to different audiences, adapting language and level of detail for engineers versus leadership.
  • Ensure access management is performed in compliance with the employee's role and responsibilities
  • Responsibility and accountability for executing League's policies and procedures within the department/ team
  • Notification of HR, Legal, Compliance & Security of any incidents, breaches or policy violations
  • Compliance with Information Security Policies

Requirements

  • 2+ years of professional experience in application or product security, or in software engineering with substantial security responsibility
  • Ability to find what scanners miss: broken access control, tenant isolation failures, business logic flaws
  • Working knowledge of authentication and authorization in modern applications, including OAUTH 2.0 / OIDC, session and token handling, and role or attribute-based access control
  • Familiarity with CI / CD and software supply chain security, including pipeline-integrated testing, dependency management, and secrets handling
  • Solid working knowledge of common application vulnerabilities (e.g., OWASP Top 10) and their mitigations
  • Experience with AI and LLM application security, including prompt injection, agentic tool-use risk and retrieval pipeline exposure
  • Some exposure to cloud security concepts and secure cloud architecture, ideally GCP, including containerized workloads.
  • A track record of writing and shipping code other people rely on, in Python, Go, or a comparable language
  • Some experience with threat modeling methodologies (e.g. STRIDE)
  • General awareness of SOC 2 Type II, HITRUST, HIPAA and PIPEDA
  • Demonstrated experience using AI tools in a practical, responsible way
  • Curiosity and openness to experimenting with new technologies
  • Ability to balance efficiency with quality and sound judgment

Skills

  • Application Security
  • Product Security
  • Software Engineering
  • Security Reviews
  • Threat Modeling
  • Cloud Architecture
  • Vendor Assessments
  • AI Security
  • LLM Security
  • Prompt Injection
  • Authentication
  • Authorization
  • OAUTH 2.0
  • OIDC
  • CI/CD
  • Software Supply Chain Security
  • OWASP Top 10
  • GCP
  • Python
  • Go
  • SOC 2 Type II
  • HITRUST
  • HIPAA
  • PHIPA
  • PHIPA
  • Data Security
  • Incident Response
  • AI Tools

Location

  • Remote (Canada)
  • Remote (US)
  • Toronto, Canada

Work Type

  • Full-time
  • Hybrid

Experience Level

  • Intermediate
  • 2+ years of professional experience

Salary/Compensations

  • $109,100—$136,400 CAD

About the Company

  • League is one of the fastest-growing technology companies in Canada and the leading healthcare experience platform.
  • League closes the gap in healthcare by identifying what each person needs to do next, clearing what’s in their way, and getting it done.
  • Health plans and health systems trust League to manage healthcare at scale for over 70 million people.
  • League ships AI-enabled features and its engineers work with AI-assisted development tooling daily.
  • League is an AI-native organization, expecting all employees to leverage AI to improve their work.
  • League celebrates differences and is looking for the best candidates, not necessarily those who meet every qualification.

Equal Opportunity

  • We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status.
  • If you are an individual in need of assistance at any time during our recruitment process, please contact us at recruitinginfo@league.com.