Talent.com
Aalyria Technologies, Inc.
Lead Product Security EngineerAalyria Technologies, Inc. • Winnipeg, Canada
No longer accepting applications
Lead Product Security Engineer

Lead Product Security Engineer

Aalyria Technologies, Inc. • Winnipeg, Canada
10 days ago
Job type
  • Permanent
Job description
Aalyria is a leading technology company that supplies laser communications technology and temporospatial software-defined networking platforms to the aerospace industry. With technology acquired from Google, Aalyria is at the forefront of innovation in satellite and airborne mesh networks, as well as cislunar and deep-space communications. We are revolutionizing the orchestration and management of planetary mesh networks using any radio or optical spectrum, any orbit, and any hardware across land, sea, air, and space.

Role Overview: You’re the technical voice of product security across Aalyria, reporting to the Director of Security & IT. You’ll own application security, CI/CD and supply‑chain security, our Kubernetes‑based product infrastructure, product‑side authentication and PKI, and you’ll partner closely with hardware engineering on Tightbeam.

This is a senior to staff level individual contributor role with room to grow into management as the function scales. We need someone who’s genuinely happy in a terminal and equally comfortable leading an architecture review.

Key Responsibilities:

Application & software security. SAST/DAST/SCA, secure SDLC, threat modeling, and software vulnerability management across our codebase.

CI/CD and supply‑chain security. Hardening our GitLab pipelines, build provenance, dependency integrity, signing, and SLSA‑aligned controls.

Product infrastructure security. GKE and Kubernetes hardening, container security, workload identity, network policy, and runtime protection.

Product PKI. Certificate lifecycle, issuance, rotation, and mTLS architecture across distributed services and remote assets.

Vulnerability management. Triage, prioritization, remediation tracking, and exception handling, for both disclosed upstream issues and internal findings.

Product incident response. Leading triage and response for product‑side security incidents, coordinating with corporate IR, and driving post‑mortems to action.

Product infra hardening. Baseline configurations, secure defaults, and compensating controls across product environments.

Hardware security partnership. Working with the Tightbeam team on firmware security, secure boot, key storage, and hardware supply‑chain integrity.

Required Qualifications:

Senior‑ or staff‑level hands‑on experience in product security or security engineering, with significant depth in software/AppSec.

Production experience securing cloud environments such as IAM, org policy, VPC Service Controls, KMS, and Kubernetes at depth.

Strong cryptographic foundations, PKI architecture, key management, signing, mTLS, and secrets handling at scale.

Hands‑on coding ability in Python, Bash, and Go; you can write tooling, automate controls, and ship Terraform/scripts when the situation calls for it. Comfort reviewing code is a plus.

A track record of building security programs, not just operating tools someone else stood up.

Experience leading product incident response, triage, response, coordination with engineering teams, customer comms, and post‑mortem ownership.

A pattern of mentoring engineers and raising the security bar of teams around you, even without direct reports.

Experience interfacing with hardware/firmware teams, even if hardware isn’t your primary domain.

Strong written communication; you’ll write threat models, design docs, and program updates that go to the executives, customers, and assessors.

Working knowledge of the compliance frameworks that govern our environment such as CMMC, FedRAMP, and DFARS along with the ability to translate controls into engineering work.

Preferred Qualifications:

Hands‑on experience with NIST 800‑53, NIST 800‑171, or DoD SRG environments.

Experience with government‑cloud platforms.

Hardware security depth in HSMs, TPMs, secure elements, supply‑chain attestation.

Embedded / firmware security background, secure boot, RoT, OTA update integrity, hands‑on firmware review.

Experience standing up or running a vulnerability disclosure program or bug bounty, triage, researcher comms, and CVE coordination.

What We Offer:

Innovative Environment:

Work at a cutting‑edge company shaping the future of aerospace communications.

Impactful Work:

Directly contribute to critical national security programs and initiatives.

Growth Opportunities:

Expand your career with opportunities for professional development and advancement.

Inclusive Culture:

Be part of a collaborative, supportive, and inclusive workplace where your contributions matter.

Flexibility:

Flexible working arrangements including hybrid remote/in‑office schedules.

Compensation and Equity:

Competitive salary, comprehensive benefits (401(k), dental, vision, health, life insurance), paid time off, and equity options.

This position involves access to export‑controlled information. To comply with U.S. government export regulations, applicants must meet one of the following criteria:

(A) Qualify as a U.S. person, which includes:

U.S. lawful permanent resident (green card holder)

Asylee under 8 U.S.C. 1158

(B) Be eligible to access export‑controlled information without requiring an export authorization.

(C) Be eligible and reasonably likely to obtain the necessary export authorization from the appropriate U.S. government agency.

The company reserves the right to decline pursuing an export licensing process for legitimate business‑related reasons.

Equal Opportunity Employer Statement: Aalyria is an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate based on race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, age, disability status, genetic information, protected veteran status, or any other characteristic protected by law. Qualified applicants from all backgrounds are encouraged to apply.

#J-18808-Ljbffr
Create a job alert for this search

Lead Product Security Engineer • Winnipeg, Canada

Similar jobs

Lead Product Security Engineer - $150,000 - $200,000 A Year

AalyriaWinnipeg, Canada
Full-time

Lead Product Security Engineer responsible for application security, CI/CD, infrastructure security, PKI, and incident response in the aerospace technology sector. Show more

 • Promoted • New!

Staff Product Security Engineer

AffirmWinnipeg, MB, CA
Full-time

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.Affirm values information... Show more

 • Promoted

Remote Staff Product Security Engineer Focusing on Software Integrity

AffirmWinnipeg, MB, CA
Remote
Full-time

Drive product security initiatives as a highly skilled Staff Product Security Engineer.Work alongside product teams to embed security throughout the development lifecycle in a fully remote environm... Show more

 • Promoted

Product Security Engineer For Web Applications And Cloud Services - Remote

AffirmWinnipeg, Canada
Remote
Full-time

Affirm seeks a Senior Product Security Engineer to ensure product security throughout the development lifecycle by conducting threat modeling, architecture reviews, and code analysis. Show more

 • Promoted

Senior Security Engineer Enhancing Product Integrity and Safety

AffirmWinnipeg, MB, CA
Full-time

Become a pivotal force in product security as a Senior Product Security Engineer.Engage in cross-functional collaboration to improve the security of innovative financial products in a remote role.T... Show more

 • Promoted

Senior Product Security Engineer

Function HealthWinnipeg, Canada
Full-time

Company Overview Function Health is the AI operating system for health, designed to empower people to live 100 healthy years.We are redefining how individuals understand, measure, and improve their... Show more

 • Promoted

Staff Product Security Architect — Remote

AffirmWinnipeg, MB, CA
Remote
Full-time

A leading financial technology company is seeking a Staff Product Security Engineer to enhance product security during development.This remote position entails partnering with product teams, conduc... Show more

 • Promoted

Lead Product Security Engineer

Aalyria Technologies, Inc.Winnipeg, Manitoba, Canada
Permanent

Aalyria is a leading technology company that supplies laser communications technology and temporospatial software-defined networking platforms to the aerospace industry.With technology acquired fro... Show more

 • Promoted

Senior Product Security Engineer

AffirmWinnipeg, MB, CA
Full-time

Affirm is reinventing credit to make it more honest and friendly, giving consumers the flexibility to buy now and pay later without any hidden fees or compounding interest.Affirm values information... Show more

 • Promoted

Senior Product Security Engineer: Build Secure, Scalable Apps

AffirmWinnipeg, MB, CA
Full-time

A financial technology company is seeking a Senior Product Security Engineer to enhance product security throughout the development lifecycle.The ideal candidate will partner with product teams, co... Show more

 • Promoted

Aalyria Senior Product Security Lead

Aalyria Technologies, Inc.Winnipeg, Manitoba, Canada
Full-time

Become Aalyria's Senior Product Security Lead, driving initiatives in application security and CI/CD while supporting a hybrid work environment.Your role is critical to advancing our aerospace comm... Show more

 • Promoted • New!

Senior Product Security Engineer – Remote Canada - Equity

AffirmWinnipeg, MB, CA
Remote
Full-time

A financial technology firm is seeking a Senior Product Security Engineer to ensure security in the product development lifecycle and mitigate vulnerabilities.The ideal candidate should have a stro... Show more

 • Promoted

Product Security Engineer Role At Chainguard

ChainguardWinnipeg, Canada
Full-time

Join Chainguard as a Product Security Engineer, focusing on securing software through innovative CI/CD practices.This individual-contributor role drives security initiatives within a remote-first c... Show more

 • Promoted

Endpoint Security Lead - Millenilink

Millenilinkwinnipeg, mb, ca
Full-time

Contract (6 Months) | Potential Extension.Millenilink is partnering with a large enterprise organization seeking an experienced Endpoint Security Lead to support a major endpoint hardening, applica... Show more

 • Promoted

Lead Product Security Engineer Needed

Function HealthWinnipeg, Manitoba, Canada
Full-time

Function Health is seeking a Senior Product Security Engineer to advance our security protocols in a fast-paced, innovative setting.Your role will focus on integrating security into all stages of p... Show more

 • Promoted

Staff Product Security Engineer New

ChainguardWinnipeg, Manitoba, Canada
Full-time

Chainguard is the trusted source for open source.By delivering hardened, secure, and production-ready builds of all the open source software engineers and AI agents rely on, Chainguard helps organi... Show more

 • Promoted

Endpoint Security Lead

Millenilinkwinnipeg, mb, ca
Full-time

Contract (6 Months) | Potential Extension.Millenilink is partnering with a large enterprise organization seeking an experienced Endpoint Security Lead to support a major endpoint hardening, applica... Show more

 • Promoted

Lead Product Security Engineer

AalyriaWinnipeg, Canada
Full-time

A leading financial technology company is seeking a Senior Product Security Engineer to enhance security across its products.Candidates should have a deep understanding of web application architect... Show more

 • Promoted • New!

Remote Senior Product Security Engineer Driving Security Solutions

AffirmWinnipeg, MB, CA
Remote
Full-time

Elevate product security as a Senior Product Security Engineer.Collaborate with engineering teams to embed security in the product development lifecycle while identifying vulnerabilities and automa... Show more

 • Promoted

Security Engineer in Semiconductor SaaS

Lawrence HarveyWinnipeg, Manitoba, Canada
Full-time

Be a key player in shaping security practices as a Security Engineer with a leading SaaS company in the semiconductor space.Focus on enhancing cloud security measures and response capabilities.Lawr... Show more