Manager Security Engineering
Toronto-founded enterprise AI company building foundation models, agentic AI, enterprise search, and private deployment products.
About Cohere
Cohere provides enterprise-focused AI models and end-to-end products, including North for agentic workplace AI, Compass for enterprise search, and models for generation and retrieval. It supports private, VPC, and on-premises deployment options.
Skills
About the Role
You will set and execute security priorities, communicate business risks, and lead high-impact security initiatives. You will establish vulnerability-management, SAST, DAST, penetration-testing, and secure-SDLC practices. You will review security architectures, manage bug bounty activity, report security metrics, ensure alignment with relevant standards, and hire, coach, and mentor security engineers.
Requirements
- 8+ years of application-security or security-engineering experience focused on vulnerability management, SDLC, and bug bounty programs
- Experience with SAST, DAST, and penetration-testing methodologies and tools
- Proficiency with Python, GoLang, and web technologies
- Experience with AWS, GCP, Azure, and container security
- Experience building and managing high-performing security teams
- Understanding of secure-engineering best practices, security vulnerabilities, risks, countermeasures, and compensating controls
Responsibilities
- Advise leadership and partner stakeholders on business risks associated with security issues
- Execute the long-term security vision
- Prioritize high-impact initiatives and strategic customer engagements
- Develop and implement enterprise vulnerability-management processes and tooling
- Establish SAST programs and integrate tools into CI/CD pipelines
- Implement DAST methodologies and assess running applications
- Lead internal and external penetration-testing engagements and manage the bug bounty program
- Review and validate security architectures and design patterns
- Embed security practices throughout the software development lifecycle
- Lead, hire, coach, and mentor security engineers
- Establish security metrics and communicate security posture to stakeholders
- Align application-security practices with OWASP Top 10 for LLMs, ISO 27001, and regulatory requirements
Benefits
- Equity
- Weekly lunch stipend of $75/£75 or local-currency equivalent
- Health and dental benefits
- Mental-health budget
- RRSP matching, 401K, and pension scheme
- 100% parental-leave top-up for up to six months
- Annual enrichment benefits for arts and culture, fitness and wellness, quality time, and workspace improvement
- Six weeks of paid vacation
- Travel budget for other offices and an annual company offsite
- Daily lunch, snacks, and community events for office-based employees
- Co-working benefit for employees not near an office
- $500 home-office stipend
