Senior Technical Security Analyst

Toronto, Canada
R&D – Engineering
Shopify receives millions of unique visitors each month and serves billions of requests per day. Our Processing Integrity Team, part of the broader Security and Trust Team here at Shopify, makes sure we provide a trustworthy commerce platform for our 600,000+ merchants each and every day.

As a Senior Technical Security Analyst on the Processing Integrity Team, you'll be a part of a highly adaptable group of folks embedded in Engineering. You'll dig deep into our systems and processes and collaborate with security engineers, developers, and members of other teams to protect our merchants and our company while supporting Shopify's rapid pace of development.

Requirements for the role:

    • A love of learning. You love digging into new products as they're developed, teaching yourself new skills, and sharing what you've learned.
    • Dedication to building relationships. You have empathy for other teams and how our work could impact them.
    • Systems thinking and communication skills. You can see the 10,000-foot view and use visual aids to communicate it to others.
    • Flexibility and lateral thinking. You can design and adapt safeguards in a constantly changing setting.
    • A trust mindset. You can assess the security of an environment and identify areas for improvement. 
    • Comfort working autonomously. You can leverage our Default to Open culture to gather the context you need to meet your goals.
    • Keen pattern recognition. You can spot redundancy and identify opportunities for automation.

Bonus experience:

    • Building controls around security safeguards and frameworks such as SOX, SOC 1, SOC 2, and PCI (SOC 2 experience would be a HUGE asset, based on the work the team is engaged in at the moment).
    • Software development experience or experience working with developers.
    • Experience with threat modeling techniques. 


    • Blazing a trail and disrupting traditional ideas of compliance while maintaining trust.
    • Assessing the effectiveness of safeguards.
    • Automating safeguards to reduce toil across Shopify.
    • Gathering information and creating documentation to enable a self service model for assurance.
    • Coming up with new ways to convey complex ideas.
    • Assessing the trustworthiness of product changes and communicating the security posture to engineering and development teams. 
    • Being the external voice of Shopify's platform to potential and existing merchants and auditors.
We know that looking for a new role can be both exciting and time-consuming, and we truly appreciate your effort. Katie is an actual real live person (👋) and is looking forward to learning more about you through your application. 
And remember, we want to know what you're really interested in building and why you want to build it at Shopify, so please give us as much detail on this as you'd like in your cover letter - we do love a good story. 👍  📖