Product Security Engineer
Movable InkRole Overview
Movable Ink is hiring a entry-level Product Security Engineer. This is a full-time role in Movable Ink - Toronto. Part of Movable Ink's Risk hiring. The posted range is $133k to $173k. Full responsibilities, required qualifications, and the apply link are listed in the description below.
Resume Keywords to Include
Make sure these keywords appear in your resume to improve ATS scoring
Job Description
Movable Ink is hiring a Product Security Engineer to help secure our codebases, CI/CD pipelines, and development practices. To succeed in this role, you'll balance a security-first mindset with a practical understanding of how engineering teams ship software: finding ways to reduce risk without slowing down delivery. This is a hands-on opportunity to build and improve the automation that keeps our code and infrastructure safe, working closely with both the Security and Engineering teams. As AI coding tools and supply chain attacks increase risk across the industry, this role is critical to staying ahead of vulnerabilities before they reach production.
Responsibilities:
- Implement and maintain static application security testing (SAST) using Semgrep across our repositories
- Configure and improve software composition analysis (SCA) tooling (Dependabot) to identify vulnerable dependencies
- Manage secrets detection scanning (Trufflehog) and respond to findings
- Integrate security scanning into CI/CD pipelines (GitHub Actions) to catch issues before code is merged
- Triage and prioritize vulnerability findings, working with engineering teams to drive remediation
- Support dynamic application security testing (DAST) efforts using tools like ZAP
- Contribute to our Application Security Posture Management (ASPM) platform to centralize findings and track remediation
- Set up and configure automation scripts to support our vulnerability management practices
- Document secure coding guidelines and help educate developers on security best practices
- Evaluate and recommend new security tools as the landscape evolves
Qualifications:
- 2+ years of experience in application security, DevSecOps, or a security-focused software engineering role
- Hands-on experience with SAST, SCA, or secrets scanning tools (Semgrep, Dependabot, Snyk, or similar)
- Familiarity with CI/CD pipelines and GitHub Actions
- Understanding of common web application vulnerabilities (OWASP Top 10) and how to detect/prevent them
- Experience reading and reviewing code in at least one language (Ruby, Python, JavaScript, or Go preferred)
- Comfortable navigating codebases and working with engineering teams to explain and prioritize security findings
- Strong written communication skills for documentation and customer-facing security responses
- Self-motivated and able to manage competing priorities in a fast-paced environment
The base pay range for this position is $133,000-$173,000 CAD/year, which can include additional bonus depending on the position ultimately offered, in addition to a full range of medical, financial, and/or other benefits. The base pay offered may vary depending on job-related knowledge, skills, and experience.
Studies have shown that women, communities of color, and historically underrepresented people are less likely to apply to jobs unless they meet every single qualification. We are committed to building a diverse and inclusive culture where all Inkers can thrive. If you’re excited about the role but don’t meet all of the abovementioned qualifications, we encourage you to apply. Our differences bring a breadth of knowledge and perspectives that makes us collectively stronger.
We welcome and employ people regardless of race, color, gender identity or expression, religion, genetic information, parental or pregnancy status, national origin, sexual orientation, age, citizenship, marital status, ethnicity, family or marital status, physical and mental ability, political affiliation, disability, Veteran status, or other protected characteristics. We are proud to be an equal opportunity employer.
Frequently Asked Questions
How do I apply for the Product Security Engineer position at Movable Ink?
Use the Apply button above to submit your application directly to Movable Ink. Most applications take less than 5 minutes if your resume and contact details are ready, and you'll be routed to the employer's official application system to finish.
Where is the Product Security Engineer position at Movable Ink located?
This position is based in Movable Ink - Toronto. Movable Ink has not indicated remote or hybrid options for this role, so candidates should plan for on-site work.
How much does the Product Security Engineer role at Movable Ink pay?
Movable Ink has posted a compensation range of $133k to $173k for this position. Final offers typically vary based on candidate experience, location, and internal salary bands.
When was the Product Security Engineer role at Movable Ink posted?
This role was posted on April 29, 2026 (56 days ago). It's still listed as actively hiring; we re-confirm openings against the source system multiple times per day and remove closed roles.
Is the Product Security Engineer role at Movable Ink entry-level?
Yes. This is an entry-level position. Strong candidates typically have 0-2 years of relevant work experience, internships, or significant project work. Read the full description for any specific qualification requirements Movable Ink has listed.
AI-powered job search
Get every job scored to your resume
Upload your resume and get jobs ranked, your resume tailored, and employee contacts found automatically.
Get Started FreeNo credit card to start