Principal Security Engineer in Canada and USA
League, a leading healthcare experience platform serving over 70 million people, is hiring a senior-level Principal Security Engineer for a healthcare technology role available in Canada and the USA. This full-time position offers a salary of $220,000, with a Canada-specific compensation range detailed in the application materials. The organization works with major payers and providers such as Manulife, SCAN, Geisinger, Medibank, Baptist, and Shoppers Drug Mart.
Role Overview and Responsibilities
As the senior technical leader within League's Security Engineering organization, you will design and drive security architecture across an AI-native engineering environment. You will work alongside Product Security and Security Operations to shape the technical direction of complex systems, including AI and agentic architectures.
- Design and implement security architecture and controls for IAM, core infrastructure, and encryption or key management.
- Set technical direction for novel integrations, major platform changes, and AI/agentic architectures.
- Partner proactively with product and engineering teams to embed secure-by-default capabilities into workflows.
- Provide technical mentorship to Security Software Engineering, Product Security, and Security Operations personnel.
- Serve as a senior technical escalation point and design advisor for complex technical questions.
- Set direction for security automation initiatives while partnering with Security Software Engineering on implementation.
- Translate technical risk into business terms for customers, leadership, and compliance stakeholders.
Requirements and Qualifications
Applicants must hold a Bachelor's degree and meet the following experience criteria:
- 8+ years of experience in security engineering, with demonstrated depth in at least two areas: IAM, cloud security architecture, application security, or encryption/key management.
- Direct, hands-on experience securing AI-integrated systems, such as coding agents, LLM applications, or MCP-style tool integrations.
- Experience operating in regulated environments like HIPAA, SOC 2, HITRUST, or PIPEDA, translating compliance needs into engineering practices.
- Background collaborating within a broader security organization alongside product security and security operations teams.
- Demonstrated ability to strategically influence peer functions and guide engineering decisions without formal authority.