Product & Offensive Security Lead
Join nesto — proudly named Canadian Rocketship 2025*. A Deloitte Fast 50 company evolving alongside Canada’s top tech innovators and disrupting a 2.1 Trillion-dollar mortgage industry at light speed by building the mortgage ecosystem of the future.
BUILD lending technology with the best developers, AI engineers, and mortgage experts in the country. Work on a modern tech stack and a development framework designed to unlock your full potential and accelerate your career.
Why join us
- Hypergrowth: Deloitte Fast 50 — 3 years in a row
- Tech community credibility: TechTO Canadian Rocketship 2025*
- Industry leadership: CLA Lending Company of the Year — 4 consecutive years
- Talent magnet: CMP Top Mortgage Employer 2025
- Trusted technology: powering major financial institutions across Canada
- An entrepreneurial culture built on trust, speed, uncomfortable ambition, being stronger together, and a relentless obsession with our clients.
About the role
nesto is looking for a hands-on Senior Lead Security Engineer to build and scale our offensive and product security practices from the ground up. Reporting directly to the Director of Security Engineering, you will serve as a player-coach—bringing offensive expertise in-house, embedding repeatable threat modeling into our engineering lifecycle, and mentoring a high-performing security team.
Whether you are acting as an attacker testing our defenses, a designer crafting threat models, or a builder automating security tooling, your work will directly protect the digital infrastructure modernizing Canada’s mortgage industry.
What You’ll Do
- Build Offensive Security Capabilities: Stand up nesto’s internal penetration testing, adversary emulation, and red-teaming functions for web apps, APIs, and cloud environments.
- Scale Threat Modeling: Establish and operationalize a risk-based threat modeling methodology (e.g., STRIDE, PASTA) across multi-functional development teams.
- Empower & Mentor: Act as a player-coach to guide and upskill security and software engineers, fostering a strong culture of security ownership.
- Enhance SecOps & Incident Response: Collaborate on cloud forensics, incident response, and continuous attack surface monitoring.
- Automate Security Integration: Build custom scripts and security tooling to embed security controls directly into our CI/CD pipelines (DevSecOps).
What You Bring
- Offensive Expertise: Deep hands-on experience in web, API, and cloud penetration testing/red-teaming at scale.
- Cloud Security Mastery: Multi-cloud depth in GCP and Azure, including IAM, container/Kubernetes security, and cloud logging.
- Leadership & Influence: Proven track record of scaling security practices and mentoring engineering teams.
- Incident Response & Automation: Strong background in cloud forensics and proficiency in scripting (Python, Go, or Bash) to build internal tooling.
- Methodology Driving: Demonstrated ability to roll out practical threat modeling frameworks across cross-functional product teams.
- Languages: Fluency in English is required; French capability is an asset.
Bonus Points For
- Experience with AI/LLM security (OWASP LLM Top 10, MITRE ATLAS) or AI-assisted reconnaissance/EASM.
- Active security research, CVE disclosures, or industry speaking engagements.
- Background in financial services, fintech, or highly regulated environments.
Diversity and Inclusion
At nesto, we believe that creativity and collaboration are the result of a diverse team. We are committed to fostering a culture of diversity, equity, inclusion, and belonging, and we strongly encourage women, people of color, LGBTQIA+ individuals, and individuals with disabilities to apply. We are committed to creating a workplace that is inclusive and welcoming to all.
#nestoposition
#nestocloud