Engineering Manager, Security

EvenUp EvenUp · Vertical AI · Toronto, ON · Hybrid · Engineering

Engineering Manager for Security at EvenUp, a rapidly growing vertical SaaS company focused on AI for personal injury law. This hybrid role involves leading security and IT teams, defining security strategy, managing compliance (SOC 2, HIPAA), embedding security into the SDLC, overseeing corporate IT and cloud security, managing vendor risk, and leading incident response. The role requires a hands-on builder mentality with strong people leadership and technical depth across cloud security, IAM, and secure SDLC practices.

What you'd actually do

  1. Define EvenUp's security roadmap and lead a growing Security & IT team. Serve as the internal authority on risk and security posture, advising engineering, legal, and the executive team. Hire and develop talent as the function scales.
  2. Own our SOC 2 Type II and HIPAA programs end-to-end: gap assessments, control design, audit readiness, and ongoing compliance. Maintain policies and procedures, manage auditor relationships, and stay ahead of evolving regulatory requirements.
  3. Partner with Engineering to embed security into the SDLC through threat modeling, secure design reviews, and vulnerability management (SAST, DAST, pen testing). Champion a shift-left, security-by-design culture across the product org.
  4. Own corporate IT systems (MDM, SSO/IdP, endpoint security, IAM) and cloud security posture. Evaluate and deploy security tooling. Enforce least-privilege and zero-trust principles across the organization.
  5. Lead the vendor risk program, including security assessments, contract reviews (BAAs, DPAs), and ongoing monitoring of third-party risk exposure.

Skills

Required

  • Security leadership
  • Security strategy
  • Team leadership
  • Compliance (SOC 2, HIPAA)
  • Product security
  • SDLC security integration
  • Cloud security (AWS/GCP/Azure)
  • IAM
  • Endpoint security
  • Vulnerability management
  • Threat modeling
  • Vendor risk management
  • Incident response
  • Risk management
  • People management
  • Hiring and talent development

Nice to have

  • Familiarity with emerging requirements (state privacy laws, AI governance)

What the JD emphasized

  • built or scaled a security function before
  • hands-on ownership of SOC 2 Type II and HIPAA programs
  • strong working knowledge of cloud security (AWS/GCP/Azure), IAM, endpoint security, and secure SDLC practices
  • experience with vulnerability management, threat modeling, and integrating security into fast-moving engineering teams
  • track record of managing and growing small technical teams
  • experience running a vendor risk program
  • equally comfortable writing a policy, configuring a SIEM, presenting to the exec team, and jumping into an incident at 10 pm