Senior Security Engineer

🇨🇦 Canada - Remote
🔒 Cybersecurity🟣 Senior

Job description

Artificial Intelligence. Actual Impact.

At Docebo, AI isn’t just a buzzword — it’s how we help teams move faster, perform better, and focus on the work that actually matters. Our learning platform is built with smart, time-saving tools that personalize training, cut the busywork, and make learning feel like less of a chore (and more of a superpower).

We’re building the future of learning, and we’re doing it with a team that loves to challenge the status quo. If you’re excited by the idea of using AI to make work-life better for real people — not just in theory — you’re in the right place.

Still thinking it over? At Docebo, values aren’t just posters on the wall — they show up in how we work every day. We lead with what we call the Docebo Heart: we trust each other, assume positive intent, and make space for the differences that make our team stronger.

So… what are you waiting for? Join 900+ Docebians around the world and help us reinvent the way people learn.

About This Opportunity:

The Senior Security Engineer will play a major role in safeguarding Docebo’s infrastructure, data security, and integrity, particularly within cloud environments. Working closely with Cloud Infrastructure & Operations teams, IT, Developers, and other Security teams, the Security Engineer will design, implement, and maintain security measures and tools to protect systems and information. They will advocate for and support adopting best practices to safeguard company assets while ensuring an optimal user experience for our internal users. They will monitor and respond to threats against Docebo’s systems and users, leading the incident response process, driving improvements to incident handling, and leveraging automation and AI to enhance speed, accuracy, and resilience in security operations. They will also collaborate with the GRC team to meet regulatory and compliance requirements.

Reports to: Security Operations Manager

To help our teams work together effectively, this role requires you to be located in the Toronto area.

Responsibilities

  • Security Measures and Tools Management: guide and deliver the installation, configuration, and management of security tools for safeguarding systems and data. Continuously monitor and adjust security measures for optimal protection. Lead security initiatives to strengthen and enhance Docebo’s cybersecurity posture.
  • Cloud Security Solutions: collaborate with Cloud Infrastructure & Operations teams to design and maintain robust security solutions for cloud environments. Define the strategy and update solutions to address evolving threats. Define and oversee the optimal account structure following best practices.
  • Endpoint and Email Security Management: deploy and manage security measures on endpoints and email systems to prevent unauthorized access and threats. Implement policies to enhance email security and reduce email-borne risks.
  • Incident Response and Analysis: Coordinate and lead the investigation of security incidents to determine causes, impacts, and potential exposure of sensitive data (e.g. PII, credentials). Perform Root Cause Analysis (RCA) to prevent recurrence, leveraging automation, AI, and threat intelligence where possible; taking responsibility for following up with internal and external parties, including SOC/IR partners, to ensure effective closure of the incident.
  • Access Control and Identity Management: define and enforce Role-Based Access Control (RBAC) policies. Oversees and manages Identity and Access Management (IAM) solutions for secure authentication and authorization.
  • Vulnerability Management: identify and prioritize vulnerabilities in systems and applications. Oversee and deliver remediation efforts to address vulnerabilities promptly.
  • SIEM and Detection Engineering: Use SIEM tools to monitor and analyze security events and logs, leveraging detection engineering practices (rule development, testing, and tuning) to improve visibility. Enhance threat detection and response capabilities by aligning with industry frameworks such as MITRE ATT&CK.
  • Development of Security Best Practices: develop and document best practices, policies, and procedures for information security.  Provide guidance and training to promote a security-aware culture.
  • Monitoring of Security Configurations: audit and assess security configurations across the IT and Cloud infrastructure. Implement automated tools and processes for effective monitoring and enforcement of the appropriate level of security controls.
  • Develop and oversee effective strategies to prevent repeated risks affecting the infrastructure.
  • Vendor relationships: Maintain relationships with security vendors for technical issues, ensure smooth operations of security tools and services, and escalate problems or incidents to vendors when required.

Requirements

  • 5+ years of relevant work experience in cybersecurity, with strong exposure to incident response, SOC operations, or IR consulting.
  • Solid experience with cloud platforms (AWS preferred; Azure/GCP a plus) and familiarity with cloud security tools (e.g. CSPM, CWPP, CIEM, CNAPP).
  • Proven experience with incident lifecycle management, including investigation, containment, remediation, and post-incident analysis.
  • Experience with SIEM and EDR platforms, including threat hunting, log investigation, and detection engineering.
  • Familiarity with automation platforms and AI-driven security tools to streamline detection, enrichment, and response.
  • Strong ability to work with large volumes of security and application data, extracting and correlating events to assess impact on sensitive information (e.g. PII, credentials).
  • Experience with threat intelligence feeds, platforms, and enrichment tools, and the ability to operationalize threat intel to enhance monitoring and response.
  • Familiarity with identity and access management (IAM), endpoint protection, and modern security architectures.
  • Experience with Infrastructure as Code (IaC) and scripting (Python, Bash, PowerShell, etc.) to develop custom workflows.
  • In-depth knowledge of information security principles, best practices, and cybersecurity frameworks (MITRE ATT&CK, NIST CSF, CIS, SOC 2, ISO 27001, PCI, FedRAMP).
  • Experience in hardening operating systems (Linux preferred).
  • Hands-on experience with network security fundamentals and practices.
  • Ability to produce clear, comprehensive, and well-structured documentation (e.g. incident reports, playbooks, procedures, and technical findings) and to communicate complex technical issues effectively to non-technical stakeholders.

Benefits & Perks 😍

-Generous Vacation Policy, plus extra floating holidays to use for religious or cultural events that matter to you

-Employee Share Purchase Plan

-Career progression/internal mobility opportunities

-Four employee resource groups to get involved with (the Docebo Women’s Alliance, PRIDE, BIDOC, and Green Ambassadors)

-WeWork partnership and “Work from Anywhere” program

Hybrid Office Model 🏢

We believe when people are together, they develop deeper relationships and accelerate innovation. Because of this, all Docebo employees worldwide are “hybrid.” We encourage in-person collaboration while supporting work-from-home when employees need dedicated focus time, allowing Docebians to do their best every day. Each team leader is able to decide how often their teams come into the office, considering the needs of the team and the employee’s needs. Our Talent Acquisition team will let you know about the role you are applying for and the hybrid details during the first interview.

About Docebo 💙

Here at Docebo, we power learning experiences for over 3000 customers around the world with our easy-to-use, AI-powered Suite designed to close the enterprise learning loop. We have successfully achieved 2 IPOs (TSX: DCBO & NASDAQ: DCBO), been recognized as a Top SaaS e-learning Solution, and are growing exponentially in the process.

Docebo is a global company with offices in North America, EMEA, APAC and more. Our people believe in six core values, simply defined and manifested in everything we do - Innovation, Simplicity, Accountability, Togetherness, Curiosity, and Impact. If this sounds like you, now is your time to join one of the fastest-growing learning technology companies on the market. Apply today!

Docebo is an Equal Employment Opportunity employer. We are committed to diversity and inclusion in our workforce. All qualified applicants and employees will receive consideration for employment regardless of their race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, citizenship status, age, disability, genetic information, or any other category protected under applicable law.

Any individuals requiring a reasonable accommodation to assist with their job search or application for employment should send an e-mail to recruiting_accommodations

(at) docebo.com. The e-mail should include a description of the requested accommodation and the position you’re applying for or interested in.

Share this job:
Please let Docebo know you found this job on Remote First Jobs 🙏

Benefits of using Remote First Jobs

Discover Hidden Jobs

Unique jobs you won't find on other job boards.

Advanced Filters

Filter by category, benefits, seniority, and more.

Priority Job Alerts

Get timely alerts for new job openings every day.

Manage Your Job Hunt

Save jobs you like and keep a simple list of your applications.

Search remote, work from home, 100% online jobs

We help you connect with top remote-first companies.

Search jobs

Hiring remote talent? Post a job

Frequently Asked Questions

What makes Remote First Jobs different from other job boards?

Unlike other job boards that only show jobs from companies that pay to post, we actively scan over 20,000 companies to find remote positions. This means you get access to thousands more jobs, including ones from companies that don't typically post on traditional job boards. Our platform is dedicated to fully remote positions, focusing on companies that have adopted remote work as their standard practice.

How often are new jobs added?

New jobs are constantly being added as our system checks company websites every day. We process thousands of jobs daily to ensure you have access to the most up-to-date remote job listings. Our algorithms scan over 20,000 different sources daily, adding jobs to the board the moment they appear.

Can I trust the job listings on Remote First Jobs?

Yes! We verify all job listings and companies to ensure they're legitimate. Our system automatically filters out spam, junk, and fake jobs to ensure you only see real remote opportunities.

Can I suggest companies to be added to your search?

Yes! We're always looking to expand our listings and appreciate suggestions from our community. If you know of companies offering remote positions that should be included in our search, please let us know. We actively work to increase our coverage of remote job opportunities.

How do I apply for jobs?

When you find a job you're interested in, simply click the 'Apply Now' button on the job listing. This will take you directly to the company's application page. We kindly ask you to mention that you found the position through Remote First Jobs when applying, as it helps us grow and improve our service 🙏

Apply