Workstream
Workstream1mo ago
$150,000 – $180,000/yr

Information Security Engineer

CanadaVancouvermid
EngineeringSecurityInformation Security Engineer
0 views0 saves0 applied

Quick Summary

Requirements Summary

you believe security should enable innovation, not block it. Able to communicate risk clearly to engineers and non-technical st

Technical Tools
EngineeringSecurityInformation Security Engineer

Workstream is a mission-driven company building the all-in-one HR, payroll, and hiring platform for managing the hourly workforce. There are 2.7 billion hourly workers, making up 80% of the global workforce, but this market has been heavily underserved by technology and deserves better. Workstream has been purpose-built for the hourly workforce from day one so that these businesses and their employees can thrive.

Our customers include leading brands from multiple sectors, including Burger King, Carl's Jr./Hardee's, IHOP, KFC, and Culvers. We are a high growth series B company and quickly expanding our product portfolio to deliver on our vision. We are backed by legendary VCs and industry experts like Founders Fund, BOND, and Coatue.

We are hiring an Information Security Engineer to be the first dedicated security engineer at Workstream. This is a hands-on, builder-oriented role focused primarily on application and product security, with ownership of our security posture as the company scales.

This role is not about writing policies or running tools in isolation. You will work directly with our product and platform engineers to identify risks, fix vulnerabilities, and build secure-by-default patterns that allow teams to move fast without compromising safety.

This is a full-time, hybrid role requiring presence three days per week in our San Francisco or Menlo Park office.

Responsibilities

~1 min read
  • Work side-by-side with software engineers to locate, triage, and fix security issues directly in the codebase, including authorization flaws, multi-tenant isolation bugs, sensitive data exposure, and business logic vulnerabilities.
  • Review and provide security input on designs, APIs, and changes involving authentication, authorization, and sensitive employee data.
  • Threat-model critical (“Tier-1”) APIs and workflows and help teams design safer defaults.
  • Build practical guardrails and reference implementations that can be reused across teams.
  • Build practical guardrails and reference implementations that can be reused across teams.
  • Act as the primary Blue Team owner, coordinating external security testing and responsible disclosure.
  • Translate findings into concrete engineering work and drive remediation through to verification.
  • Help define and mature incident response processes and participate in real incidents when they occur.
  • Establish a clear baseline of Workstream’s security posture and propose a prioritized roadmap for improvement.
  • Own and maintain SOC 2 readiness, focusing on making renewals more predictable and less disruptive.
  • Partner with engineering and legal teams on privacy-related workflows, including data access and deletion.
  • Ensure compliance supports product development rather than slowing it down.
  • Own and maintain SOC 2 readiness, focusing on making renewals more predictable and less disruptive.
  • Partner with engineering and legal teams on privacy-related workflows, including data access and deletion.
  • Ensure compliance supports product development rather than slowing it down.

Requirements

~1 min read
  • Strong software engineering background with the ability to read and write production-level code.
  • Hands-on experience securing real systems, not just writing policies or reports.
  • Comfortable auditing Node.js and Ruby on Rails codebases.
  • Experience working in SaaS environments with enterprise customers and sensitive data.
  • A pragmatic, collaborative mindset: you believe security should enable innovation, not block it.
  • Able to communicate risk clearly to engineers and non-technical stakeholders.

Nice to Have

~1 min read
  • Experience owning security end-to-end at a startup or mid-stage company.
  • Exposure to bug bounty programs or external security testing.
  • Experience with SOC 2 or similar compliance frameworks.
  • Familiarity with securing multi-tenant SaaS platforms.
  • Be comfortable operating with broad ownership, ambiguity, and limited specialization.

What We Offer

~1 min read
A mission-driven company building software that impacts millions of hourly workers
An opportunity to shape security from the ground up at a growing Series B company
Competitive salary and equity
Comprehensive health coverage (95% employee / 85% dependents)
401(k), pre-tax commuter benefits, and flexible PTO
Learning and development stipend
In-office amenities and stocked kitchen

What We Offer

~1 min read
https://www.workstream.us/blog/funding-series-b
https://techcrunch.com/2021/08/26/workstreams-text-based-recruitment-tool-gets-a-48m-bet-from-bond-and-beyond/
https://techbuzz.news/buzzworthy-august-27-2021/

Listing Details

Posted
March 17, 2026
First seen
March 26, 2026
Last seen
April 20, 2026

Posting Health

Days active
25
Repost count
0
Trust Level
41%
Scored at
April 20, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Workstream
Workstream
greenhouse

Workstream is the top HR and Payroll platform designed for the hourly workforce, streamlining hiring and administrative processes for businesses.

Employees
350
Founded
2017
View company profile
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

WorkstreamInformation Security Engineer$150k–$180k