About this Principal Security Architect role at Menlo Security
Menlo Security is the leader in Browser Security for human and agentic workforces. Our mission is to enable humans and agents to connect, communicate, and collaborate securely, without compromise. The Menlo Browser Security Platform protects organizations from cyberattacks by stopping threats across the web, documents, and email before they reach the user. With Menlo Agent Runtime Security (MARS), that protection now extends to the AI agents working alongside every employee. Menlo Security is trusted by major global businesses, including Fortune 500 companies and government agencies, to protect their most valuable asset, their data, and is backed by top-tier investors.
Responsibilities
Security Design reviews, both broad product architecture and more minor changes. Includes integration/interaction with Cloud infrastructure (AWS).Security Code reviews.
Designing and documenting the process of integration and deployment of enterprise Hardware Security Module and Key Management.
Conducting assessments of third party software / SaaS offerings.
Conducting assessments of integration with third party software / SaaS, both design and actual implementation.
Overseeing internal and third party security assessments.
In-depth assessment of vulnerability impact, both third party vulnerabilities and product vulnerabilities.
Keeping abreast of and assessing product impact of upcoming technologies (e.g., new web standard or browser behavior changes).
Assisting compliance and sales teams on technical aspects of regulations / RFPs
Participating in in-depth technical conversations with customers around security topics.
Assisting with patent writing and review.
Creating and reviewing technical material meant for external consumption, both written (blogs, white papers...) and oral (presentations…).
Developing novel product features in the security space.
Requirements
Advanced knowledge of applied cryptography (e.g. HSMs, TPMs) and Key Management Life Cycle (e.g. Key Generation, Storage, Distribution, Backup, Rotation, Revocation, Destruction)
Deep knowledge of web and browser technologies: Same Origin Policy, XSS, CSRF, HTTP security headers, browser architecture, JavaScript engine internals.
Thorough understanding of network and OS fundamentals: TCP, HTTP, TLS, DNS, Firewalls, WAFs…; DAC/MAC, Sandboxing.
AWS security experience: IAM, Organizations, EC2, VPC...
Familiarity with static and dynamic analysis concepts and tools.
Advanced knowledge of C/C++, with focus on secure coding, and at least one other language (Python or JS preferred).
Willingness to get your hands dirty to get things done.
Minimum MSc/MEng or equivalent, PhD preferred.
Our Compensation and Benefits
At Menlo Security, Base Salary is one part of our competitive total compensation and benefits package and is determined using a salary range. The base salary range for this role is 158,000 CAD - 263,000 CAD.
In accordance with Canadian law, the range provided is Menlo Security’s reasonable estimate of the base compensation for this role. The actual amount may be higher or lower, based on non-discriminatory factors such as experience, knowledge, skills, abilities, and location. All employees may be eligible to become Menlo Security shareholders through eligibility for stock-based compensation grants, which are awarded to employees based on company and individual performance.
Menlo Security does not accept unsolicited resumes from search firm recruiters. Fees will not be paid in the event a candidate submitted by a recruiter without an agreement in place is hired; such resumes will be deemed the sole property of Menlo Security.
Menlo Security is an equal opportunity employer. All aspects of employment will be based on merit, competence, performance, and business needs. We do not discriminate on the basis of race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law.
MSGL-I4
Follow us on LinkedIn!
Why Menlo?
At Menlo, we don't settle for the status quo — in our technology or our culture. How we think and act is just as important as what we build. Our culture is defined by five core mindsets: Proactive Leadership, Straight Talk, United Impact, Elevated Talent, and Customer-Compelled. We take ownership and drive outcomes without waiting to be told. We communicate directly and seek hard truths. We break down silos and win together. We hold a high bar for ourselves and the people around us. And we treat every customer interaction as mission-critical. If you're someone who sees it, owns it, solves it, and does it — you'll thrive here.
All qualified applicants will receive consideration for employment without regard to race, sex, color, religion, sexual orientation, gender identity, national origin, protected veteran status, or on the basis of disability.
TO ALL AGENCIES: Please, no phone calls or emails to any employee of Menlo Security outside of the Talent organization. Menlo Security’s policy is to only accept resumes from agencies via Ashby (ATS). Agencies must have a valid services agreement executed and must have been assigned by the Talent team to a specific requisition. Any resume submitted outside of this process will be deemed the sole property of Menlo Security. In the event a candidate submitted outside of this policy is hired, no fee or payment will be paid.