Product & Offensive Security Lead

nesto· Technologie - Technology
Apply Now ↗
📍 CanadaFULL TIME

About this role


Join nesto — proudly named Canadian Rocketship 2025*. A Deloitte Fast 50 company evolving alongside Canada’s top tech innovators and disrupting a 2.1 Trillion-dollar mortgage industry at light speed by building the mortgage ecosystem of the future.


BUILD lending technology with the best developers, AI engineers, and mortgage experts in the country. Work on a modern tech stack and a development framework designed to unlock your full potential and accelerate your career.

Why join us

  • Hypergrowth: Deloitte Fast 50 — 3 years in a row
  • Tech community credibility: TechTO Canadian Rocketship 2025*
  • Industry leadership: CLA Lending Company of the Year — 4 consecutive years
  • Talent magnet: CMP Top Mortgage Employer 2025
  • Trusted technology: powering major financial institutions across Canada
  • An entrepreneurial culture built on trust, speed, uncomfortable ambition, being stronger together, and a relentless obsession with our clients.


About the role 


nesto is looking for a hands-on Senior Lead Security Engineer to build and scale our offensive and product security practices from the ground up. Reporting directly to the Director of Security Engineering, you will serve as a player-coach—bringing offensive expertise in-house, embedding repeatable threat modeling into our engineering lifecycle, and mentoring a high-performing security team.

Whether you are acting as an attacker testing our defenses, a designer crafting threat models, or a builder automating security tooling, your work will directly protect the digital infrastructure modernizing Canada’s mortgage industry.


What You’ll Do


  • Build Offensive Security Capabilities: Stand up nesto’s internal penetration testing, adversary emulation, and red-teaming functions for web apps, APIs, and cloud environments.
  • Scale Threat Modeling: Establish and operationalize a risk-based threat modeling methodology (e.g., STRIDE, PASTA) across multi-functional development teams.
  • Empower & Mentor: Act as a player-coach to guide and upskill security and software engineers, fostering a strong culture of security ownership.
  • Enhance SecOps & Incident Response: Collaborate on cloud forensics, incident response, and continuous attack surface monitoring.
  • Automate Security Integration: Build custom scripts and security tooling to embed security controls directly into our CI/CD pipelines (DevSecOps).


What You Bring


  • Offensive Expertise: Deep hands-on experience in web, API, and cloud penetration testing/red-teaming at scale.
  • Cloud Security Mastery: Multi-cloud depth in GCP and Azure, including IAM, container/Kubernetes security, and cloud logging.
  • Leadership & Influence: Proven track record of scaling security practices and mentoring engineering teams.
  • Incident Response & Automation: Strong background in cloud forensics and proficiency in scripting (Python, Go, or Bash) to build internal tooling.
  • Methodology Driving: Demonstrated ability to roll out practical threat modeling frameworks across cross-functional product teams.
  • Languages: Fluency in English is required; French capability is an asset.


Bonus Points For


  • Experience with AI/LLM security (OWASP LLM Top 10, MITRE ATLAS) or AI-assisted reconnaissance/EASM.
  • Active security research, CVE disclosures, or industry speaking engagements.
  • Background in financial services, fintech, or highly regulated environments.

Diversity and Inclusion


At nesto, we believe that creativity and collaboration are the result of a diverse team. We are committed to fostering a culture of diversity, equity, inclusion, and belonging, and we strongly encourage women, people of color, LGBTQIA+ individuals, and individuals with disabilities to apply. We are committed to creating a workplace that is inclusive and welcoming to all.


#nestoposition

#nestocloud


Frequently Asked Questions

Is the salary disclosed for the Product & Offensive Security Lead position at nesto?
The salary for this Product & Offensive Security Lead role at nesto is not publicly listed. Click "Apply Now" to learn more about the compensation package on their official careers page.
Where is the Product & Offensive Security Lead position at nesto located?
This Product & Offensive Security Lead role at nesto is based in Canada. The position is listed as on-site or hybrid. Check the full job description or apply directly to confirm the work arrangement.
Is the Product & Offensive Security Lead role at nesto full-time or part-time?
This is listed as a FULL TIME position. It is posted as a Product & Offensive Security Lead role in the Technologie - Technology department at nesto.
Which team or department does the Product & Offensive Security Lead at nesto belong to?
This Product & Offensive Security Lead position is part of the Technologie - Technology department at nesto. See the full job description for more information about the team structure and responsibilities.
How do I apply for the Product & Offensive Security Lead position at nesto?
Click the "Apply Now" button on this page. You will be redirected to nesto's official application portal hosted on rippling where you can submit your application directly.
When was the Product & Offensive Security Lead job at nesto posted?
This Product & Offensive Security Lead position at nesto was posted on Aug 24, 2026. Apply as soon as possible — early applications are often reviewed first.
Product & Offensive Security Lead
nesto
Apply for this role ↗

You'll be redirected to nesto's official application page on rippling.