[All remote jobs](https://jobicy.com/jobs.md)Open role[![League logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/09/1252bb2582abaece8d30e08e4a386bd2.png)](https://jobicy.com/company/league.md)Remote opportunity at[League](https://jobicy.com/company/league.md)

# Principal Security Engineer

Review the role, location requirements, compensation details, and application process before deciding whether this opportunity fits your next career move.

[Apply for this job](#job-application)[View company](https://jobicy.com/company/league.md)Share25 Aug 2026Published24Listing views2Application actions24 Sep 2026Apply before  Opportunity details

## About this role.

AI SummaryLeague seeks a Principal Security Engineer to set security architecture and technical direction for complex, AI-native healthcare-platform systems. The role focuses on encryption and key management, IAM, cloud and application security, secure AI and agentic architectures, and security automation direction. This senior individual contributor will partner closely with Product Security, Security Operations, product, and engineering teams while mentoring security specialists. The position requires at least eight years of security-engineering experience, hands-on security experience with LLM-integrated systems, and familiarity with regulated frameworks such as HIPAA, HITRUST, SOC 2, or PIPEDA.

## Role DNA

A quick view of the complexity, pace, ownership and collaboration implied by the job description.

### Job Complexity

5/5EasyHard

### Pace & Pressure

4/5RelaxedFast-paced

### Autonomy Level

5/5GuidedFull ownership

### Communication Load

5/5IndependentCollaborative

AI insightThis is a principal-level architecture role requiring deep expertise across multiple security domains and direct experience securing AI-integrated systems. Success depends on influencing technical decisions across teams without formal authority while operating in a highly regulated healthcare environment.

## Salary analysis

Estimated compensation compared with the broader CA market for similar roles.

Estimated job medianHighly competitiveC$250,000CA market rangeC$190k–C$260k0C$286k

AI insightThe disclosed Canada-only base-salary range is CAD 220,000 to CAD 280,000 yearly, producing an offer median of CAD 250,000. The US market range is estimated at USD 190,000 to USD 260,000 annually for a principal security engineer with AI security and regulated-healthcare expertise; actual US compensation may vary by location, base-versus-total-compensation structure, and scope.

## Core skills

Skills and capabilities most closely associated with this opportunity.

[Security architecture](https://jobicy.com/jobs?search_keywords=Security%20architecture.md)[AI security](https://jobicy.com/jobs?search_keywords=AI%20security.md)[LLM applications](https://jobicy.com/jobs?search_keywords=LLM%20applications.md)[Agentic systems](https://jobicy.com/jobs?search_keywords=Agentic%20systems.md)[Encryption](https://jobicy.com/jobs?search_keywords=Encryption.md)[Key management](https://jobicy.com/jobs?search_keywords=Key%20management.md)[Identity and access management](https://jobicy.com/jobs?search_keywords=Identity%20and%20access%20management.md)[Cloud security](https://jobicy.com/jobs?search_keywords=Cloud%20security.md)[Application security](https://jobicy.com/jobs?search_keywords=Application%20security.md)[HIPAA and HITRUST compliance](https://jobicy.com/jobs?search_keywords=HIPAA%20and%20HITRUST%20compliance.md)

Sample interview questionsHow would you develop a security architecture for an AI-agent workflow that can access sensitive healthcare data and invoke external tools?I would begin with data-flow mapping, asset classification, and a threat model covering prompt injection, tool abuse, identity impersonation, data leakage, and unsafe output handling. I would enforce strong workload identity, least-privilege and scoped tool permissions, isolated execution environments, policy enforcement at tool boundaries, encryption, audit logging, and human approval for high-impact actions. I would also define security tests and continuous monitoring so controls remain effective as models, prompts, and integrations change.

Describe how you have influenced secure design decisions without directly managing the engineering teams involved.

I establish trust by joining design discussions early, framing concerns in terms of customer impact and engineering trade-offs, and offering implementable patterns rather than only identifying problems. I use risk-based prioritization, reference architectures, and measurable outcomes to make the secure path easier to adopt. When exceptions are needed, I ensure ownership, compensating controls, and a clear remediation timeline are documented.

What approach would you take to improve key management and encryption across a growing cloud platform?

I would inventory data stores, secrets, keys, trust boundaries, and current cryptographic dependencies, then define a target architecture with centralized key-management controls, envelope encryption where appropriate, rotation standards, separation of duties, and tightly governed access. I would prioritize systems holding regulated data and high-impact secrets, automate evidence collection, and establish migration plans that minimize service disruption. Regular reviews would validate key usage, rotation, logging, and recovery procedures.

How do you translate HIPAA, HITRUST, SOC 2, or PIPEDA requirements into engineering practice?

I translate requirements into concrete, testable controls embedded in engineering workflows, such as access-control standards, secure SDLC gates, logging requirements, data-retention rules, and incident-response procedures. I partner with compliance and engineering to assign accountable owners and collect automated evidence wherever possible. This makes compliance a repeatable engineering capability rather than a periodic audit exercise.

How would you prioritize security investments when Product Security, Security Operations, and platform engineering all have competing needs?

I would use a shared risk model that considers likelihood, impact, regulatory exposure, exploitability, customer commitments, and dependency reach. I would distinguish urgent remediation from strategic architectural work, then create a roadmap with measurable risk reduction and clear ownership across functions. Transparent communication of trade-offs and progress helps leadership make informed investment decisions.

About League

League is one of the fastest-growing technology companies in Canada and the leading healthcare experience platform. Getting healthcare is often the easy part — finishing it is where things fall apart: people book the appointment and skip the follow-up, fill the prescription and stop taking it, get the referral and never make the call. That gap costs health plans and health systems money, and it costs people their health. League closes that gap — identifying what each person needs to do next, clearing what’s in their way, and getting it done, for the 70 million+ people whose care already runs through our platform. Health plans and health systems trust us to do this at scale. Organizations like Manulife, SCAN, Geisinger, and Medibank on the payer side, and Baptist and Shoppers Drug Mart on the provider side.

Position Summary:

League is looking for a Principal Security Engineer to serve as the senior technical leader within our Security Engineering organization. This role entails designing and driving security architecture across a rapidly AI-native engineering environment, in close partnership with Product Security and Security Operations.

Product Security owns day-to-day security reviews and vulnerability management; Security Operations owns detection and response. This role sets technical direction and design for the organization’s most complex and novel systems, including AI/agentic architectures, and serves as the connective tissue that makes the broader security function more effective.

The right person for this role doesn’t wait for a ticket. They show up in design conversations, ask the right question at the right moment, and leave engineering and security colleagues alike more capable than they found them – all while being a strategic cross-functional partner that people enjoy collaborating with.

What you’ll be doing:

* Design and implement security architecture and controls across encryption/key management, IAM, and core infrastructure
* Set technical direction and design for the organization’s most complex and novel systems – including AI/agentic architectures, major platform changes, and novel integrations
* Partner proactively with engineering and product teams on secure-by-default design, embedding security capability directly into their workflows
* Provide technical mentorship to Security Software Engineering and to individuals within Product Security and Security Operations, raising technical capability across the broader security function
* Serve as senior technical escalation point and design advisor to Product Security and Security Operations on complex technical questions, without owning execution of their programs
* Set direction and design for security automation initiatives, partnering with Security Software Engineering, who owns implementation and build
* Translate technical risk into business terms for leadership, customers, and compliance stakeholders

What you’ll bring to the team:

* 8+ years in security engineering, with demonstrated depth in at least two of: encryption/key management, IAM, cloud security architecture, application security
* Direct, hands-on experience securing AI-integrated systems including LLM applications, coding agents, or MCP-style tool integrations; not just familiarity with the concepts
* Experience operating in a regulated environment (HIPAA, HITRUST, SOC 2, PIPEDA, or equivalent), including translating compliance requirements into engineering practice
* Experience collaborating within a broader security organization (partnering with product/application security and security operations functions) rather than as a sole practitioner owning every function end-to-end
* Able to strategically influence across peer functions and ensure alignment to overall Security objectives
* Track record of influencing engineering decisions and behaviour without formal authority over the teams involved

CANADA APPLICANTS ONLY: The Canada-specific compensation range below for this full-time position is exclusive of bonus, equity and benefits. This range reflects the minimum and maximum target for base salaries for the position across all Canadian locations. The salary range is intentional to account for the performance and career progressions a Leaguer will experience in the role throughout their time at League. Where in the band you may land is determined by job-related skills/experience. Your recruiter can share more about the specific salary range specific to your skills and experience during the hiring process.

Compensation range for Canada applicants only

$220,000—$280,000 CAD

AI Fluency & Ways of Working

At League, we are an AI-native organization. We expect all employees regardless of role or level to thoughtfully leverage AI to improve the quality, speed, and impact of their work.

What this means in practice:

* Use AI tools as part of your daily workflow to enhance productivity, problem-solving, and decision-making (e.g., drafting, analysis, coding, research, or process automation)
* Apply judgment and accountability when using AI by reviewing outputs for accuracy, bias, and quality before use
* Continuously learn and adapt as new AI tools and capabilities emerge, incorporating them into your ways of working
* Identify opportunities to improve how work gets done from personal productivity to team-level workflows by leveraging AI effectively
* Operate with strong data responsibility and security awareness, especially when working with sensitive or regulated information

How this scales by level:

* Individual Contributors: Use AI to improve personal productivity and quality of output
* Senior ICs / Managers: Integrate AI into team workflows and improve processes
* Leaders: Drive AI adoption at the organizational level and shape how work is done across teams

What we look for:

* Demonstrated experience using AI tools in a practical, responsible way
* Curiosity and openness to experimenting with new technologies
* Ability to balance efficiency with quality and sound judgment

Our employees come from different backgrounds, and we celebrate those differences. We are looking for the best candidates for our open roles, but do not expect applicants to meet every qualification in order to be considered. If you are excited about what you could accomplish at League and believe you can add value to our team, we would love to hear from you.

We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. If you are an individual in need of assistance at any time during our recruitment process, please contact us at [recruitinginfo@league.com](mailto:recruitinginfo@league.com).

Our Application Process:

Applying to a role you love can be exhausting, and understanding the next steps can feel vague and uncertain. You have done the hard part of submitting your application; let’s do ours by sharing potential next steps

* You should receive a confirmation email after submitting your application.
* A recruiter (not a computer) reviews all applications at League.
* If we see alignment with League’s needs, a recruiter will reach out to learn more about your goals. The recruiter will also share the team-specific interview process depending on the roles you are exploring.
* The final step is an offer, which we hope you will accept!
* Prior to joining us, we conduct reference and background checks. Additional checks could be required for US Candidates, depending on the role you are exploring.

Here are some additional resources to learn more about League:

* [Learn about our platform, leadership team and partners](https://league.com/about/?utm_medium=job+posting)
* [Highmark Health, Google Cloud, League: new digital front door to seamless care](https://league.com/newsroom/highmark-google-cloud-digital-front-door-health-experience/?utm_medium=job+posting)
* [Former Providence President and Workday EVP of Corporate Strategy join League Board of Directors](https://league.com/newsroom/michael-butler-leighanne-levensaler-join-board-of-directors/?utm_medium=job+posting)
* [League raises $95 million USD in Series C to build world’s leading healthcare CX platform](https://league.com/newsroom/league-raises-95-million-to-build-worlds-leading-health-os-platform/?utm_medium=job+posting)
* [Forbes x League: The Platformization Of Healthcare Is Here](https://www.forbes.com/sites/forbestechcouncil/2022/06/08/the-platformization-of-healthcare-is-here/?sh=6790a07f145a)
* [Fast Company x League: If we want better innovations in healthtech, we need more competition](https://www.fastcompany.com/90795794/if-we-want-better-innovations-in-healthtech-we-need-more-competition)

Work Location:

We have a mix of office-centric roles based in our vibrant Toronto office, and remote-eligible roles based anywhere in Canada or US. Each job posting will indicate where the role will be based. Regardless of the role’s posted location, all Toronto-area Leaguers (living within 65 km of our downtown HQ) collaborate in-office Monday through Thursday. Depending on your distance to the office, you’ll enjoy 10 or 20 Flexible Remote Days each quarter for focus and deep-work time. We are committed to fostering a meaningful work environment and connections for all Leaguers regardless of location.

Recognize and Avoid Employment scams. Practice safe job searching.

Scammers are getting craftier and leveraging fake job postings to get personal information. Know the warning signs and protect yourself from scammers. Learn more [here](https://go.league.com/phishing-guidelines).

Use of AI Notice
We are committed to ensuring fairness and transparency throughout our hiring process. League may use Artificial Intelligence (AI) tools to assist in the screening of applicants for this position. Please check out our stance on using AI in recruitment [here](https://league.com/ai-policy-hiring/).

Privacy Policy

Review our [Privacy Policy](https://league.com/applicant-privacy-notice/) for information on how League is protecting personal data.

Show more

[Apply now >](https://jobicy.com/jobs/151600-principal-security-engineer.md)

*

![Upload CV](data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHdpZHRoPSI2NSIgaGVpZ2h0PSI2NSIgZmlsbD0ibm9uZSIgeG1sbnM6dj0iaHR0cHM6Ly92ZWN0YS5pby9uYW5vIj48ZyBjbGlwLXBhdGg9InVybCgjQSkiPjxwYXRoIGQ9Ik0wIDBINjVWNjVIMFYwWiIgZmlsbD0iIzAyOWFlYiIvPjxnIGZpbGw9IiNmZmYiIHN0cm9rZT0iI2ZmZiIgc3Ryb2tlLXdpZHRoPSIyIj48cGF0aCBkPSJNMzMuMDQ5IDE1LjQ1NGExLjQzIDEuNDMgMCAwIDAtMi4wOTcgMGwtNy41NzkgOC4xNDdhMS4zOCAxLjM4IDAgMCAwIC4wOSAxLjk3MyAxLjQ0IDEuNDQgMCAwIDAgMi4wMDgtLjA4OGw1LjEwOS01LjQ5MnYyMC42MWExLjQxIDEuNDEgMCAwIDAgMS40MjEgMS4zOTdjLjc4NSAwIDEuNDIxLS42MjUgMS40MjEtMS4zOTd2LTIwLjYxbDUuMTA5IDUuNDkyYTEuNDQgMS40NCAwIDAgMCAyLjAwOC4wODggMS4zOCAxLjM4IDAgMCAwIC4wOS0xLjk3M2wtNy41NzktOC4xNDZ6TTE2Ljc2OSAzOC40YzAtLjc3My0uNjItMS40LTEuMzg1LTEuNFMxNCAzNy42MjcgMTQgMzguNHYuMTAybC4yMTUgNi4yMjljLjIyMyAxLjY4LjcwMSAzLjA5NSAxLjgxMyA0LjIxOHMyLjUxIDEuNjA3IDQuMTcyIDEuODMzYzEuNi4yMTggMy42MzYuMjE4IDYuMTYuMjE4aDExLjI4bDYuMTYtLjIxOGMxLjY2Mi0uMjI2IDMuMDYxLS43MDkgNC4xNzItMS44MzNzMS41ODktMi41MzggMS44MTMtNC4yMThDNTAgNDMuMTEzIDUwIDQxLjA1NSA1MCAzOC41MDNWMzguNGMwLS43NzMtLjYyLTEuNC0xLjM4NS0xLjRzLTEuMzg1LjYyNy0xLjM4NSAxLjRsLS4xOSA1Ljk1OGMtLjE4MiAxLjM3LS41MTUgMi4wOTUtMS4wMjYgMi42MTJzLTEuMjI4Ljg1My0yLjU4MyAxLjAzOGMtMS4zOTUuMTktMy4yNDMuMTkzLTUuODkzLjE5M0gyNi40NjJjLTIuNjUgMC00LjQ5OC0uMDAzLTUuODkzLS4xOTMtMS4zNTUtLjE4NC0yLjA3Mi0uNTIxLTIuNTgzLTEuMDM4cy0uODQ0LTEuMjQyLTEuMDI2LTIuNjEyYy0uMTg3LTEuNDEtLjE5MS0zLjI3OS0uMTkxLTUuOTU4eiIvPjwvZz48L2c+PGRlZnM+PGNsaXBQYXRoIGlkPSJBIj48cGF0aCBmaWxsPSIjZmZmIiBkPSJNMCAwaDY1djY1SDB6Ii8+PC9jbGlwUGF0aD48L2RlZnM+PC9zdmc+)

### Upload your resume now

To unlock remote work opportunities and be discovered by global employers.

This job listing has been manually reviewed by the Jobicy Trust & Safety Team for compliance with our posting guidelines, including verification of the company's legitimacy, accuracy of job details, clarity of remote work policy, and absence of misleading or fraudulent content.

Next step

## Apply now.

Follow the employer’s application method and review Jobicy’s safety guidance before sharing personal information.

Keep exploring

## Related remote jobs.

Matched by job category10 related opportunities[Cybersecurity](https://jobicy.com/categories/cybersecurity.md) [Browse all jobs](https://jobicy.com/jobs.md)
*
![Docplanner logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/84f2fa86-221.png)
Docplanner  Aug 24

### [Senior Platform Security Engineer (100% Remote within Poland)](https://jobicy.com/jobs/151521-senior-platform-security-engineer-100-remote-within-poland.md)

Welcome to the good side of tech 👋 You might have heard about us, but with a different name: Znany Lekarz. It all started 12 years ago when we asked…

*
![Docplanner logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/08/84f2fa86-221.png)
Docplanner  Aug 24

### [Senior Platform Security Engineer (100% Remote within Spain)](https://jobicy.com/jobs/151520-senior-platform-security-engineer-100-remote-within-spain.md)

Welcome to the good side of tech 👋 You might have heard about us, but with a different name: Doctoralia. It all started 12 years ago when we asked ourselves:…

*
![Qventus logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2022/01/0ad7e933ffa7b62281cc4b26710abfab.jpeg)
Qventus  Aug 24

### [Senior Security Engineer](https://jobicy.com/jobs/151504-senior-security-engineer-2.md)

On this journey for over 12 years, Qventus is leading the transformation of healthcare. We enable hospitals to focus on what matters most: patient care. Our innovative solutions harness the…

*
![CertiK logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2021/03/Jobicy-210308091023-955845.jpg)
CertiK  Aug 24

### [Blockchain Security Engineer – (Solidity / Rust / Golang)](https://jobicy.com/jobs/151470-blockchain-security-engineer-solidity-rust-golang.md)

About the Company CertiK is the largest blockchain security auditor and provides a comprehensive suite of tools to secure the industry at scale. To date, CertiK has worked with over…

*
![Sporty Group logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/8e6c246a-221.png)
Sporty Group  Aug 24

### [Security Platform Engineer](https://jobicy.com/jobs/151442-security-platform-engineer.md)

About the roleStrengthen Sporty’s security monitoring and detection capability by managing, tuning, and continuously improving EDR and SIEM platforms. Ensure security alerts are accurate, actionable, and provide reliable visibility across…

*
![Lakeshore Learning Materials, LLC logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/d8ba23f6-221.jpg)
Lakeshore Learning Materials, LLC  Aug 23

### [Manager of IT Security](https://jobicy.com/jobs/149591-manager-of-it-security.md)

Company DescriptionAt Lakeshore, we create innovative learning materials and world-class guest experiences for teachers, parents and children. Since 1954, we’ve grown into a global community—with a thriving e-commerce business, multiple…

*
![Tenable logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/01879e02-221.jpg)
Tenable  Aug 22

### [Senior Director, Ecosystem & Solution Architectures – Technical Alliances](https://jobicy.com/jobs/151413-senior-director-ecosystem-solution-architectures-technical-alliances.md)

Who is Tenable? Tenable® is the Exposure Management company. Over 40,000 organizations around the globe rely on Tenable to understand and reduce cyber risk. Our global employees support 65 percent…

*
![Canonical logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)
Canonical  Aug 22

### [Security Risk Management Specialist](https://jobicy.com/jobs/149564-security-risk-management-specialist.md)

In security risk management we’re looking to harness the power of industry best practice combined with driving new innovation on how we do security risk assessments and modelling. Our security…

*
![Canonical logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)
Canonical  Aug 22

### [Ubuntu Security Engineer](https://jobicy.com/jobs/149565-ubuntu-security-engineer.md)

Canonical is a leading provider of open source software and operating systems to the global enterprise and technology markets. Our platform, Ubuntu, is very widely used in breakthrough enterprise initiatives…

*
![Canonical logo](https://jobicy.com/data/server-nyc0409/galaxy/mercury/2025/06/b4d068a9-221-1.png)
Canonical  Aug 22

### [Senior Security Operations Engineer](https://jobicy.com/jobs/149578-senior-security-operations-engineer.md)

The Canonical Security Operations team is hiring for a Senior or Staff engineer. The Security Operations team is responsible for designing, building, and operating a world-class Security Operations Center, and…