Principal Offensive Security
Varicent · Toronto, Canada · On-site
Pay: CAD 138,200 – 200,000 a year
Posted Oct 7, 2026
Sign up free: we match you to jobs like this, tailor your application and fill the form. 2 free applications every day.
At Varicent, we’re not just transforming the Sales Performance Management (SPM) market—we’re redefining how organizations achieve revenue success. Our cutting-edge SaaS solutions empower revenue leaders globally to design smarter go-to-market strategies, maximize seller performance, and unlock untapped potential. Varicent stands at the forefront of innovation, celebrated as a market leader in the 2025 Forrester Wave Report for SPM , 2023 Ventana Research Revenue Performance Management (RPM) Value Index , Gartner Peer Insights , 2024 Gartner SPM Market Guide , and G2. Our solutions are trusted by a diverse range of global industry leaders like T-Mobile, ServiceNow, Wawanesa Bank, Shaw Industries, Moody's, Stryker and hundreds more. Here’s why you’ll thrive at Varicent:
Innovate with Purpose: Build impactful solutions for customers worldwide.
Join Excellence: Work in a diverse, collaborative, and innovative team.
Shape the Future: Lead in redefining revenue optimization.
Grow Together: Unlock your potential in a supportive environment.
Join us at Varicent—where your talent and ambition meet limitless opportunities for success!
We're looking for a Principal Offensive Security engineer to be the senior technical authority for our offensive security practice across applications, cloud environments, enterprise systems, and AI-enabled products.
This is an individual contributor role for a recognized expert. You won't just execute tests. You'll decide which security problems matter most, define how the organization approaches them, and coach others to raise the technical bar. You'll work across Engineering, Product, Security, engineering, Legal & Compliance and security leaders will rely on your judgment when making risk decisions.
What You'll Do
Define the Offensive Security Approach
Frame the problem space: identify which offensive security risks matter most to the business, and set the technical strategy, frameworks, and priorities that guide how multiple teams address them.
Shape the multi-year technical roadmap for penetration testing, red teaming, AI security validation, and vulnerability research.
Define the standards, methodologies, and metrics that make offensive security work measurable and tied to risk reduction.
Anticipate downstream impact, such as emerging attack techniques, architectural shifts, and AI adoption, and bring it into planning before it becomes an incident.
Lead Complex Security Testing and Validation
Personally lead the most complex and ambiguous engagements across web, API, mobile, cloud, container, and AI-enabled systems.
Design and guide red team operations, adversary simulations, and purple team exercises.
Set technical direction and quality bars for external penetration testing partners and vendors, and review their findings and methodology.
Evolve attack surface management and continuous security validation into a repeatable, scalable capability.
Secure AI-Enabled Products
…