Careers · Growing into
Cybersecurity Lead
Secure operational AI systems that hold real business data under Canadian privacy law. Least-privilege design, hardened build gates, and the defences that keep the Canadian-hosting promise credible.
What you would own, end to end
You are the security conscience of every build. That means least-privilege architecture from the first schema migration: row-level security on every table, secrets out of source control before the first commit, IAM scoped to the minimum the feature needs. You own the dependency audit that runs before a package lands, the supply-chain review that catches a compromised transitive dep, and the security gate that every release passes before it ships to a client who is trusting us with their operational data.
AI adds attack surface most firms have not thought through yet: prompt injection in retrieval pipelines, tool-use abuse in agent workflows, data exfiltration through insufficiently scoped model access. You understand these threats and build the controls that address them, the same way the AI Developer builds the evaluation harness that catches output failures. Canadian data residency is the default we scope to, and where a service runs outside Canada we say so in writing. You are the one who makes it verifiable.
The work and why it pulls
Operational systems hold sensitive data: intake records, compliance documents, financial workflows. The businesses that use them are not large enterprises with dedicated security teams; they are the kind of operators who trusted a recommendation and want to know their data is handled correctly. The studio's commitment to Canadian hosting and privacy-first architecture is what separates the offer from a generic SaaS. The Cybersecurity Lead is the person who makes that commitment technically real.
The AI layer makes the problem more interesting. LLM-backed features have threat models that differ from a standard web application: the input surface is wider, the output paths are less predictable, and the retrieval components that give models context also need controls on what context they can access and from where. Entoura already engineers to a high bar on these problems. This role is the one that deepens that bar, formalizes it, and holds it across every build the team ships.
In your first months, expect to audit an active build's security posture end to end: access controls, secrets handling, RLS policies, dependency surface, and the AI-specific threat model. You produce a clear report and close the gaps you find, in the codebase, not a slide deck.
Who you would work with and where it leads
The studio is a senior team that stays deliberately lean. You work alongside engineers who already hold a high bar on correctness and maintainability, and you raise the bar on security by being the person who has thought through the threat model before the code is written. The expectation is that you can embed in a build, identify the risks specific to that system and that client's data, and communicate them plainly to engineers and to Carter without requiring them to become security specialists.
The role grows toward owning the firm's security architecture across all builds: setting the standards the team holds to, advising on new tooling and platform decisions before they are made, and shaping how the studio approaches security review as we move into new client verticals. If you want to be the person whose threat modeling and access-control decisions determine how a growing firm's operational data stays safe, this is the track that gets you there.
You think in threat models before you think in features. You have audited real systems, found real gaps, and fixed them in the code. You understand RLS, secrets management, and supply-chain hygiene well enough to be the person who defines how they are done, not the person who checks whether someone else did them.
How to get in touch
This role is one we are growing toward. Email careers@entoura.studio with a note about your background. Strong candidates stay in mind as the studio grows. If the fit looks right when the role opens, you will hear from us.
Send a note about your background and the kinds of systems you have audited or secured. It stays on file.
Get in touch