
Staff Security Engineer (Americas)
Shopify · NAMER
- Hybrid
- Full-time
- $150,000 / year
- NAMER
Job highlights
- Build impactful security solutions for cyber risk protection.
- Lead incident response and mitigate long-term threats.
- Develop AI-driven security operations and detection.
- Champion cross-functional projects and stakeholder communication.
- Operate with autonomy and drive work from ambiguity.
About the role
About The Role
We are hiring staff security engineers who build impactful solutions fast. You will protect our company, our merchants and our data against any and all cyber risks. You will help Shopify maintain a high-trust operating environment by building tailored detection and response solutions.
Key Responsibilities
- Design, build and ship security solutions that defend against cyber attacks and data exfiltration
- Champion cross-functional projects
- Respond to and lead incident response for critical security events
- Cut through complexity to focus on high-impact work that reduces real risk
- Partner with IT, legal, and business teams to mitigate threats and remediate for the long-term
- Communicate security risks and technical recommendations to both technical and non-technical stakeholders
Qualifications
- Expertise in building great software in the security detection and response domain
- Broad expertise in endpoint security, enterprise IT security and cloud security
- Proven experience responding to cyber security incidents
- Active awareness of emerging threats and AI-enabled attack vectors including prompt injection, supply chain compromises and social engineering
- Experience building real AI solutions that deliver tangible value to security operations, not just novel experiments
- Proficiency in Python, Swift and GCP; with Cursor and other AI tools
- Excellent communication skills: you can distill complex security data into clear, actionable insights
- Brings senior-level judgment and operates with high autonomy, proactively identifying and driving work from ambiguity to outcomes
About Shopify
Opportunity is not evenly distributed. Shopify puts independence within reach for anyone with a dream to start a business. We propel entrepreneurs and enterprises to scale the heights of their potential. Since 2006, we’ve grown to over 8,300 employees and generated over $1 trillion in sales for millions of merchants in 175 countries.
This is life-defining work that directly impacts people’s lives as much as it transforms your own. This is putting the power of the few in the hands of the many, is a future with more voices rather than fewer, and is creating more choices instead of an elite option.
About You
Moving at our pace brings a lot of change, complexity, and ambiguity—and a little bit of chaos. Shopifolk thrive on that and are comfortable being uncomfortable. That means Shopify is not the right place for everyone.
Before you apply, consider if you can:
- Care deeply about what you do and about making commerce better for everyone
- Excel by seeking professional and personal hypergrowth
- Keep up with an unrelenting pace (the week, not the quarter)
- Be resilient and resourceful in face of ambiguity and thrive on (rather than endure) change
- Bring critical thought and opinion
- Put AI agents and tools to work on the tasks they're built for, and focus on the work only humans can do
- Embrace differences and disagreement to get shit done and move forward
- Work digital-first for your daily work
We may use AI-enabled tools to screen, select, and assess applications. All AI outputs are reviewed and validated by our recruitment team.
Key skills/competency
- Staff Security Engineer
- Security Detection and Response
- Cybersecurity Incident Response
- Endpoint Security
- Cloud Security
- Python
- GCP
- AI Security Solutions
- Risk Mitigation
- Communication Skills
Skills & topics
- Staff Security Engineer
- Security Engineer
- Cybersecurity
- Incident Response
- Security Detection
- Security Response
- Cloud Security
- Endpoint Security
- Python
- GCP
- AI Security
- Prompt Injection
- Social Engineering
- Supply Chain Compromise
How to get hired
- Tailor your resume: Highlight expertise in security detection, response, and AI solutions.
- Showcase your impact: Quantify achievements in defending against cyber threats and exfiltration.
- Demonstrate autonomy: Emphasize experience leading projects and driving outcomes from ambiguity.
- Prepare for technical questions: Be ready to discuss Python, Swift, GCP, and AI security tools.
- Align with culture: Understand Shopify's fast-paced, high-trust environment and customer focus.
Technical preparation
Behavioral questions
Frequently asked questions
- What does a Staff Security Engineer do at Shopify?
- A Staff Security Engineer at Shopify designs, builds, and ships security solutions to protect against cyber risks and data exfiltration. They also lead incident response, partner with other teams, and communicate security insights to stakeholders, with a focus on building AI-driven security operations.
- What are the key technical skills required for this Staff Security Engineer role at Shopify?
- The role requires expertise in security detection and response, broad knowledge of endpoint, enterprise IT, and cloud security, and proven experience in incident response. Proficiency in Python, Swift, and GCP, along with experience in AI security solutions and AI-enabled attack vectors, are essential.
- How does Shopify use AI in its security operations for this role?
- Shopify seeks candidates experienced in building real AI solutions that provide tangible value to security operations. This includes understanding and defending against AI-enabled attack vectors like prompt injection and leveraging AI tools for enhanced security detection and response.
- What kind of work environment can I expect at Shopify as a Staff Security Engineer?
- Shopify is known for its fast-paced, dynamic environment with a significant amount of change, complexity, and ambiguity. The company culture values individuals who can thrive in this setting, take initiative, and operate with a high degree of autonomy.
- How important is communication for a Staff Security Engineer at Shopify?
- Excellent communication skills are critical. You must be able to distill complex security data into clear, actionable insights for both technical and non-technical audiences, and effectively communicate security risks and recommendations.
- What is the expected seniority and level of autonomy for this Staff Security Engineer position?
- This is a Staff-level position, indicating a senior role with high autonomy. You are expected to bring senior-level judgment, proactively identify needs, and drive work from ambiguity to successful outcomes independently.