Full-Time

Senior Security Engineer

Forma.ai

Forma.ai

51-200 employees

Real-time sales compensation modeling platform

Compensation Overview

CA$160k - CA$190k/yr

+ Employee stock ownership plan + $750 yearly training stipend

Toronto, ON, Canada

Remote

Category
IT & Security (1)
Required Skills
LLM
PowerShell
Datadog
Bash
Kubernetes
Python
Incident Response
Git
Computer Networking
Docker
Vulnerability Analysis
SOC 2
AWS
Cryptography
Terraform
DevOps

Get referred to Forma.ai

See people who can refer or advise you

Requirements
  • Six or more years of experience in security engineering, cloud security, application security, DevSecOps, or infrastructure engineering.
  • Strong hands-on experience securing Amazon Web Services environments, including identity and access management, networking, encryption, logging, and secrets management.
  • Experience with Terraform, Kubernetes, containers, and security controls in continuous integration and continuous delivery pipelines.
  • Strong understanding of application and application programming interface security, authentication, authorization, and multi-tenant software-as-a-service risks.
  • Experience with vulnerability management, threat modelling, incident response, and security automation.
  • Ability to write scripts using Python, Bash, PowerShell, or a similar language.
  • Strong communication, troubleshooting, and cross-functional collaboration skills.
Responsibilities
  • Design and implement security controls across Forma's Amazon Web Services environments, focusing on identity and access management, least-privilege access, service identities, and account boundaries.
  • Embed security requirements into Terraform and other Infrastructure as Code, and improve secrets, certificate, encryption-key, and credential management.
  • Build automated checks for insecure configurations, excessive permissions, exposed resources, and configuration drift across Kubernetes, containers, serverless workloads, networking, and data services.
  • Run threat modelling and security architecture reviews for new products, services, application programming interfaces, data pipelines, and third-party integrations.
  • Strengthen tenant isolation, authorization enforcement, and fine-grained data access controls at the schema, table, row, and column levels.
  • Protect sensitive compensation, financial, customer, and employee data across databases, data warehouses, Amazon S3, analytics services, and internal tools, including logging and auditability for sensitive-data access.
  • Review artificial intelligence and agentic workflows for data leakage, prompt injection, insecure tool use, and excessive permissions; ensure agents operate within the calling user's permissions; and define secure patterns for approved services such as Amazon Bedrock.
  • Identify and help remediate application vulnerabilities, and build tooling and reusable libraries that make secure development easier for engineers.
  • Embed security testing into continuous integration and continuous delivery, including static analysis, dependency and container scanning, secrets detection, Infrastructure as Code scanning, and dynamic testing.
  • Define vulnerability-severity, remediation, exception, and escalation standards, and partner with developers to separate real risk from noise and fix root causes.
  • Improve software supply-chain security, including build permissions, artifact integrity, dependency governance, and GitHub administration.
  • Improve security visibility across cloud infrastructure, applications, identities, endpoints, and software-as-a-service systems, and build actionable alerts and detection logic.
  • Lead investigations and coordinate containment, remediation, and root-cause analysis using clear runbooks, ownership, and escalation paths.
  • Run tabletop exercises, and track and communicate security metrics and material risks to technical and business stakeholders.
  • Strengthen single sign-on, multifactor authentication, privileged access, and onboarding, offboarding, and access-review processes across Amazon Web Services, GitHub, Microsoft 365, Entra ID, production systems, and internal software-as-a-service applications.
  • Automate provisioning, entitlement reviews, and evidence collection where practical.
  • Translate security and compliance requirements into concrete technical controls, and support customer security reviews, audits, SOC 2, and ISO 27001 programs.
  • Evaluate third-party tools and integrations for security, privacy, and access-control risk, and help select, consolidate, and rationalize security tooling for coverage and cost.
  • Maintain clear technical standards and provide practical guidance, training, and mentorship that raises security capability across Engineering.
  • Build an understanding of the application architecture, Amazon Web Services environments, deployment processes, data flows, identity systems, and security obligations.
  • Meet key partners across Engineering, DevOps, IT, Product, Legal, and Privacy and agree on how security reviews and escalations will operate.
  • Review existing controls, open findings, incidents, access patterns, monitoring, and compliance commitments.
  • Identify immediate risks, quick wins, and areas needing deeper assessment.
  • Deliver a prioritized security roadmap based on risk, business impact, and engineering effort.
  • Address high-priority gaps in cloud access, secrets management, continuous integration and continuous delivery security, vulnerability management, and monitoring.
  • Introduce or improve consistent processes for threat modelling and security architecture reviews, and define vulnerability-severity, ownership, remediation, and exception standards.
  • Assess the current security tool stack for coverage, overlap, and cost, with consolidation recommendations.
  • Improve incident-response runbooks, alert ownership, and escalation paths for critical systems, and recommend measurable security objectives and reporting metrics.
  • Put automated security guardrails in place across Amazon Web Services, Terraform, Kubernetes, GitHub, or continuous integration and continuous delivery.
  • Run repeatable processes for vulnerability management, access reviews, security assessments, and incident follow-up.
  • Complete security reviews for the highest-priority product, data, or artificial intelligence initiatives, with required controls agreed and in progress.
  • Improve visibility into high-risk identities, infrastructure changes, and sensitive-data access.
  • Present progress, key risks, and the next phase of the security roadmap to leadership.
Desired Qualifications
  • Experience supporting SOC 2, ISO 27001, privacy programs, or enterprise customer security reviews.
  • Experience securing analytics platforms, data pipelines, or systems handling sensitive customer data, including row-level, column-level, or attribute-based access controls.
  • Experience with Amazon Web Services security services, Elastic Kubernetes Service, Datadog, Wiz, Snyk, CrowdStrike, or similar tools.
  • Experience securing artificial intelligence applications, large language models, agents, or Amazon Bedrock workloads.
  • Experience in a business-to-business software-as-a-service or high-growth technology company.
  • Relevant security or cloud certifications.

Forma.ai provides a real-time modeling platform that helps businesses optimize sales compensation. It lets customers test different compensation ideas against historical data to estimate costs and potential impact, then implement the best-performing plan. The product works by running simulations on past sales data to forecast outcomes under various pay structures, enabling quick experimentation and rollout of new strategies. Forma.ai differentiates itself by offering live, scenario-based testing at scale for organizations ranging from startups to large enterprises across the globe, including customers like Autodesk. Its business model is service-based, typically charging a subscription fee for access to the platform. The company aims to turn sales compensation into a strategic advantage by making it faster and easier to design, compare, and deploy compensation plans that align with business goals.

Company Size

51-200

Company Stage

Series B

Total Funding

$58M

Headquarters

Toronto, Canada

Founded

2016

Get referred to Forma.ai

See people who can refer or advise you

Simplify Jobs

Simplify's Take

What believers are saying

  • Forma.ai launched with a large medical device company and now supports 800M+ transactions annually.
  • Deloitte named Forma.ai Fast 500 North America 2025 and Fast 50 Canada 2025.
  • SeaMonster and FatStax AI acquisitions suggest aggressive product expansion for 2025 enterprise deals.

What critics are saying

  • Xactly and CaptivateIQ attack the same enterprise SPM budget with deeper category awareness.
  • A 2022 layoff round cut 15 employees, signaling prior operating leverage pressure.
  • If enterprise renewals slow, Forma.ai's premium SPM platform faces fast commoditization.

What makes Forma.ai unique

  • Forma.ai unifies planning, crediting, governance, and analytics for enterprise sales compensation.
  • The global medical technology leader uses Forma.ai across 40+ countries and 4,200 payees.
  • SeaMonster acquisition added verified activity monitoring, enabling activity-based incentives beyond standard quota plans.

Help us improve and share your feedback! Did you find this helpful?

Benefits

Health Insurance

Dental Insurance

Vision Insurance

Life Insurance

Disability Insurance

Parental Leave

Professional Development Budget

Company Equity

Growth & Insights and Company News

Headcount

6 month growth

-2%

1 year growth

-2%

2 year growth

-2%
Voucherify
Apr 28th, 2026
Introducing Vincent: ai-powered incentive optimization.

Introducing Vincent: ai-powered incentive optimization. April 28, 2026 * Vincent is an AI incentive optimization agent that builds, analyzes, and optimizes incentives in Voucherify using natural language. * Vincent is multi-agent by design: built to connect with Bloomreach, Braze, and other platforms so your incentive logic talks to your entire stack. * Early access is available now. Table of contents Incentives are one of the fastest ways to drive conversion, increase average order value, and improve repurchase. But in practice, optimizing incentives is operationally heavy, so most teams fall back on the same static discounts quarter after quarter. The result is a costly tradeoff: brands either over-discount and erode margin, or under-incentivize and miss revenue opportunities. Today, Software limited is excited to announce the launch of Vincent, a conversational AI interface designed to remove these barriers. Vincent allows teams to design, test, analyze, and modify incentives using natural language, reducing the time between idea and live experiment from days to minutes. "Voucherify has always been built for complex incentives," said Tomasz Pindel, CEO and co-founder of Voucherify. "Vincent makes that power accessible without slowing teams down. Instead of translating intent into configuration steps, users can express what they want to achieve, launch experiments faster, and iterate in real time." Conversational access to incentive optimization. With Vincent, Software limited is introducing a new way to design and optimize incentives. Instead of translating marketing ideas into configuration logic across multiple interfaces, teams can describe the outcome they want to achieve. Vincent converts that intent into structured incentive logic using the same rules, validation layers, and safeguards that power Voucherify today. By shortening the cycle between idea, launch, and analysis, Vincent enables teams to run more experiments and continuously improve the incentives that drive conversion, repurchase, and revenue. From market signals to incentive decisions. Vincent also connects incentive optimization with external market intelligence. Promotions do not operate in isolation. Pricing pressure, competitive campaigns, and seasonal trends all influence how customers respond to incentives. Yet most teams still plan promotions using internal data alone, with limited visibility into how competitors structure their offers. Vincent can incorporate external promotional intelligence sources, such as market and competitive data platforms, to provide broader context for incentive decisions. Instead of treating competitive research and campaign execution as separate processes, Vincent brings them into the same workflow. Market signals become actionable inputs for incentive design, enabling teams to respond faster to changing promotional landscapes. Human control at enterprise scale. Incentives directly influence pricing, margin, and customer experience. For enterprise teams, that makes control and governance essential. Vincent is designed to accelerate experimentation without compromising oversight. Every proposed campaign change is surfaced for review before execution, allowing teams to approve, modify, or reject configurations while maintaining full visibility into how incentive logic is applied. "This isn't about removing humans from the loop," said Pindel. "It's about giving teams the ability to experiment faster while keeping full control over how incentives impact the business." Built for the next phase of commerce. Vincent reflects a broader shift in how incentives will be delivered in the coming years. As commerce becomes increasingly AI-assisted, incentive systems must evolve beyond static campaign logic. Future incentive decisions will increasingly be made in real time, responding to signals such as customer intent, purchasing context, and automated agent interactions. By introducing natural language as an interaction layer, Software limited is supporting both human-led experimentation today and the agent-driven commerce models emerging across digital platforms. Vincent is currently available to selected customers, with broader rollout planned in phases. FAQs. What is Vincent? Can Vincent mess up my live campaigns??? What can Vincent actually do today? How do I get access to Vincent? Notes on incentives, by Mike (its CMO). Hot takes on loyalty & incentives. Product updates that are actually helpful. Monthly zodiac sign advice for your incentive strategy. I don't really get what Mike does, but if it helps people stop sending those awful 'last chance!' emails, then I'm all for it. Mike's mom, Subscriber #001 Are you optimizing your incentives or just running them?

BetaKit
May 29th, 2024
A|I: The Ai Times – Openai’S “Whether You Like It Or Not” Philosophy

Plus: Shopify's Tobi Lütke will help advise Meta's AI strategy

Newswire
May 23rd, 2024
Forma.ai Acquires SeaMonster to Create World's First Activity-Based Sales Incentives Solution

Forma.ai acquires SeaMonster to create world's first activity-based sales incentives solution.

BetaKit
May 23rd, 2024
Forma.ai Acquires SeaMonster for Sales Incentives

Forma.ai has made its first acquisition by purchasing fellow Toronto-based sales software startup SeaMonster. The deal aims to combine SeaMonster's sales activity monitoring and compliance capabilities with Forma.ai's AI-powered sales performance management software to provide activity-based sales incentives. SeaMonster's CTO Jesse Lancaster joins Forma.ai as VP of Data Engineering, while CEO Kevin North remains as an advisor. Financial terms were not disclosed.

Technical.ly
May 16th, 2024
Ai Can Now Design Greener Cities, But Architects Still Have The Final Say

Imagine what Philly could look like if builders turned Vine Street Expressway into a giant park, bringing more fresh air and positive environmental impacts to the city. That might sound impossible, but AI is already coming up with ideas to make it happen. A group of faculty and students at Thomas Jefferson University’s Institute for Smart and Healthy Cities are experimenting with AI to design green infrastructure in Philadelphia just like that. The institute worked on a project this year developing ideas for “urban interventions” that mediate climate change using AI tools, Edgar Stach, director of the institute and architecture professor, told Technical.ly. “We tailored the design process based on your location and the need to improve environmental aspects in that location,” Stach said