Security and compliance roles account for over 130 postings we track
Published Aug 16, 2026 · 3 min read
A job family bigger than it looks
Across the 598 postings we track, security and risk-adjacent work is spread across several distinct categories rather than one tidy label. Add them up and the picture is bigger than any single category count suggests: Security (37), Security Engineering (23), Security Operations (10) and Risk, Credit & Banking (16) together account for 86 postings. Fold in Legal & Compliance (7) and Accounting & Audit (19), and the broader risk-and-compliance family across the catalogue climbs past 130 postings.
That is a meaningful share of the 598 postings we track, and it spans employers well beyond traditional banks — fintech, infrastructure and consumer tech companies all show up in these categories.
What the skills say
The skill counts back up the idea that this isn't a niche specialty confined to one team. Regulatory Compliance is required in 42 postings, Identity & Access Management in 27, Application Security in 25, Cloud Security in 23, Incident Response in 20, and AML & KYC plus Audit & Internal Controls in 14 each. Fraud Prevention rounds things out at 14.
These skills don't stay confined to the categories named "Security" — Regulatory Compliance at 42 postings is nearly double the size of the Security Operations category itself (10), which means compliance requirements are being written into job postings across Finance & Accounting, Risk, Credit & Banking, and elsewhere, not just inside dedicated security teams.
The infrastructure angle
Security work in this catalogue is also tightly coupled to cloud and platform skills. Kubernetes appears in 59 postings, AWS in 63, CI/CD in 54, and Observability & Monitoring in 70 — all skills that overlap heavily with the DevOps & SRE (23) and Security Engineering (23) categories. That overlap suggests employers increasingly expect security engineers to be platform-fluent, not just policy-fluent.
Terraform (22) and Identity & Access Management (27) point to the same trend: infrastructure-as-code and access control are treated as core security competencies rather than separate specialties.
Where the roles concentrate
Among the 20 employers in the catalogue, fintech names dominate the risk and compliance side. Neo Financial, with 94 open postings, and Wealthsimple, with 39, are the kind of employers where Risk, Credit & Banking and AML & KYC requirements would be expected to cluster, given their business. Trulioo, with 18 open postings, operates in identity verification, a natural fit for the Identity & Access Management skill count of 27.
On the pure infrastructure-security side, companies like Tenstorrent (53 postings) and Elastic (26 postings) sit closer to the Application Security (25) and Cloud Security (23) skill demands, reflecting hardware and search/observability businesses that need to secure complex technical stacks rather than financial transactions.
A caveat on salary data
Only 11 of the 598 postings in the catalogue state a salary range at all, so it isn't possible to say anything about what security or compliance specialists are paid relative to other categories. What the catalogue does support is scope: security, risk and compliance responsibilities are distributed across at least six named categories and touch dozens of specific skills, from AML & KYC to Kubernetes, making it one of the more structurally diffuse job families we track rather than a single, self-contained category.
Written by Jobliy's AI from the live Canadian job-market data in this catalogue. Figures are drawn from postings we hold today.