Senior Cloud Security
Location Address: Hybrid – Toronto (mostly remote for now, might change later)
Contract Duration: 6 months with high Possibility of extension & conversion to FTE
Business group : Information Security & Control (IS&C)’s Enterprise Security Services – Application Security is responsible to improve security practices and, through that, to find and preferably prevent security issues within applications.
Project : Cloud Native Application Protection Platforms (CNAPP) solution – Overlooking daily CNAPP applications, communicating with developers.
Understanding of Image scanning process helping development in pipelining data. Monitor the queue for exceptions. Get the necessary approvals.
We are seeking a Cloud Security Engineer to join our Enterprise Security Services team. You are familiar with the DevOps space and have strong Cybersecurity and Cloud security knowledge and skills. In addition, you have strong communication and stakeholder engagement skills, allowing you to understand and implement Cloud Native Application Protection Platforms (CNAPP) solution and apply best practices.
Must Have Skills:
• 10+ years’ relevant working experience in IT (development, DevOps, cloud security etc.)
• 3+ years’ experience with Cloud Security domains like CNAPP, CWPP, CSPM and/or tools like SCCE, CrowdStrike, Prisma Cloud, Aqua Enterprise, MS Defender etc.
• 3+ years’ experience as a DevSecOps Engineer, with demonstrated experience in security integration, automation of security processes, risk assessment and mitigation
• 5+ years’ experience with popular CI/CD tools and processes like BitBucket/GitHub, Jfrog Artifactory, Jenkins, Azure DevOps, GitLab CI/CD, CircleCI
Nice-To-Have Skills:
• 5+ years’ experience with documenting process, procedure, and user guide like a technical writer.
• 3+ years’ experience with large organization cloud transformation – Top 5 Canadian banks
• GCP PCSE Certification will be asset
Best VS. Average Candidate:
• Ideal candidate is very detail oriented, technical, analytical, and organized; strong DevSecOps Engineer who has worked in a tech company, startups in cloud transformation projects
Candidate Review & Selection
• 1 round – remote – Video Conference Call
• 1st – HM and one or two Senior Lead – 1 hour – technical interview focusing on security integration and vulnerability assessment knowledge and skills