Cybersecurity Engineer strengthening security across EDC’s cloud, applications, and enterprise technology. Supporting secure delivery and AI/ML security for Canada’s export finance corporation.
Responsibilities
Partner with infrastructure, cloud, and application teams to embed security controls across cloud-native services, APIs, on-premise systems, and SaaS platforms
Identify security gaps and vulnerabilities, prioritize remediation, and develop tactical remediation plans
Design and implement security tooling, hardening standards, and automation
Contribute to threat modelling, security architecture reviews, and emerging-technology assessments
Monitor the threat landscape and translate new attack techniques into security improvements
Embed as a security partner within delivery squads and agile teams during design, development, and deployment
Review project documentation, architecture diagrams, code changes, and configuration decisions
Champion secure-by-default patterns, DevSecOps, and shift-left security
Develop and maintain security standards, guidelines, and reusable patterns
Advise product and engineering stakeholders on risk-based decisions
Assess and address AI/ML security risks, including model integrity, data pipeline security, prompt injection, and secure AI deployment
Support AI security risk assessments, reviews, governance, and collaboration with platform and delivery teams
Apply AI/ML tools to anomaly detection, threat hunting, alert triage, and other security operations
Evaluate AI-assisted security tooling
Collaborate with technology and business stakeholders to align security with EDC’s transformation roadmap
Communicate security concepts to technical and non-technical audiences
Contribute to KPI and metrics development for security posture improvements
Support continuous improvement and evolution of the security program
Requirements
Post-secondary degree in Computer Science, Information Security, Engineering, or a related field and equivalent practical experience
Minimum 7 years of hands-on experience in cybersecurity engineering, application security, cloud security, or a comparable technical security role
Breadth across multiple security domains, including application security, cloud security, identity, network security, endpoint security, data protection, or vulnerability management
Experience partnering with software delivery or platform engineering teams and embedding security into SDLC processes, CI/CD pipelines, and agile workflows
Proficiency with cloud security; Azure preferred, with AWS or GCP experience valued
Experience securing cloud-native architectures and services
Hands-on experience with security tools such as SIEM, vulnerability management, DAST/SAST, secrets management, identity platforms, endpoint security, or cloud security tools
Familiarity with AI/ML security considerations
Strong communication skills for translating technical security risk into business impact
Ability to collaborate, operate independently, manage ambiguity, engage stakeholders, and escalate appropriately
Candidates must be able to work legally in Canada at the time of application; preference is given to Canadian Citizens or Permanent Residents
Must meet requisite government security screening requirements
Security architect securing Thomson Reuters’ legal, tax, compliance, government, and media technology platforms. Leading architecture reviews, cloud security, threat modelling, and AI system risk controls.
Product Security Engineer securing Cohere’s enterprise AI products and foundation models. Reviewing architecture, threat modeling capabilities, and testing vulnerabilities across production systems.
Ingénieur cybersécurité renforçant la posture de sécurité d’EDC, société canadienne de financement du commerce international. Intégration de contrôles, DevSecOps et sécurité de l’IA.
Senior Program Manager driving enterprise cybersecurity programs for NBCUniversal, a global media and entertainment company. Coordinating technical delivery, operational change, adoption, risk, and executive reporting.
Head of Information Security leading OpenZeppelin’s enterprise security, privacy, IT, and AI governance programs. Securing open - source infrastructure used across onchain finance and digital assets.
Red Team Security Engineer evaluating Motive's fleet - management platform and cloud environments. Executing adversary simulations, validating detection coverage, and driving remediation of security issues.
Information Systems Security Manager securing RideCo’s cloud - based on - demand transit platform. Leading compliance, risk management, incident response, and security operations.