Cloud Security Specialist securing Fortinet’s cloud products and infrastructure. Leading vulnerability management, SOC operations, incident response, DevSecOps, and AI-driven security initiatives.
Responsibilities
Manage the end-to-end vulnerability lifecycle, including triaging, risk prioritization, and remediation coordination
Participate in daily SOC operations by monitoring and triaging security alerts
Collaborate with cloud operations teams to resolve security events
Lead security incident response for Fortinet cloud services, including detection, investigation, containment, remediation, recovery, and post-incident reviews
Integrate SAST, DAST, software composition analysis, container image scanning, secret detection, and infrastructure-as-code security checks into CI/CD pipelines
Define security gates and release criteria and tune security results with development teams
Support security compliance requirements, audits, and certification efforts such as ISO 27001
Perform CIS Benchmark assessments, map results to controls, document findings, and track gaps to closure
Participate in designing and implementing an AI-based cloud security posture management system focused on public IP scanning and security exposure analysis
Collect and analyze threat intelligence and evaluate risks
Requirements
5+ years of dedicated experience in a security engineering role, such as Security Engineer, Penetration Tester, or DevSecOps/SRE
Hands-on experience with FortiSIEM, FortiAnalyzer, and FortiSOAR, or equivalent enterprise SIEM and SOAR tools
System administration experience with firewalls, VPN, and SIEM, including policy and rule management, log source onboarding, and health monitoring
Experience with Linux server administration, backup and restore procedures, patching and upgrade cycles, and high availability/disaster recovery operations
Familiarity with vulnerability scanning tools such as Nessus, Nuclei, or Wiz/Lacework
Experience applying Agentic AI to security operations, including designing and deploying AI agents for alert triage, threat hunting, and response orchestration
Understanding of AI security risks including prompt injection, insecure agent tool/function calling, model and data poisoning, and evaluation/testing of LLM-backed applications
Strong knowledge of web application fundamentals, including authentication, authorization, session management, HTTP, web languages, web servers, and browser architecture
Proficient programming ability for security code review, scripting, security scan enrichment, and penetration testing automation
Bachelor's degree in Computer Science, Information Security, Electrical Engineering, or a related field
Benefits
100% company-paid medical, dental, and vision coverage
Health Spending Account
Personal Spending Account
Employee & Family Assistance Plan, including counseling, legal advice, and mental health resources
Critical illness, disability, and life insurance
Group Registered Retirement Savings Plan (RRSP) with company match
Competitive Paid Time Off
Flexible leave policies, including paid health days
Equity program eligibility
Bonus eligibility reviewed at hire and annually at the Company’s discretion
Regional Health & Safety Manager leading health, safety, and regulatory compliance for GFL’s environmental services operations in Quebec. Conducting audits, incident management, training oversight, and regional site visits.
Information Security Student supporting vulnerability management and cloud security at Nasdaq Verafin. Assisting with remediation, security posture enforcement, and cloud environment protection.
Senior Principal Security Architect shaping enterprise security architecture for Invesco, a global investment - management firm. Leading cloud, identity, network, data - protection, and risk initiatives.
Principal Security Architect securing Menlo Security’s browser and AI - agent protection platform. Leading cryptography, cloud, vulnerability, and product security architecture.
BDC banking manager overseeing commercial loan security and disbursements across Western Canada. Coordinating due diligence, risk evaluation, lending partners and compliant loan funding.
Cybersecurity new graduate rotating through Intact’s 24 - month tech development program. Supporting threat detection, incident response, infrastructure security, and AI - enhanced security insights.