Principal Security Engineer leading cyber security efforts and providing technical direction at Intact. Focusing on risk mitigation and mentoring security teams in a hybrid environment.
Responsibilities
Provide technology direction on the architecture and design of security-related technology initiatives.
Serve as a trusted advisor to security specialists, leveraging expertise to ensure high judgement decisions are made on complex and ambiguous security problems across all security domains, either by acting as decision-maker or by helping other specialists with the decision-making process.
Act as a force multiplier: Leverage your extensive expertise to enhance the effectiveness and efficiency of the entire engineering team.
Foster a culture of innovation and excellence by mentoring colleagues, enhancing mechanisms, introducing best practices, and driving architectural improvements that enable the team to implement strong security risk mitigations.
Promote cross-team collaboration and drive technical direction across teams, functions, and products, ensuring decisions support overall business, technology and security strategy.
Collaborate closely with senior leadership and principals to develop and implement strategic initiatives that contribute to a durable and resilient security control environment.
Continually identify opportunities for improvement and act as an agent of change by championing innovative ideas and initiatives to improve mechanisms.
Monitor and assess the impact of industry trends, emerging technologies, and changes in threat actor tactics and techniques; recommend strategies to evolve security countermeasures in response.
Serve as an active member of the tech community and promote technology within and outside the organization as a thought leader and contributing to advance IFC’s interests.
Requirements
Bachelor’s or master’s degree in computer science, Engineering or related field.
10+ years of experience in cyber security and/or software development, with at least 3+ years in technical leadership role.
Deep expertise in multiple cyber security domains, including application security, data security, endpoint security, network security, identity and access management, detection engineering, threat intelligence, incident response, and third-party risk management.
Strong understanding of software architecture principles and modern system design patterns.
Strong understanding of cloud service provider platforms and strategies for securing cloud-based technology assets.
Proven ability to design and operate scalable, resilient systems in production environments.
Excellent problem-solving skills and the ability to navigate ambiguity.
Excellent communication and stakeholder management skills to bridge the gap between cyber security teams and business leaders.
Proven leadership in mentoring security specialists and building technical communities.
For candidates located in Quebec, bilingualism is required considering the necessity to interact on a regular basis with English-speaking colleagues across the country.
No Canadian work experience required however must be eligible to work in Canada.
Benefits
Flexible work arrangements and a hybrid work model
Possibility to purchase up to 5 extra days off per year
Multiple benefits offered to support physical and mental wellbeing, including telemedicine, Wellness account and much more
Share plan & other savings: up to 12% of salary or even more (ask how you could earn guaranteed income for life)
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.
Développeur.euse sécurité cloud protégeant l’infrastructure de nesto, plateforme de financement hypothécaire canadienne. Conception de contrôles cloud, automatisation DevSecOps et réponse aux incidents.
Lead SCADA and cybersecurity engineer designing compliant electric - substation systems for GE Vernova. Coordinating multidisciplinary teams, vendors, testing, estimates, and project risk for decarbonized energy infrastructure.
Join RBC's Application Security Group to develop innovative security solutions, mentor junior staff, and collaborate across teams to enhance decision - making and automate tasks.
Lead SCADA and cybersecurity engineer designing compliant substation systems for GE Vernova. Guiding project teams, vendor designs, estimates, and acceptance testing for cleaner energy infrastructure.
Senior security advisor simulating cyber threats and strengthening defenses for Desjardins, North America's largest cooperative financial group. Leading complex initiatives, methodologies and cybersecurity risk mitigation.
SA&A Lead securing Azure applications and Microsoft platforms for PLATO, Canada’s Indigenous - owned software testing company. Leading authorization, control testing, evidence collection, and risk remediation.