Azure SA&A Specialist supporting Government of Canada security assessments, controls, evidence, and testing. PLATO delivers Indigenous-owned software testing and technology services across Canada.
Responsibilities
Provide security subject matter expertise for Azure-based solutions and cloud environments
Support the completion of required Security Assessment and Authorization (SA&A) documentation and activities
Develop and maintain Document Control Responses
Collect, organize, and document security control evidence
Prepare and maintain Security Installation Plans (SIPs)
Execute security testing activities and document findings in formal test reports
Collaborate with project teams, architects, and security stakeholders to ensure compliance with security requirements
Support security reviews, assessments, and audits throughout the project lifecycle
Identify and document security risks and remediation recommendations
Requirements
Active Government of Canada Secret Clearance is required at the time of application
Strong knowledge and hands-on experience with the Microsoft Azure platform
Experience implementing and configuring security controls across Azure components and services
Demonstrated experience supporting cloud security compliance and governance initiatives
Experience developing SA&A artifacts, security documentation, and evidence packages
Experience executing and documenting security testing activities
In-depth knowledge of Government of Canada Security Assessment and Authorization (SA&A) processes and requirements
Preferred: Experience working on Government of Canada cloud transformation or modernization initiatives
Preferred: Familiarity with GC IT Security Risk Management methodologies and standards
Preferred: Experience with Azure security services such as Microsoft Defender for Cloud, Azure Policy, Microsoft Entra ID (Azure AD), Key Vault, and Sentinel
Preferred: Relevant security certifications such as AZ-500, CISSP, CCSP, or equivalent
Benefits
Collaborative environment
Mentorship and knowledge-sharing opportunities
Inclusive hiring practices
Recruitment accommodation support
Opportunity to contribute to complex, real-world client projects
IT Security Officer overseeing information security for Desjardins’ property and casualty insurance sector. Managing risks, vulnerabilities, suppliers, complex projects, and executive security reporting.
Senior Security Engineer owning identity, IT automation, and cloud security for Maze, a user research platform. Driving vulnerability management, compliance, and secure infrastructure at scale.
Product Security Engineer securing WorkOS developer tools and APIs for enterprise authentication and identity. Leading secure design, offensive testing, tooling, and vulnerability remediation.
Product Security Lead securing Miovision’s intelligent transportation products, cloud services, and connected devices. Leading secure - by - design engineering and product risk management for safer smart transportation networks.
Staff Product Security Engineer securing Phantom’s self - custodial multi - chain crypto wallet. Assessing vulnerabilities, leading security projects, and integrating protection across development and platform teams.
Cybersecurity co - op protecting TD’s banking technology, data, and fraud systems. Testing security solutions, operating tooling, and mitigating cyber and technology risks.