Senior Associate designing cloud, application, and AI security solutions for PwC Canada’s consulting clients. Leading technical delivery pods and embedding DevSecOps across client environments.
Responsibilities
Design, develop, test, and deploy security solutions across AWS, Azure, GCP, and applications
Implement and integrate cloud and application security products
Configure secure baselines and perform cloud and Kubernetes security architecture reviews and remediation
Build production-quality code and infrastructure, including secure CI/CD pipelines, IaC modules, and cloud landing zones
Implement IAM, data encryption, network security, and other cloud security controls
Conduct security assessments and threat modeling for cloud environments and applications
Deliver cloud and application security strategy engagements and advise organizations on security transformation
Integrate security into the software development lifecycle and CI/CD pipelines
Design secure architectures and coding guidelines
Prepare reports, presentations, technical documentation, runbooks, and ADRs
Engage with client stakeholders and communicate technical findings and recommendations
Collaborate with cybersecurity specialists, data architects, business consultants, cloud engineers, developers, and risk advisors
Serve as senior engineer on a delivery pod and mentor Associates
Stay current on cloud and application security trends, threats, services, and compliance changes
Contribute to pre-sales through POCs, demos, prototypes, RFP technical content, and solution architecture artifacts
Drive practice growth while remaining hands-on and technical
Requirements
Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity or a related STEM discipline
3–6+ years of relevant experience in hands-on software development, security engineering, DevSecOps, or cloud security
Bilingual French/English
Hands-on experience with at least one major cloud: AWS, Azure, or GCP
Knowledge of IAM, networking, KMS, native cloud security services, and Terraform/IaC
Depth in cloud security or application security
Familiarity with Kubernetes, Helm, container security, CSPM/CNAPP tooling, or zero-trust networking
Familiarity with Secure SDLC, SAST/DAST/SCA, API security, threat modeling, secure code review, secrets management, or supply-chain security
Familiarity with security platforms such as Microsoft Defender, Google SecOps/Chronicle, CrowdStrike, Splunk, or Sentinel
Understanding of cloud security concepts and secure application development practices, including OWASP Top 10
Experience in security architecture reviews or implementing security controls for cloud services and applications
Proficiency in one or more scripting or programming languages, such as Python or Java
Effective communication and problem-solving skills
Experience working in project-based or consulting environments
Knowledge of security standards and frameworks such as NIST CSF, ISO 27001, or CSA Cloud Controls
Preferred certifications include CCSP, AWS/Azure Solutions Architect or specialty, CISSP, CKS, or relevant cloud/application/cybersecurity certifications
Experience in AI Security, LLM application development, LangChain/LangGraph, MCP server development, AI/ML frameworks, MLOps, AI red-teaming, or LLM observability is preferred
Experience embedding directly with customers to deploy and operationalize security or AI products is preferred
Comfort with hands-on debugging in Linux, Kubernetes, networking, and distributed systems is preferred
Open-source contributions to AI, security, or cloud-native tooling are preferred
Not available for work visa sponsorship
Government clearance is not required
Benefits
Variable incentive pay programs for eligible employees
Competitive compensation package
Inclusive benefits
Flexibility programs
Wellbeing support
Accommodation throughout the application, interview, and employment process
Information Security Manager leading enterprise EUC governance technology deployment and product roadmaps at TD, a global financial institution. Driving risk controls, adoption, delivery and assurance across business segments.
Principal Cloud Security Engineer securing Pax8’s cloud marketplace, infrastructure, and AI - enabled platforms. Establishing cloud, Kubernetes, identity, and software - delivery security standards across USA and Canada.
Cyber Security Engineer auditing diverse codebases, fixing vulnerabilities, and optimizing backend software. Contributing security insights and improvements to AI training datasets for a technology company.
Application Security Researcher building autonomous application - security capabilities for OX Security. Researching attack paths, AI models, and detection engines from prototype through production.
Managing Norfolk County’s cybersecurity, disaster recovery, incident response, and security projects. Supervising IT security staff and protecting municipal systems, services, and information.
IT Security Officer overseeing information security for Desjardins’ property and casualty insurance sector. Managing risks, vulnerabilities, suppliers, complex projects, and executive security reporting.
Azure SA&A Specialist supporting Government of Canada security assessments, controls, evidence, and testing. PLATO delivers Indigenous - owned software testing and technology services across Canada.