Senior Associate in Cyber Security developing and deploying security solutions for diverse cloud environments. Collaborating with clients to enhance their security posture through various initiatives.
Responsibilities
Design, develop, test, and deploy security solutions across cloud (AWS/Azure/GCP) and applications (SDLC integrations, AppSec pipelines)
Implement and integrate a variety of security products (e.g. Cloud & Application Security); configure secure baselines; perform cloud and Kubernetes security architecture reviews and remediation.
Build production-quality code and infrastructure including but not limited to secure CI/CD pipelines, IaC modules, cloud landing zones.
Work with cloud architects and developers to implement security solutions including cloud platforms and applications.
Configure security controls (identity & access management, data encryption, network security) and ensure cloud configurations follow leading security practices and compliance requirements.
Conduct security assessments and threat modeling for client cloud environments and applications, identifying vulnerabilities, misconfigurations, and compliance gaps.
Deliver cloud and application security strategy engagements and advise organizations on how to transform their current cloud & application security practice.
Integrate security into the software development lifecycle, collaborating with DevOps teams to incorporate automated security tools and secure coding practices (DevSecOps) into CI/CD pipelines.
Design secure architecture and coding guidelines, ensuring that new applications and services are built with security by design.
Support the delivery of client projects by preparing clear, high-quality deliverables (reports, presentations, technical documentation) that communicate security findings and recommendations effectively.
Engage with client stakeholders, explaining technical issues in clear terms and advising on improving cloud and app security postures from planning through deployment.
Collaborate within multidisciplinary teams – including other cybersecurity specialists, data architects, and business consultants – to deliver comprehensive security solutions.
Contribute to knowledge sharing and mentor associates by demonstrating best practices in cloud and application security (review code; write runbooks, ADRs, and technical documentation).
Stay updated on emerging cloud and application security trends (e.g., new cloud security services, emerging threats, compliance changes) to continuously improve our offerings.
Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity or a related discipline (STEM)
3–6+ years of relevant experience in hands-on software development, security engineering, DevSecOps, or cloud security.
Solid hands-on with at least one major cloud (AWS, Azure, GCP) — IAM, networking, KMS, native security services (GuardDuty, Defender, SCC), and IaC (Terraform).
One of the following depth areas: Cloud: Kubernetes (EKS/AKS/GKE), Helm, container security (Falco, Trivy), CSPM/CNAPP tooling (Wiz, Prisma, Defender for Cloud, Lacework), zero-trust networking.
Familiarity with security platforms: Microsoft Defender, Google SecOps/Chronicle, CrowdStrike, Splunk, Sentinel, or equivalents.
Solid understanding of core cloud security concepts (network segmentation, identity & access management, encryption, monitoring) and secure application development practices (e.g., familiarity with OWASP Top 10 vulnerabilities and remediation).
Experience in security architecture reviews or implementation of security controls for cloud services and applications.
Proficiency in one or more scripting or programming languages (e.g., Python, Java, or similar) is expected.
Effective communication and problem-solving skills, able to break down complex security concepts and translate technical findings into business implications.
Experience working in project-based or consulting environments, with a record of delivering results collaboratively in team-oriented projects to meet client needs under guidance of project leaders.
Knowledge of security standards and frameworks (e.g., NIST CSF, ISO 27001 compliance, CSA Cloud Controls, etc.) is advantageous for performing security assessments and guiding clients on compliance best practices.
Expert in application cybersecurity analyzing web components and supporting secure development practices within a dynamic team. Collaborate on cloud application security based in Quebec, Canada.
Information Security Consultant leading Risk Control Self Assessments and risk governance at Manulife. Collaborating on technology, data, and operational risk management while ensuring strong governance.
Penetration Testing Consultant at BMO conducting extensive manual security assessments for critical financial applications. Collaborating with stakeholders to enhance security strategies and practices.
Software Specialist at Xona developing secure software for the Pulsar ecosystem. Collaborating with teams to integrate security features in partner hardware.
Cybersecurity Intern at FloSports assisting in identity, cloud, and endpoint security. Work in a hybrid setup at the Waterloo office focusing on real - world cybersecurity practices.