Senior Security Specialist securing RBC’s cloud banking environments across AWS, Azure, and Google Cloud. Executing red/purple team exercises and refining offensive security tooling.
Responsibilities
Assess and improve the security of public cloud environments across AWS, Microsoft Azure, and Google Cloud Platform
Participate in hands-on Red and Purple Team Exercises in mature production environments
Develop, evolve, and refine offensive tradecraft and tooling
Partner with Cloud Security, Cloud Operations, Threat Hunting, Threat Intelligence, SOC/IR, and ATO ML/AI analytics teams
Liaise with cloud operations, internal customers, the security operations center, business stakeholders, and management regarding information security incidents and trends
Requirements
Experience in scripting/automating operations via various cloud APIs or CLIs
Good understanding of modern, cloud-centric architectures and DevOps principles
Strong experience managing AWS, Microsoft Azure, or Google Cloud Platform
Strong experience building systems and/or platforms using AWS, Microsoft Azure, or Google Cloud Platform
Intermediate experience with Ansible or Puppet, CloudFormation or Terraform, and Jenkins
Background in PaaS/SaaS environment practices, including maintaining SLAs, load-balancing, high availability, operating system patching, networking, and security management/patching
Strong technical understanding of Linux and Windows hardware and software platforms
Ability to communicate complicated technical concepts or attack paths to broader non-technical audiences
Certifications in information security, AWS, Azure, or GCP are nice-to-have
Experience running Kubernetes environments and understanding multi-tenancy and security implications is nice-to-have
3+ years of Cyber Security experience with background executing network/application-layer penetration tests is nice-to-have
Ability to analyze complex security and vulnerability events
Ability to set ambitious but achievable goals and surpass them
Ability to build, grow, and maintain internal and external relationships
Benefits
Comprehensive Total Rewards Program including bonuses and flexible benefits, competitive compensation, commissions, and stock where applicable
Dedicated budget for annual training and conference attendance
Leaders who support your development through coaching, training, and managing opportunities
Flexible work/life balance options including a hybrid-remote working environment
Opportunities to attend industry-leading public and private training sessions
Opportunities to take on progressively greater accountabilities
Opportunities to build close relationships with various cyber security teams
Head of Information Security leading OpenZeppelin’s enterprise security, privacy, IT, and AI governance programs. Securing open - source infrastructure used across onchain finance and digital assets.
Red Team Security Engineer evaluating Motive's fleet - management platform and cloud environments. Executing adversary simulations, validating detection coverage, and driving remediation of security issues.
Information Systems Security Manager securing RideCo’s cloud - based on - demand transit platform. Leading compliance, risk management, incident response, and security operations.
Senior Security Specialist operating BloodHound Enterprise for RBC, a Canadian bank. Mapping identity attack paths and prioritizing remediation across cloud, AD, DevOps, and PAM environments.
Staff Security Researcher conducting vulnerability research and penetration testing for GitLab’s AI - powered DevSecOps platform. Developing attack methodologies, tooling, and security improvements.
Principal Security Researcher securing GitLab’s AI - powered DevSecOps platform. Leading vulnerability research, AI attack analysis, penetration testing, and remediation across GitLab’s codebase.
Senior security advisor strengthening Desjardins's security posture across governance, data protection, and fraud prevention. Leading complex strategic initiatives for the Desjardins financial services organization.