Senior Security Engineer supporting end-to-end security architecture and compliance for healthcare AI startup. Designing Azure security solutions and partnering with engineering teams for integrated security throughout SDLC.
Responsibilities
Support end-to-end security architecture across all domains (IAM, infrastructure security, application security, cyber defense, and data security).
Design and implement Azure-native security solutions using the full Microsoft security stack: Entra ID, Defender for Cloud, Microsoft Sentinel, Defender for Endpoint, Purview, and Azure Policy.
Support and collaborate on GRC programs across the full compliance lifecycle.
Partner with Engineering, ML, and Infrastructure teams to embed security throughout the SDLC.
Build and operationalize security monitoring, alerting, and incident response capabilities.
Champion product security across the AIMS platform, conducting security design reviews, threat modeling, and vulnerability assessments.
Requirements
Bachelor’s degree in computer science/engineering or equivalent practical experience.
5+ years of experience in security engineering, with deep, hands-on expertise in Microsoft Azure security architecture and the Microsoft security product ecosystem.
Technically strong across all security domains (IAM, infrastructure, application security, cyber defense, and data protection).
Comfortable securing both fully cloud-native and hybrid environments.
Experienced operating in highly regulated environments, with direct involvement in SOC 2 Type II, HIPAA, or equivalent compliance programs.
Strong communication skills with the ability to engage engineering teams, executive stakeholders, and external customers.
Expert in application cybersecurity analyzing web components and supporting secure development practices within a dynamic team. Collaborate on cloud application security based in Quebec, Canada.
Penetration Testing Consultant at BMO conducting extensive manual security assessments for critical financial applications. Collaborating with stakeholders to enhance security strategies and practices.
Information Security Consultant leading Risk Control Self Assessments and risk governance at Manulife. Collaborating on technology, data, and operational risk management while ensuring strong governance.
Software Specialist at Xona developing secure software for the Pulsar ecosystem. Collaborating with teams to integrate security features in partner hardware.
Cybersecurity Intern at FloSports assisting in identity, cloud, and endpoint security. Work in a hybrid setup at the Waterloo office focusing on real - world cybersecurity practices.