Cloud Application Security Engineer securing SaaS applications and infrastructure hosted in AWS. Collaborating with DevOps and Engineering for scalable security solutions within a hybrid work environment.
Responsibilities
Collaborate with DevOps, Engineering, and other stakeholders to design, implement, and operate cloud and application security capabilities across CI/CD pipelines and production environments
Support application security reviews and threat modeling, including code review, static and dynamic testing
Support vulnerability management processes across application and infrastructure layers, including CI/CD-integrated workflows
Assist in implementing and maintaining AWS security guardrails, ensuring services are properly configured with effective monitoring, visibility, and alerting
Support Kubernetes and container security controls, including configuration standards, access controls, and runtime considerations
Contribute to automation of security workflows to reduce manual effort and improve response times
Support Infrastructure as Code (IaC) security practices, including Terraform-based deployments
Monitor systems for irregular behavior, improve detection capabilities, and assist in incident response and investigation
Support reporting and continuous improvement of security controls and operational security processes
Support the evaluation and adoption of AI-assisted security and operational workflows
Work closely with senior engineers and cross-functional teams to support secure platform operations and continuous improvement initiatives
Requirements
2-5 years of experience in cloud, application, or platform security, with demonstrated depth in AWS and modern cloud-native environments
Bachelor’s degree in computer science, engineering, or equivalent experience
Experience working with cloud security technologies, preferably AWS, including implementation of security controls and guardrails
Experience securing containerized environments and Kubernetes platforms (RBAC, network policies, workload security), including implementing controls in production environments
Experience implementing security controls within CI/CD pipelines and supporting developer workflows
Experience with vulnerability management across application and infrastructure layers, including prioritization and remediation workflows
Hands-on experience with AWS security services such as SecurityHub, GuardDuty, IAM, Config, Control Tower, CloudWatch, and related tooling
Experience working within DevSecOps environments and CI/CD workflows, ideally in AWS-based infrastructure (bonus points for AWS certifications)
Strong scripting and automation experience (Python, Terraform, or similar), with a focus on reducing manual operational work
Experience with monitoring and logging platforms (e.g., Sumo Logic or equivalent)
Knowledge of security frameworks and standards (e.g., OWASP Top 10, ISO 27001, SOC 2)
Strong technical background in Linux and cloud-based systems
Ability to manage competing priorities and operate effectively within a collaborative team environment
Strong problem-solving and critical thinking skills, with a focus on practical, scalable solutions
Excellent communication and collaboration skills across engineering and security teams.
Benefits
We provide a robust benefits package for full-time, permanent employees, including health, dental, and vision coverage
Retirement plans with company match
Paid time off
Parental leave
Annual education & training stipend (equivalent to $1,000 in local currency)
Flexible Hybrid Working Environment: Our offices are designed to support both collaboration and flexibility. Enjoy weekly lunches, quality coffee, and regular social events.
Many locations also feature parent rooms, on-site gyms, comfortable lounges, and adaptable workstations to support your comfort and productivity.
Wellness: We care about your well-being. Team members have access to wellness workshops and events, as well as a complimentary Headspace subscription to help you stay focused, grounded, and energized.
Employee Resource Groups: Belonging is an important part of doing your best work.
Senior Application Security Engineer leading Trimble’s global SCA and SAST strategy. Embedding automated security into CI/CD pipelines across diverse technology stacks.
Sales Application Engineer advancing Intel connectivity solutions for Canadian telecom customers. Developing technical solutions, supporting design wins, and guiding telecom OEMs through the sales cycle.
Senior power systems engineer developing protection and control algorithms for GE Vernova’s grid automation products. Leading simulations, product specifications, technical guidance, and innovation.
Customer Applications Engineering intern at Nokia, a global connectivity company, maintaining network management platforms. Applying Linux, Java, scripting, and networking skills to customer infrastructure challenges.
Security Engineer securing Sentry’s application - monitoring platform through threat modeling, vulnerability management, and secure development practices. Partnering with product and engineering teams on emerging cloud and AI security challenges.
Join CIBC's Capital Markets Technology group as a Consultant, Application Development. Lead design and development of complex enterprise applications, enhancing compliance and reporting efficiency.
Senior Applications Architect needed for 1 - year hybrid contract in Toronto. Expertise in IBM Maximo, MAS 9.1, Cloud Transformation, IaC, Asset Management, and Enterprise Architecture required.