Infrastructure Security Engineer ensuring security for Yelp’s AWS and Google Cloud environments. Collaborating with security engineers to enhance cloud and corporate security posture.
Responsibilities
Design, implement, operationalize and maintain systems that ensure the security of Yelp’s AWS and Google Cloud Platform (GCP) environments, focusing on least privilege, containerization, and developer efficiency
Develop and enforce data security controls to support privacy initiatives, including data mapping and data retention
Manage system-level access controls (such as Linux, Docker, Kubernetes), and tiered access for internal digital assets, balancing strict authentication/authorization with usability
Create, extend, and monitor company-wide security standards, proactively identifying and correcting insecure usage across Yelp
Develop and operationalize telemetry, reporting, and alerting systems to collect and analyze security-related data
Conduct timely vulnerability identification, assessment, and remediation across Yelp’s infrastructure, applications, and services
Participate in a robust on-call rotation, respond to security incidents, and contribute to proactive threat modeling and system reviews
Mentor other engineers passing on your skills, and serve as a resource in our #security Slack channel by promoting best practices and offering your expertise across the organization.
Requirements
Experience building secure, scalable, and distributed cloud environments (preferably on AWS and GCP)
Familiarity with modern access controls and authentication mechanisms (Linux, Docker, Kubernetes, IAM, etc.)
Proficient in at least one programming language (e.g., Python, Java, JavaScript, C) and in designing well-structured APIs
Passion for automation to streamline security policy enforcement, detection, and response
Strong analytical skills and a proactive approach to vulnerability assessment and threat modeling
Effective communicator, able to collaborate across diverse teams and provide security guidance in a constructive, approachable manner
Committed to continuous learning, knowledge sharing, and staying current with evolving security trends.
Lead agentic AI cybersecurity initiatives, building automated vulnerability discovery and remediation pipelines. Requires deep expertise in offensive security, software engineering, and AI tools.
Security director at Intact, an insurer, protecting customer and broker digital channels and third - party risk platforms. Leading technical teams, governance, strategy, and security operations.
Information Security Advisor conducting cyber - risk assessments and contract reviews for Sun Life, a global financial - services company. Advising business and technology teams on security controls, compliance, and risk remediation.
Enterprise Security Architect securing technology for Vancity, a member - owned Canadian credit union. Designing enterprise application security frameworks, controls, and risk - based cybersecurity solutions.
Director leading IT and cybersecurity operations for the Azrieli Foundation, a Canadian philanthropic organization. Assessing technology risks, overseeing infrastructure, vendors, incident response and executive technology strategy.
Data Security Specialist protecting Sun Life’s financial - services data through DLP, CASB and insider - threat programs. Investigating cyber risks and advancing enterprise data protection.
Senior SaaS Security Manager protecting RBC’s banking platform from third - party cloud risks. Leading controls, vulnerability management, compliance, and security transformation initiatives.