Cyber Secruity Engineer
Listed on 2026-10-01
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Cloud Computing: Infrastructure & Operations, Network Security
Yes
- Open and available immediately Company Description
For over years, Lorex has been creating security systems designed to protect your home and business. Founded and headquartered in Canada, we’ve grown to become leaders in DIY (Do It Yourself) security, offering premium solutions built on innovation, reliability, and expertise that enhance your lifestyle and protect what matters most.
Job SummaryThe Cyber Security Engineer is a key member of the Cloud Technology & Security team, reporting to the Director of the department. You will own the day-to-day security of Lorex's cloud environment — vulnerability and patch management, software supply-chain/SBOM tracking, and incident response — while supporting SOC2 audit evidence and secure design reviews led by the broader security function. This is a hands-on, build-and-fix role: you'll be the one implementing and automating the controls that keep the cloud stack secure, not just reporting on gaps.
In addition to security, you should be comfortable with privacy considerations, as privacy goes hand in hand with security, though you are not required to be a subject-matter expert.
- Own vulnerability scanning of cloud infrastructure and services (AWS/GCP), and drive remediation to agreed SLAs
- Build and maintain Software Bill of Materials (SBOM) generation and dependency/CVE triage across services; extend existing dependency-scanning coverage to services that don't yet have it
- Implement and validate secure cloud configurations (IAM, network segmentation, encryption at rest/in transit, logging and monitoring)
- Manage patch cadence across cloud infrastructure and CI/CD pipelines; track and report on remediation status
- Build, maintain, and run the incident response process — detection, containment, eradication, recovery, and post-incident review
- Act as first responder for security incidents; escalated per the defined chain
- Monitor infrastructure, security reports, and vulnerability assessments to identify threats or weaknesses
- Collaborate with software development, Dev Ops, and engineering teams to integrate security requirements and testing into the delivery pipeline
- Support SOC2 audit cycles — evidence-gathering, control testing, and remediation tracking for identified gaps
- Support Threat and Risk Assessments (TRAs) on Lorex products and services
- Partner with engineering teams to provide secure design and deployment guidance for new cloud services
- Undergraduate degree in Information Security, Computer Science/Engineering, or related field (or equivalent hands-on experience)
- 3-5 years of hands-on experience in information security engineering, with a focus on cloud environments
- Solid technical expertise in vulnerability management, patch management, cloud security controls (IAM, network security, encryption), and incident response
- Experience building/maintaining SBOM tooling (e.g., CycloneDX, SPDX) and dependency/SCA scanning (e.g., Dependabot, Snyk, npm audit)
- Experience implementing security controls in cloud environments (AWS and/or GCP)
- Experience supporting a SOC2 (Type I or II) audit cycle
- Working knowledge of monitoring/logging tooling (e.g., Cloud Trail, Guard Duty, or equivalent)
- Comfortable scripting/automating (Python, Bash, or similar) for scanning, reporting, and patch tracking
- Ability to work independently, with strong problem-solving and analytical skills
- All prospective employees must pass a background check
- AWS Certified Security
- Specialty, GCP Professional Cloud Security Engineer, CISSP, CISA, or CCSK - Exposure to mobile app (iOS/Android) or embedded/IoT device security
- SIEM or endpoint-protection tooling experience
- Experience with surveillance, video, or real-time communications products
Lorex welcomes and encourages applications from people with disabilities. Accommodations are available on request for candidates taking part in all aspects of the selection process.
Please note that we use AI tools as part of our recruitment process to enhance efficiency and improve candidate experience.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).