More jobs:
Senior Information Security Specialist (Cloud Security
Job in
Vaughan, Ontario, Canada
Listed on 2026-08-23
Listing for:
Martinrea International
Full Time
position Listed on 2026-08-23
Job specializations:
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Cloud Computing: Infrastructure & Operations, Systems Engineer
Job Description & How to Apply Below
Job Summary:
Senior Information Security Cloud Specialist with 8–10+ years of experience, deep multi-cloud expertise (AWS + Azure), and the ability to drive technical strategy across an IT, Cybersecurity, and other business units. The Senior Specialist will act as Dev Sec Ops lead on security-related projects and technologies and ensure the effective implementation and management of security tools as we continue to improve information security Security Specialist will be responsible for providing daily support, IR, and on-call rotation.
RequiredEducation and Experience:
- Bachelor’s degree in Information Security, Cyber Security, Computer Science, or equivalent
- 10+ years of working experience in support of a large-scale, mission-critical enterprise security infrastructure
- 5+ years of previous experience in Sec Ops, Dev Sec Ops , Cloud Security, Threat Detection & Response, or software development with a strong focus on security tool onboarding and optimization
- 5+ years of working experience with security tools and technology (Defender, Intune, IAM, Vulnerability Management, DLP, and others)
- Deep subject matter expertise with security engineering best practices for subjects such as CVSS, EPSS.
- Design, implement, and maintain security measures for our cloud infrastructure, including VPCs, security groups, IAM roles, and access controls
- Expertise across AWS and Azure security
- Experience with CSPM/CNAPP platforms (Wiz, Crowd Strike, Defender, etc.)
- Experience with AI/ML platforms and cloud-based AI services
- Expert in cloud-native security controls (IAM, KMS, VPC security, encryption, logging, and monitoring).
- 5+ years of experience with MS O365, Azure security, MFA, and MDM are a must
- Deep knowledge and experience with Email Security
- Stay current with cloud security trends, emerging threats, and best practices, ensuring configuration guidance remains accurate and relevant
- Knowledge of security industry standards and certification frameworks such as ISO 27001, SOC2, CSA CCM, NIST, PCI DSS, etc.
- Preferred to have: CCSP, Azure Security Engineer, AWS Security Specialty, and CISSP
Essential Functions:
- Lead CNAPP architecture & rollout across multi-cloud and Hybrid solutions, including integration patterns and operationalization design.
- Perform security assessments and audits of our infrastructure, identifying and mitigating security gaps and weaknesses
- Implement and maintain security controls across AWS/Azure, focusing on EKS/AKS cluster security, EC2 hardening, and cloud-native protection
- Investigate potential security incidents and serve as the initial incident responder
- Harden our cloud-native environments (AWS, Azure) by introducing secure‑by‑default designs and features into network, tooling, and processes
- Drive the design and implementation of Zero Trust architectures, including identity‑based perimeters, mTLS, network segmentation, and least‑privilege access controls
- Monitor and analyze logs, events, and metrics to identify security incidents, potential breaches, and emerging threats
- Represent Dev Sec Ops to leadership, audit (internal and external), and regulators on technical questions
- Define and publish Security Reference Architectures and reusable patterns (secure‑by‑design) for engineering adoption across platforms and products. Partner with platform engineering / Dev Sec Ops teams to integrate scanning and controls into CI/CD (e.g., Terraform Cloud, Git Hub Actions, Azure Dev Ops), including risk decisions and exceptions
- Embed security into the full software development lifecycle through scalable guardrails, automated testing frameworks, and developer‑facing documentation.
- Develop required documentation to help operationalize and automate technologies in close coordination with security operations to ensure compliance requirements are met
- Continuously identify areas needing improvement, create action plans, and execute to implement changes on time
- Hybrid (3 days in Office)
- Constant communication with employees, peers, and leadership
- Overtime as required
- This job description is not designed to contain a comprehensive list of duties and responsibilities required for this job. Duties and responsibilities may change at any time with or without notice
This job description does not constitute a contract of employment. The Company may exercise its employment at will right at any time.
#J-18808-LjbffrPosition Requirements
10+ Years
work experience
Note that applications are not being accepted from your jurisdiction for this job currently via this jobsite. Candidate preferences are the decision of the Employer or Recruiting Agent, and are controlled by them alone.
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
To Search, View & Apply for jobs on this site that accept applications from your location or country, tap here to make a Search:
Search for further Jobs Here:
×