- Collaborate with the infrastructure, cloud, and application teams to integrate security controls into EDC's technology stack
- Identify security gaps and vulnerabilities, prioritize remediation measures, and develop tactical plans
- Design and implement security and automation tools and hardening standards
- Contribute to threat modeling, security architecture reviews, and assessments of emerging technologies
- Monitor the threat landscape and develop actionable improvements
- Act as a security partner to agile and delivery teams throughout design, development, and deployment
- Conduct security reviews of project documentation, architecture diagrams, code changes, and configuration decisions
- Promote secure-by-default practices, DevSecOps, and a shift-left approach
- Design and maintain reusable security standards, guidelines, and templates
- Advise engineering and product stakeholders and translate security risks into business language
- Assess security risks associated with AI and machine learning workloads
- Support EDC's AI security approach through risk assessments, security reviews, and governance feedback
- Use AI and machine learning to improve security operations, including anomaly detection, threat hunting, and alert triage
- Explore and evaluate AI-assisted security tools
- Collaborate with stakeholders to align security practices with EDC's strategic objectives and 2030 roadmap
- Communicate complex security concepts to technical and non-technical audiences
- Contribute to key performance indicators and metrics tracking the progress of the security posture
- Contribute to continuous improvement initiatives and the evolution of the security program
Requirements
- Postsecondary degree in computer science, information security, engineering, or a related field, combined with equivalent practical experience
- At least 7 years of hands-on experience in cybersecurity engineering, application or cloud security, or a similar technical role
- Extensive, demonstrated experience across multiple security domains, such as application, cloud, network, or endpoint security, identity, data protection, or vulnerability management
- Expertise in several areas of security and working knowledge of others
- Experience integrating security into software development life cycle processes, continuous integration and continuous delivery practices, and agile workflows
- Strong cloud security expertise, preferably with Azure; experience with AWS and GCP is also recognized
- Hands-on experience with a broad range of security tools, including SIEM, vulnerability management, SAST, DAST, secrets management, identity platforms, endpoint security, and cloud security tools
- Knowledge of AI and machine learning security considerations
- Experience with AI security, including hands-on work, architecture reviews, governance, risk assessment, proof-of-concept development, or collaboration with AI platform teams
- Excellent communication skills and the ability to translate security risks into business language
- Collaborative, curious, comfortable with ambiguity, and able to work independently
- CISSP, CCSP, CEH, OSCP, Azure Security specialization, Microsoft professional certifications, or equivalent certifications are considered an asset
- Experience with AI and machine learning platforms, large language models, or analytics and data science pipelines is considered an asset
- Experience with Copilot Studio, Databricks, AI embedded in SaaS, or similar AI services is considered an asset
- Knowledge of Salesforce, ServiceNow, and other SaaS security models is considered an asset
- Knowledge of Canadian compliance and regulatory frameworks applicable to federal Crown corporations is considered an asset
- Experience writing scripts and coding with Python, PowerShell, or Bash is considered an asset
- Fluency in both official languages, English and French, is considered an asset
- Preference will be given to candidates legally authorized to work in Canada at the time of application
- Candidates must meet government security requirements
Core Competencies
Demonstrates expertise in cybersecurity engineering with a focus on application and cloud security, integrating security into the software development life cycle, and utilizing AI and machine learning for security operations. Strong communication skills are essential for translating complex security concepts into business language and collaborating with diverse teams.
Highest-signal resume keywords
- Cybersecurity Engineering
- Cloud Security Expertise
- AI Security Experience
- Security Tools Proficiency
- Communication Skills
ATS Optimization Keywords
Hard Skills
- Cybersecurity Engineering
- Application Security
- Cloud Security
- Vulnerability Management
- Security Automation
- Threat Modeling
- Security Architecture Reviews
- Scripting with Python
- Scripting with PowerShell
- Scripting with Bash
Soft Skills
- Excellent Communication
- Collaborative
- Curious
- Comfortable with Ambiguity
- Independent Work
Certifications & Qualifications
- CISSP
- CCSP
- CEH
- OSCP
- Azure Security Specialization
- Microsoft Professional Certifications
Industry Keywords
- DevSecOps
- Shift-Left Approach
- Canadian Compliance
- Regulatory Frameworks
- AI and Machine Learning Security
Tools & Technologies
- SIEM
- Vulnerability Management Tools
- SAST
- DAST
- Identity Platforms
- Endpoint Security Tools
- Cloud Security Tools
- AI Platforms
- Databricks
- Salesforce