Enable job alerts via email!

Information Security Engineer

Dentons

Toronto

On-site

CAD 80,000 - 110,000

Full time

12 days ago

Boost your interview chances

Create a job specific, tailored resume for higher success rate.

Job summary

An established industry player is seeking an Information Security Engineer to enhance its security posture and protect vital information assets. This role involves implementing and improving security controls across cloud and on-premise environments, particularly focusing on Microsoft 365 and Azure. The ideal candidate will have a strong background in cybersecurity, with expertise in vulnerability management and incident response. Join a forward-thinking organization that values innovation and offers a comprehensive benefits package, including wellness programs and professional development opportunities. This is your chance to make a significant impact in the realm of information security while growing your career in a dynamic environment.

Benefits

Comprehensive health benefits
Mental health plans
Paid time off
Fitness subsidy
Parental leave top-up
Professional development programs

Qualifications

  • 6+ years in IT with focus on cybersecurity solutions.
  • Experience in cloud technologies and penetration testing.

Responsibilities

  • Implement and maintain security posture of Microsoft 365.
  • Conduct vulnerability assessments and manage security incidents.

Skills

Microsoft 365 Security
Azure Security
Vulnerability Management
Incident Management
Technical Architecture Assessment
Stakeholder Management
Communication Skills
Problem Solving

Education

Post-secondary education in Information Technology
Relevant certifications (CISSP, CISM)

Tools

Azure
CIS
NIST
ISO 27001

Job description

Join to apply for the Information Security Engineer role at Dentons

1 week ago Be among the first 25 applicants

Join to apply for the Information Security Engineer role at Dentons

Dentons Canada LLP is currently recruiting for an Information Security Engineer who will be responsible for ensuring the security, integrity, and availability of Dentons Canada information assets. The candidate will contribute to the management and continuous improvement of multiple security programs. The position entails the development, implementation, and maintenance of security controls, through people, processes, and technology, across the organization.

KEY RESPONSIBILITIES & ACCOUNTABILITIES

General

  • Implement, maintain, and improve the security posture of the Microsoft 365.
  • Maintain operational oversight of our security systems and administer secure configurations for both on-premise and cloud environments.
  • Proactively manage system settings to counter evolving threats and safeguard enterprise systems and accounts.
  • Actively monitor and assess new and emerging security threats. Recommend tactical and strategic initiatives that mitigate risks and keep our security posture ahead of the curve.
  • Prepare and deliver periodic reports that highlight the current security posture of our Information Security Program.
  • Ensure that all systems and processes comply with industry-recognized frameworks such as ISO 27001, NIST, CIS, and internal policies.
  • Collaborate with IT Infrastructure, Operations, and other stakeholders to design and maintain secure, resilient enterprise-grade processes.
  • Ensure that security requirements are integrated into IT services, balancing operational needs with risk management.
  • Support regional internal and external audits related to IT security and compliance.
  • Work with business services to ensure that security measures are effectively represented in client RFP responses and align with global standards.
  • Contribute to the development, evaluation, and implementation of policies, standards, and procedures that meet both business and security requirements.
  • Continuously refine technical processes to address the latest threats and compliance mandates.

Security Engineering

  • Conduct technical architecture assessments to identify and mitigate risks.
  • Translate business requirements into robust technical security controls.
  • Develop, implement and maintain cloud security architectures, ensuring operational compliance (Azure expertise is a must).
  • Leverage advanced Azure security features to architect and secure cloud deployments, ensuring compliance with best practices and regulatory standards.
  • Author technical policies and develop SOPs to support secure architectural practices, with a focus on Azure and hybrid environments.
  • Oversee patch deployment and secure configuration baselines for on-premise and cloud environments (Virtual Machines and Operating Systems).
  • Ensure timely updates while minimizing downtime and risk.
  • Perform regular audits (e.g., CIS, asset management, firewall rule review) to ensure compliance with internal policies and industry best practices.
  • Conduct regular reviews and annual audits of firewall rules to ensure compliance with security policies, identify potential risks, and maintain optimal network protection.
  • Provide recommendations to address audit findings and improve security controls.
  • Develop and maintain secure configuration baselines for servers, endpoints, and network devices.
  • Continuously monitor and remediate configuration drift.
  • Manage and enhance privilege access controls, focusing on SecretServer or similar PAM solutions.
  • Enforce least-privilege principles and monitor privileged accounts.
  • Coordinate internal and external penetration testing efforts.
  • Analyze results, prioritize remediation activities, and track corrective actions to closure.

Vulnerability Management Program

  • Analyze threat and vulnerability feeds data for applicability to the environment and perform compensating controls analysis and validate efficacy of existing controls and provide recommendations.
  • Perform security research, analysis, assessments and support with penetration testing and remediation actions.
  • Conduct vulnerability assessments to evaluate attack vectors, identify vulnerabilities, and develop remediation plans.
  • Work with IT stakeholders to guide and assist them during the remediation process.
  • Monitor external security ratings and coordinate improvement efforts.
  • Identify and address high-risk areas to strengthen overall security posture.
  • Lead monthly vulnerability management meetings, assessments, and remediation coordination.
  • Develop metrics and dashboards to track progress and highlight key risk areas.

Security Operations and Incident Management Program

  • Assist the SOC team with daily operation of Information Security technologies.
  • Assist with creating detailed runbooks and playbooks for incident response that integrate engineered solutions with operational procedures, ensuring quick and consistent responses to security events.
  • Offer expert insights during and after incidents to identify root causes, recommend immediate fixes, and suggest long-term security improvements to prevent recurrence.
  • Work closely with the security operations team to ensure that engineered systems meet operational needs, participate in incident drills, and provide training on new tools or technologies that enhance incident response capabilities.
  • Handle spam/phishing requests, Mimecast URL exceptions, and data loss alerts.
  • Act as an active participant within Incident Tabletop exercise.

SKILLS & COMPETENCIES

  • Strong written and oral communication skills.
  • Strong stakeholder management skills and experience.
  • Strong organizational skills with impeccable attention to detail.
  • Strong situational analysis and decision-making skills, with experience balancing technical trade-offs.
  • Demonstrates how to Act as One by being a team player across the Firm.
  • Strong problem solving and analytical skills; can clearly explain and present problems and issues to others and contribute to their resolution.
  • Ability to work under pressure and think clearly in challenging situations in a logical manner.
  • Ability to be flexible in approach and be comfortable with a fluid organizational structure that requires both teamwork and self-sufficiency as necessary, with the ability to work under minimal supervision.
  • Demonstrate initiative and the ability to be proactive, anticipating needs.
  • Flexibility to accommodate working in multiple time zones.

EDUCATION, EXPERIENCE & CERTIFICATIONS

  • Post-secondary education with a specialization in Information Technology and / or minimum of 6+ years of Information Technology experience in designing, developing, and maintaining IT cybersecurity solutions
  • 6+ years of experience in an Information Security related role with at least 3 years of experience in cloud technologies, vulnerability and penetration testing.
  • Advanced knowledge of Azure security features, architecture, and best practices for securing cloud deployments.
  • Expertise in deploying patches and maintaining secure configuration baselines across on-premise and cloud environments.
  • Proficient in coordinating and executing both internal and external vulnerability assessments and penetration tests.
  • Experience in designing secure systems, conducting technical assessments, and translating business requirements into robust security controls.
  • Knowledge in developing secure cloud security architectures.
  • Competence in auditing systems against defined standards (e.g., CIS, NIST, ISO 27001) and preparing compliance reports.
  • Familiarity with ITSM processes for ticket handling and incident response, including developing runbooks and incident playbooks.
  • At least one relevant certification such as CISSP, CISM, or from GIAC/ISACA is required.

We thank all applicants for their interest, however, only those selected for an interview will be contacted.

At Dentons we are committed to offering equitable and competitive pay, we achieve this by aligning internal salary ranges for specific roles to similar positions in the external market. In the normal course, our practice is to hire, transfer and promote employees within the entry part of our range, adjusting as needed based on the prior experience, skills and competencies required for the role along with any market differentials.

Recognizing our exceptional talent means providing a comprehensive total rewards package beyond a competitive salary. We have curated our employee benefits portfolio to offer inclusive and comprehensive wellbeing and developmental programs for our people. With extended benefits and mental health plans, paid time off, savings plans, fitness subsidy, parental leave top up and more, our benefits are flexible, aligned to our core values and supports the various needs of our people. Additionally, our personal and professional development programs include people networks, mentorships, and leadership series programming to help people grow their career.

Note: Availability of the benefits and perks may be subject to your location and employment type and may have certain eligibility requirements. Dentons reserves the right to alter these programs and offerings in whole or in part at any time without advance notice.

Seniority level
  • Seniority level
    Mid-Senior level
Employment type
  • Employment type
    Full-time
Job function
  • Job function
    Information Technology
  • Industries
    Law Practice

Referrals increase your chances of interviewing at Dentons by 2x

Get notified about new Information Security Engineer jobs in Toronto, Ontario, Canada.

Senior Information Security Analyst - Technology Controls Officer
Information Systems Security Engineer (ISSE)
Cyber Security Co-op/ Intern (Fall 2025)
Senior Information Security Engineer-R-245220
Senior Information Security and Compliance Manager
Lead, Security Architecture & Engineering, Information & Corporate Security (12-month contract)
Cloud Security Engineer, Deloitte Global Technology
Information Security Specialist ( Cloud DevSecOps Engineer)

We’re unlocking community knowledge in a new way. Experts add insights directly into each article, started with the help of AI.

Get your free, confidential resume review.
or drag and drop a PDF, DOC, DOCX, ODT, or PAGES file up to 5MB.

Similar jobs

Senior Network Security Engineer

Carrier Refrigeration

Greater Toronto Area

Remote

CAD 80,000 - 120,000

6 days ago
Be an early applicant

Information Security Engineer

Verra Mobility

Remote

CAD 70,000 - 110,000

4 days ago
Be an early applicant

Information Security Engineer

Verra Mobility

Toronto

On-site

CAD 70,000 - 95,000

Yesterday
Be an early applicant

Information Security Engineer

Tata Consultancy Services

Toronto

On-site

CAD 70,000 - 110,000

Today
Be an early applicant

Information Security Engineer

TTEC

London

Remote

CAD 84,000 - 84,000

11 days ago

Information Security Engineer

Verra Mobility

Toronto

On-site

CAD 70,000 - 110,000

3 days ago
Be an early applicant

Staff Product Security Engineer

Affirm

Oshawa

Remote

CAD 80,000 - 110,000

Yesterday
Be an early applicant

Information Security Engineer, Senior

Zebra Technologies

Mississauga

Hybrid

CAD 80,000 - 110,000

4 days ago
Be an early applicant

Senior Information Security Engineer

Mastercard

Old Toronto

On-site

CAD 80,000 - 120,000

11 days ago