Senior Cloud Security Engineer, Information Security

Peoples Group

Vancouver

Hybrid

CAD 150,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Hybrid work environment
Competitive salary
Profit sharing

Job summary

Peoples Group is seeking a Senior DevSecOps Engineer to lead security strategy across AWS and Azure, drive IaC and automation, and partner with leadership on risk and regulatory compliance. The role blends hands‑on engineering with architecture, threat modeling, and vendor evaluation, in a hybrid, office‑based and remote work environment.

You will mentor engineers, own critical security workstreams, and contribute to a resilient security program within a regulated financial institution.

Qualifications

  • 8–10+ years of DevSecOps/security engineering experience.
  • Deep multi-cloud expertise (AWS + Azure) and Terraform.
  • Experience with regulated financial institutions and security strategy.

Responsibilities

  • Define and drive DevSecOps strategy across CI/CD, IaC, and compliance automation.
  • Lead security tooling evaluations and architecture decisions with engineering leadership.
  • Architect and build complex IaC pipelines and cross‑cloud detection fabric.
  • Own threat modeling, SOC 2/PCI‑DSS evidence, and regulator interactions.
  • Mentor junior engineers and disseminate CI/CD best practices.
  • Publish security patterns and ensure on‑call readiness.

Skills

Leadership
Mentoring
Strategic thinking
Regulatory compliance
Cross-functional collaboration

Tools

Terraform
AWS
Azure

Job description

We are hiring for this position out of our Toronto, Vancouver and Calgary offices. Successful candidates who apply outside of these areas will be expected to relocate and reside in a location that is within a commutable distance.

About The Role

We’re hiring a Senior DevSecOps Engineer with 8–10+ years of experience, deep multi‑cloud expertise (AWS + Azure), strong Terraform and the ability to drive technical strategy across a regulated financial institution. This is a senior individual contributor role. You’ll set technical direction for DevSecOps, partner with the AVP of Corporate Information Security on strategy, mentor and grow the team, and personally own the hardest pieces of work. You’ll be a primary point of contact for engineering leadership, audit, and external regulators when DevSecOps topics come up.

Day‑to‑day Responsibilities
Technical leadership and strategy (~30%)
  • Build and evolve the DevSecOps technical strategy across CI/CD, IaC, secure cloud architecture, detection, and compliance automation.
  • Partner with the AVP of Corporate Information Security and the Team Lead, DevSecOps, on the security roadmap; translate risk decisions into engineering work.
  • Collaborate on architecture decisions and ADRs for the DevSecOps platform. Champion paved roads and golden paths over one‑off solutions.
  • Lead vendor evaluations and POCs for security tooling. Make the build‑vs‑buy argument with the data to back it up.
  • Develop and maintain a Security Centre of Excellence for all new products and substantial changes, ensuring security requirements are met before they reach production.
  • Represent DevSecOps to engineering leadership, audit (internal and external), and regulators on technical questions.
Hands‑on engineering (~40%)
  • Personally architect and build the hardest pieces: the IaC pipeline that gates all production change, the cross‑cloud detection fabric, the SBOM/supply‑chain integrity program, the secrets management migration.
  • Drive the AWS‑to‑Azure migration of applications as a senior security engineering owner: design target‑state controls in Azure, run gap analysis against AWS, validate equivalence before workload cutover.
  • Architect and review Terraform at scale: module strategy, state isolation, workspace patterns, drift detection, breaking‑change management.
  • Implement and operate policy‑as‑code across the SDLC: PR‑time, pipeline‑time, deploy‑time, and runtime enforcement.
  • Lead implementation of supply‑chain security: signed builds (Sigstore/cosign), SBOM generation and storage, SLSA‑aligned provenance, dependency pinning, runner isolation.
  • Integrate, monitor, and tune SAST/DAST platforms across CI/CD pipelines.
  • Build out Zero Trust patterns: workload identity federation, conditional access, just‑in‑time access and microsegmentation.
  • Publish and disseminate CI/CD best practices, patterns, and solutions across product engineering teams.
Compliance, audit, and risk (~20%)
  • Own the threat‑modeling program: set the methodology (STRIDE, LINDDUN, attack‑tree, MITRE ATT&CK‑mapped), train others on it, and ensure outputs become real backlog items.
  • Be an engineering owner of control evidence for SOC 2, PCI‑DSS and applicable Canadian regulatory expectations.
  • Automate audit evidence collection wherever feasible: replace screenshot‑based evidence with API‑pulled, signed, dated artifacts.
  • Contribute to the cybersecurity risk register and risk treatment plans; partner with GRC and Operational Risk Management.
  • Make the case to regulators and auditors that controls are designed effectively and operating effectively.
  • Stay current on emerging threats and regulatory changes in cloud security, AI, and automation; apply innovative solutions to enhance the security framework.
People and team (~10%)
  • Mentor Intermediate and Junior DevSecOps engineers: set development goals, do code reviews that teach, sponsor stretch projects.
  • Build the team's documentation and onboarding so it scales with hires.
  • Contribute to a healthy on‑call culture: sustainable rotations, blameless retros, runbook quality.
Nice To Have / Differentiators
  • Canadian regulated financial services experience (banking, trust company, credit union, fintech sponsor bank).
  • Active certifications: CISSP, CCSP, OSCP/CPTS, AWS Security Specialty, Azure SC‑100, AZ‑500, AZ‑400, CKS, HashiCorp Terraform Associate/Pro.
  • Prior Security Centre of Excellence experience: stood one up or served as the lead engineer inside one.
  • Supply‑chain security: Sigstore, in‑toto, SLSA, SBOM (CycloneDX/SPDX), Dependency Track.
  • Offensive security background: OSCP, real red‑team/purple‑team engagements, CTF placement.
  • AI/LLM security experience: secure agent design, prompt‑injection defenses, model supply‑chain integrity.
About The Work Environment

Peoples Group offers a flexible and hybrid work environment. In this role you will work a combination of in‑office and remotely from home. Typically, you’ll be working regular business hours, Monday to Friday between 8:00 am and 4:30 pm with flexibility around start/end times.

The role requires the candidate to participate in on‑call, acting as an escalation path in the event of a severe incident.

We Offer
  • A hybrid work environment, enabling you to balance your personal and professional life seamlessly.
  • Competitive salaries, profit sharing, RRSP matching and benefits from day one.
  • Generous paid time off to help achieve a healthy work‑life balance.
  • A strengths‑based approach, ensuring we work together more effectively.
  • A commitment to your well‑being in five key areas: Financial, Physical, Social, Career, and Community.

Peoples Group is an Equal Employment Opportunity employer. Please accept our utmost appreciation for your interest; however, only those applicants under consideration will be contacted.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Calgary

Hybrid
CAD 140,000 - 190,000
Hybrid work environment
Profit sharing
RRSP matching
+2
Senior Cloud Security Engineer, Information Security
Senior Cloud Security Engineer, Information Security

Peoples Group • Toronto

Hybrid
CAD 140,000 - 180,000
Senior Cloud Security Developer (Global Security)
Senior Cloud Security Developer (Global Security)

United States Digital Space LLC • Toronto

On-site
CAD 120,000 - 180,000
Bonuses
Flexible benefits
Stock options
+2
Senior Security Engineer
Senior Security Engineer

EQ Bank | Equitable Bank • Toronto

Hybrid
CAD 100,000 - 140,000
Competitive discretionary bonus
Market-leading RRSP match program
Medical, dental, vision, life, and disability benefits
+3
Senior Cloud Security Engineer ( Global Security)
Senior Cloud Security Engineer ( Global Security)

United States Digital Space LLC • Toronto

On-site
CAD 120,000 - 180,000
Senior Security Engineer
Senior Security Engineer

Quantum Technology Recruiting Inc. (QTR) • Toronto

Hybrid
CAD 125,000 - 135,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Scotiabank • Toronto

On-site
CAD 100,000 - 120,000
Diversity and Inclusion program
Tuition assistance
Competitive Rewards program
Senior Security Engineer
Senior Security Engineer

fispan • Vancouver

On-site
CAD 130,000 - 160,000
Extended health and dental benefits
Paid time off
Savings and retirement plan matching
+5
Enterprise Security Specialist
Enterprise Security Specialist

Cprvision • Whitchurch-Stouffville

Hybrid
CAD 120,000 - 135,000
Flexible working arrangements
Comprehensive benefits package
Annual bonus program
+1
Cloud Security Engineer
Cloud Security Engineer

Scotiabank • Toronto

On-site
Competitive rewards program
Tuition assistance
Flexible vacation
+1