Senior Cyber Security Engineer

CAAT Pension

Toronto

Hybrid

CAD 126,000 - 157,000

Full time

12 days ago
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Total Rewards program
Pension plan
Flexible work arrangements

Job summary

CAAT Pension is seeking a Senior Cybersecurity Engineer to safeguard our IT infrastructure, applications, and data. You will lead threat detection, incident response, and vulnerability management, working with cross‑functional teams to implement robust security controls.

The role emphasizes cloud security and secure development practices across the SDLC. Ideal candidates have 8+ years of hands‑on experience, relevant computer science education, and security certifications.

Qualifications

  • Eight years of practical cybersecurity experience in areas such as Application Security, Vulnerability Management, Incident Response, and Cloud Security.
  • Degree in computer science or a related field is required.
  • Relevant security certifications (CISSP, CCSP, Security+, CEH, CompTIA Security, etc.).

Responsibilities

  • Lead security monitoring and incident response initiatives across IT infrastructure and cloud environments.
  • Develop and refine vulnerability management and patching programs.
  • Collaborate with development teams to embed secure coding practices and conduct application security testing (SAST/DAST).
  • Oversee SIEM/SOAR usage, threat detection, and incident investigations with Azure Sentinel and CrowdStrike.

Skills

Incident Response
Cloud Security
Threat Detection
Vulnerability Mgmt
Application Security
SAST & DAST
SIEM & SOAR
Security Monitoring

Education

BSc in Computer Science

Tools

Splunk Enterprise Security
Azure Cloud Security
CrowdStrike
Rapid7 InsightVM
Imperva WAF
Data Loss Prevention (DLP)
Tenable CSPM
Azure Sentinel

Job description

At CAAT, we’re passionate about what we do. And it shows! Here, you’ll find a cultural spark in everything we do – from the way we partner with members and employers, to the way we work, collaborate, and grow. It doesn’t just feel different at CAAT. It is different. We’re one of the fastest-growing pensions in the country for a reason. We challenge the status quo, making a real impact on the hundreds of employers we serve – from education institutions to major corporations and household brands. And we’re just getting started. Driven by core values and a shared purpose, we’re fierce champions for better retirement security, known for our can‑do culture where everyone plays a role in bringing our vision to life. If this sounds like a fit, we’d love you to be a part of it.

About the Role

We are seeking a Senior Cybersecurity Engineer for our Information Technology team. The Senior Cyber Security Engineer will play a critical role within the Security Operations team, responsible for safeguarding the organization’s IT infrastructure, applications, and data against cyber threats. The role requires deep expertise in security monitoring, incident response, vulnerability management, and cloud security, ensuring the organization’s security posture remains strong. The successful incumbent will bring hands‑on experience with security tools and platforms such as Splunk Enterprise Security, Azure Cloud Security, CrowdStrike, Rapid7 InsightVM, Imperva WAF, and Data Loss Prevention (DLP) solutions. They will drive proactive threat detection, incident response, and security enhancements, working closely with cross-functional teams to implement robust security measures. As the Newest Member of our Team, You’ll: Provide SME leadership to improve Cloud security posture, ensuring adherence to regulatory standards and best practices across all infrastructure and services. Deploy and manage WAF, DLP (endpoints, cloud, email), XDR/ EDR platforms, Cloud Security tools (CrowdStrike CNAPP, Tenable CSPM) and SIEM and SOAR (Azure); lead Incident Response efforts while integrating AI/ML threat detection to safeguard against evolving AI based and data‑centric risks. Partner with software engineering teams to embed secure coding, conduct application security testing (SAST & DAST), and reinforce application‑layer defenses throughout the SDLC. Manage and enhance the Vulnerability Management Program using Tenable; provide SME‑level threat intelligence to proactively track emerging vulnerabilities and drive the implementation of security patches, configuration changes, and targeted mitigations. Conduct regular risk assessments, support penetration testing (external & internal), and compliance audits to enforce adherence to industry frameworks (ISO 27001, NIST, CIS, GDPR, SOC 2), while actively supporting all security audit and regulatory requirement initiatives. Develop and continuously refine security playbooks, incident response plans, and threat‑hunting methodologies to strengthen detection capabilities and organizational resilience. Monitor, analyze, and respond to incidents via Azure Sentinel; provide SME‑level support to analysts using CrowdStrike and Azure Sentinel for advanced threat investigations, while crafting SIEM use cases tailored to the current threat landscape. Lead IR efforts—including containment, eradication, and forensic analysis—while executing a strategic vision to develop innovative approaches that accelerate threat response and remediation and continuously refine incident response plans and threat‑hunting methodologies. Harden CAAT environments against AI/ML‑based attacks; provide technical mentorship to junior security engineers and analysts; and clearly communicate security risks and mitigation strategies to stakeholders. Lead the documentation of security incidents, technical project requirements, runbooks, and standard operating procedures to institutionalize knowledge across teams as an SME. Ensure adherence to industry standards (ISO 27001, NIST, CIS, GDPR, SOC 2) and actively support security audits and regulatory compliance initiatives. Communicate security risks and mitigation strategies to stakeholders, collaborate cross‑functionally with IT, development, and operations to embed security across the organization, and manage multiple concurrent projects while applying strong analytical and problem‑solving skills, working autonomously with excellent written and verbal communication. Integrate secure coding practices into the SDLC; conduct SAST, DAST, and IAST; perform secure code reviews; and provide tailored remediation guidance to development teams. Manage WAF and related security solutions against OWASP Top 10 threats (SQLi, XSS, insecure deserialization); enforce API security (authentication, authorization, encryption) alongside OAuth, JWT, and MFA; and conduct threat modeling and risk assessments to identify application weaknesses. Embed security controls into CI/CD pipelines to automate vulnerability scanning and compliance checks; utilize SCA to track and mitigate third‑party dependency risks; implement secrets management to eliminate hardcoded credentials; and enforce zero‑trust principles across DevOps workflows. Partner with development teams as an Application Security SME to foster a security‑first culture, promoting proactive ownership of security controls throughout software development. Rapidly acquire skills in fast‑moving domains (AI, ML, Quantum); understand attacker exploit techniques and remediation methods; maintain expertise across infrastructure, network, endpoint, and mobile security; and provide technical mentorship to junior security engineers and analysts.

You Bring:
  • A minimum of eight (8) years of practical experience in various cybersecurity areas such Application Security, Vulnerability Management, Incident Response, Cloud Security.
  • A degree in the field of computer science.
  • A Relevant security certification such as CISSP, CCSP, Security+, CEH, CompTIA Security, etc.
  • Understanding of security standards and frameworks such as ISO27001, NIST and CIS, etc.
  • Strong knowledge of technical configurations from various operating systems and security solutions (Windows, Linux, Mac, IDS / IPS, DLP, SIEM, SOAR, WAF, VPNs, firewalls, encryption, etc.)
  • Excellent problem‑solving and analytical skills to identify and resolve security issues effectively.
  • Excellent understanding of MITRE ATT&CK and MITRE ATLAS frameworks.
  • Good understanding of cloud security concepts and experience securing cloud‑based infrastructure is an asset.
  • Proven project management and organizational skills, specifically managing multiple, concurrent projects.
  • Excellent written and verbal communication coupled with an ability to work with minimal supervision.
Salary

The target hiring salary for this position is $125,800 to $157,200. Placement within our salary range will be based on factors such as internal equity, market conditions, and the candidate’s experience, skills, and qualifications relevant to the role.

Benefits
  • Opportunities to Build a Better You: We never stand still. As we grow, so do you. Enjoy a place that provides endless opportunities to learn and master your skills while cultivating new ones.
  • Comprehensive & Holistic Care: Be at your best with a Total Rewards program that feeds and prioritizes your physical, mental, and financial wellness. From flexible work arrangements, comprehensive benefits to wellness incentives, and a defined benefit pension plan – we have you covered.
  • A Place to Collaborate and Win: We’ve built a lively environment where creativity and open communication thrive. It’s why we’re consistently recognized as one of ‘Canada’s Most Admired Corporate Cultures’, one of ‘Greater Toronto’s Top Employers’, and one of the ‘Best Places to Work’.
  • Work that Truly Matters. You’re giving Canadians the opportunity for better retirement security, and organizations the chance to do more.

Start your journey with us today.

Learn more about us by visiting www.caatpension.ca/careers

No artificial intelligence tools are used to screen, assess, or select applicants for this position. Artificial intelligence tools may be used to help recruiters identify potential candidates on external platforms. All hiring decisions are made by human reviewers.

Diversity, Equity, Inclusion, and Belonging (DEIB)

DEIB at CAAT means we respect and value the broadest range of experiences, geographies, gender, ethnicities, backgrounds, and perspectives as key elements of our culture. Our vision is to provide an environment where employees can bring their best, professional, authentic, selves to work. CAAT Pension Plan is an equal opportunity employer, and we will accommodate any needs under the Accessibility for Ontarians with Disabilities Act and the Ontario Human Rights Code. Hiring processes will be modified to remove barriers to accommodate those with disabilities, if requested. Should any applicant require accommodation through the application processes, please contact us at hr@caatpension.ca or call Human Resources at 416-673-9000 for assistance.

Vacancy

Vacancy: This posting is for an existing vacancy At CAAT, we live our values of integrity, impact, and teamwork every day. We cultivate a culture of collaboration and fun, through an inclusive and energetic environment where CAATsters can work, learn, and grow together. We prioritize comprehensive and holistic care for our employees, designed to cater to every aspect of your life and wellbeing. Through our Total Rewards program, we prioritize your physical, mental, and financial wellness. This includes compensation, paid time off, health and dental benefits, wellness incentives, and a defined benefit pension plan. At CAAT, we embrace growth as a way of life where opportunities for adaptation, innovation, and learning prosper in our dynamic and evolving environment. As we expand and transform, so do you. Together, we’re on a mission to secure a better financial future for Canadians.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cyber Security Engineer
Senior Cyber Security Engineer

CAAT Pension Plan • Toronto

On-site
CAD 126,000 - 157,000
Total Rewards program
Flexible work arrangements
Wellness incentives
+1
Technical Support Analyst
Technical Support Analyst

CAAT Pension • Toronto

On-site
CAD 73,000 - 86,000
Opportunities to Build a Better You
Comprehensive & Holistic Care
A Place to Collaborate and Win
+1
Application Support Analyst
Application Support Analyst

CAAT Pension • Toronto

Hybrid
CAD 73,000 - 86,000
Flexible work arrangements
Health and dental benefits
Wellness incentives
+1
Analyst, Application Portfolio & Governance
Analyst, Application Portfolio & Governance

CAAT Pension • Toronto

Hybrid
CAD 64,000 - 75,000
Career growth
Total rewards
Collaborative culture
+1
ITSM Analyst
ITSM Analyst

CAAT Pension • Toronto

Hybrid
CAD 84,000 - 99,000
Flexible work arrangements
Total Rewards program
Pension plan
+1
Senior Privacy Specialist
Senior Privacy Specialist

CAAT Pension • Toronto

On-site
CAD 97,000 - 114,000
Flexible work arrangements
Total Rewards program
Defined benefit pension plan
+1
Senior Administrative Assistant (12-Month Contract)
Senior Administrative Assistant (12-Month Contract)

CAAT Pension • Toronto

On-site
CAD 64,000 - 75,000
Competitive compensation
Total Rewards program
Growth and development opportunities
+1
ServiceNow Developer
ServiceNow Developer

CAAT Pension • Toronto

Hybrid
CAD 97,000 - 114,000
Total Rewards program
Competitive compensation
Flexible work arrangements
Pension Software Testing Analyst
Pension Software Testing Analyst

CAAT Pension • Toronto

On-site
CAD 84,000 - 99,000
Technical Support Analyst
Technical Support Analyst

CAAT Pension Plan • Toronto

On-site
CAD 73,000 - 86,000
Total Rewards program
Comprehensive benefits
Defined benefit pension