Senior Platform Engineer

Gerber Collision & Glass

Burlington

On-site

CAD 130,000 - 150,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Annual Paid Time Off
401(k) Retirement Plan with company 50
Employer Paid Short‑Term Disability

Job summary

Gerber Collision & Glass is seeking a Platform Engineer to strengthen cloud security foundations across AWS and Azure, designing and implementing secure patterns, automation, and governance. You will translate roadmaps into deployable standards and collaborate with Infrastructure Architecture on target designs.

This hands-on role focuses on Terraform, Python/PowerShell, and CI/CD security in GitLab, with on‑call escalation for platform issues and a bias toward secure-by-default configurations

Qualifications

  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or related field.
  • 5+ years in platform/cloud security engineering and enterprise environments.
  • Experience designing security platforms with target-state roadmaps.
  • Strong AWS security engineering experience (Control Tower/Organizations).
  • CI/CD security and policy enforcement in pipelines and PR workflows.
  • Terraform automation and Python/PowerShell scripting.

Responsibilities

  • Build and evolve cloud foundations in AWS Control Tower with baseline standards.
  • Enforce least-privilege patterns and secure administration workflows.
  • Improve service/API security and secure service-to-service access patterns.
  • Implement cloud network security and centralized egress/inspection where appropriate.
  • Design security‑as‑code and policy‑as‑code in GitLab CI/CD.
  • Standardize secure delivery patterns with Terraform modules and templates.
  • Manage privileged access and secrets platforms (CyberArk, PAM/EPM).
  • Provide continuous controls monitoring outputs and audit-ready configurations.
  • Maintain platform design docs and drive targeted improvement efforts.

Skills

Cloud security engineering
Platform engineering
Terraform
Python
PowerShell
GitLab CI/CD
AWS security
Azure experience
Security automation
Least privilege

Education

Bachelor's degree in Computer Science or related field

Tools

CyberArk
Delinea / BeyondTrust
GitLab

Job description

Job Description

The Platform Engineer serves as a senior technical resource responsible for strengthening cloud security foundations across AWS and Azure through preventive controls, secure network architecture, and CI/CD enforcement. This role is highly hands‑on and designs and implements security platforms in collaboration with Infrastructure Architecture, translating agreed designs and roadmaps into deployable technical standards, automation (Terraform, Python/PowerShell), and operationalized platform capabilities. Limited on‑call expectations focus on escalation for platform‑level issues.

Key Job Responsibilities
Cloud Foundations
  • Build and evolve cloud foundations in AWS Control Tower, including baseline standards for account structure, preventive cloud controls, and secure‑by‑default patterns.
  • Reduce privilege escalation paths by defining and enforcing least‑privilege patterns, privileged role boundaries, and secure administrative workflows for cloud operations and automation.
  • Improve service/API security through standard patterns for workload/service identities, credential handling, and secure service‑to‑service access with application and platform teams.
  • Reduce lateral movement risk by implementing cloud network security architecture patterns (segmentation, controlled east‑west paths, and a centralized egress/inspection approach where appropriate).
  • Collaborate with the Infrastructure Architect on target designs and multi‑quarter roadmaps; implement approved designs through standards, automation, and platform changes.
CI/CD Engineering
  • Design and implement security‑as‑code and policy‑as‑code enforcement in GitLab CI/CD for infrastructure and access changes, focusing on preventing high‑risk IAM and network patterns from being deployed.
  • Standardize secure delivery patterns through reusable pipeline templates/components and Terraform module conventions (PR‑based change control, reviewable outputs).
  • Secure CI/CD automation identities and secrets usage patterns in pipelines (permissions, separation of duties, and safe credential handling).
  • Drive adoption across engineering teams by providing clear patterns, documentation, and reference implementations.
Privileged Access & Secrets Platforms
  • Design, implement, and own CyberArk across PAM, EPM, and Secrets Hub: onboarding patterns, access models, rotation workflows, elevation policies, privileged workflows, and platform automation.
  • Maintain and improve the current MFA/SSO platform as required and support rationalization/consolidation toward the target platform strategy over time.
  • Provide standardized privileged access and secrets usage patterns that directly support cloud and CI/CD security objectives (automation identities, break‑glass approach, service credential patterns).
Continuous Controls Monitoring & Audit Support
  • Establish continuous controls monitoring outcomes for cloud and platform controls (control validation, exception identification, and standardized reporting outputs).
  • Provide and maintain security configurations and audit‑ready outputs for control reviews (cloud controls, CI/CD enforcement controls, privileged access controls), coordinating with control owners as needed.
  • Translate security requirements into deployable technical standards implemented through established change processes.
Continuous Improvement
  • Maintain documentation for platform designs, standards, CI/CD enforcement, privileged access workflows, and operational procedures.
  • Identify control gaps and operational inefficiencies and propose/implement targeted improvements.
  • Incorporate lessons learned from incidents, changes, and platform issues into standards, automation, and runbooks.
  • Participate in ongoing professional development to stay current with cloud security engineering practices and platform security tooling.
Minimum Education And/or Experience Required For The Job
  • 5+ years of experience in platform engineering, cloud/infrastructure engineering with security ownership, and/or platform engineering in an enterprise environment.
  • Demonstrated experience designing and implementing security platforms, partnering with architecture stakeholders to define target‑state designs and roadmaps and executing them through technical delivery.
  • Strong AWS security engineering experience, including an AWS Organizations / Control Tower operating model; Azure experience is a plus.
  • Proven ability to implement preventive controls addressing privilege escalation, service/API security, and network lateral movement in cloud environments.
  • Strong CI/CD engineering experience with GitLab, including implementing security and policy enforcement into pipelines and PR workflows.
  • Proficiency with Terraform and strong automation skills using Python and/or PowerShell (API‑driven integrations, repeatable tooling).
  • Hands‑on experience with privileged access and secrets platforms: CyberArk preferred (PAM/EPM/Secrets Hub). Equivalent experience with Delinea/BeyondTrust acceptable.
  • Bachelor’s degree in Computer Science, Cybersecurity, Engineering, or related field (or equivalent experience).
Benefits That Drive Your Success
  • Annual Paid Time Off (PTO) plans
  • 2 weeks of Paid Parental Leave for Full‑time Employees who work a minimum of 30 hours per week
  • 6 paid holidays annually
  • Medical, Prescription Drug, Dental & Vision Insurance effective Day 1
  • 401(k) Retirement Plan with company match
  • Employer Paid Short‑Term Disability & Life Insurance
  • Additional Voluntary Life Insurance
  • Continuing Education Opportunities
  • Free Prescription or Non‑Prescription Safety Glasses annually
  • Annual Voluntary Uniform Stipend
  • Voluntary Daily Pay option available
AI Disclosure Statement

At The Boyd Group and all affiliated companies, we do not use artificial intelligence (AI) or automated tools to screen, assess, or select applicants for employment. All hiring decisions are made by real people who review each application individually.

Compensation Details

$130,000 – $150,000 / Year

Supplemental Pay

Compensation is commensurate with skill, education and experience. This position may also be eligible for bonus opportunities tied to individual or business initiatives.

EEO Statement

The Boyd Group welcomes unique talents from all backgrounds and characteristics. We act with integrity and appreciate the diverse perspectives that make our “Greater Team” exceptional. Qualified individuals, including those with disabilities and Protected Veterans, are encouraged to apply.

Physical Demands

The physical demands of your job must be met to successfully perform the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the job.

About Us

Gerber Collision & Glass has been WOWing customers with our collision repair services for over 80 years. Please visit gerbercareers.com to learn more about our company.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Software Engineer-Workday
Sr. Software Engineer-Workday

Gerber Collision & Glass • Burlington

On-site
CAD 125,000 - 140,000
Annual PTO
Parental Leave
Paid Holidays
+8
Sr. Business Analyst, Workday Financials - (AR/AP)
Sr. Business Analyst, Workday Financials - (AR/AP)

Gerber Collision & Glass • Burlington

On-site
CAD 179,000 - 221,000
Annual Paid Time Off (PTO) plans
Medical, Prescription Drug, Dental & Vision Insurance
401(k) Retirement Plan with company match
+1
Senior Principal Engineer
Senior Principal Engineer

United States Digital Space LLC • Toronto

On-site
CAD 157,000 - 230,000
Estimator
Estimator

Boyd Group Services • Hudson

On-site
CAD 69,000 - 139,000
Annual PTO
Paid parental leave
6 paid holidays
+6
General Manager - Automotive (51st Street)
General Manager - Automotive (51st Street)

Boyd Group Services • Saskatoon

On-site
CAD 80,000 - 90,000
Competitive Pay
Medical, Prescription Drug, Dental & V
Vision, after 1 month of employment
+6
General Manager - Auto Body (32nd St)
General Manager - Auto Body (32nd St)

Mobile Auto Solutions, LLC • Calgary

On-site
CAD 77,000 - 94,000
Competitive Pay
Medical benefits
RRSP with company match
+5
Senior Manager, Engineering - Platform Security
Senior Manager, Engineering - Platform Security

United States Digital Space LLC • Denver

Hybrid
CAD 317,000 - 380,000
Medical, dental, vision insurance
401(k) with company match
Employee Stock Purchase Program
+1
General Manager - Auto Body (29th St)
General Manager - Auto Body (29th St)

Mobile Auto Solutions, LLC • Calgary

On-site
CAD 68,000 - 92,000
Competitive Pay
Medical Insurance
RRSP match
+5
Staff Platform Engineer
Staff Platform Engineer

Robots and Pencils • Calgary

Hybrid
CAD 96,000 - 138,000
Senior Platform Engineer - LLM and AI Infrastructure
Senior Platform Engineer - LLM and AI Infrastructure

CARFAX • London

On-site
CAD 92,000 - 136,000
401(k) / DCPP matching
Annual bonus program
Flexible work schedules
+1