An application made for this job — a tailored resume and cover letter that speak straight to the posting.
Sun Life is seeking a Senior Security Platform Engineer to design, implement and enhance cryptographic security platforms including CyberArk MIS, Venafi, ISG Crypto Vulnerability Scanner, and HashiCorp Vault. You will collaborate with infrastructure, architecture and operations teams to mitigate risk and protect client data.
You’ll deploy security tech, lead enterprise initiatives, and contribute to incident response and 24x7 on-call coverage, driving security improvements across Sun Life’s
You are as unique as your background, experience and point of view. Here, you'll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll have new and exciting opportunities to make life brighter for our Clients - who are at the heart of everything we do.
At Sun Life, we're driven by our Purpose: helping our Clients achieve lifetime financial security and live healthier lives. Our values shape how we work: caring, authentic, bold, inspiring, and impactful.
When you join Sun Life, you'll work with passionate colleagues and empowering leaders who support your growth and celebrate your contributions, so you can make a meaningful difference in our Clients' lives.
Discover how you can make a difference in the lives of individuals, families and communities around the world.
Position Summary:
The Senior Security Platform Engineer is responsible for designing, implementing, supporting, and continuously enhancing Sun Life's enterprise cryptographic security platforms, including CyberArk Machine Identity Security (Venafi), ISG Crypto Vulnerability Scanner, and HashiCorp Vault. You will work closely with infrastructure, architecture, operations, and application development teams to identify security risks and deliver solutions that protect customer and financial information.
The successful candidate will bring strong expertise in cryptographic security platforms, a deep understanding of security risks and controls, and a passion for continuous improvement. You will also participate in operational support activities, including incident response and on-call rotations.
Operate, maintain, and innovate across Cryptographic platforms particularly ISG Crypto Vulnerability Scanner and CyberArk Machine Identity Security (formerly called Venafi TPP). Design and implement automation and integration solutions to improve platform scalability, operational efficiency, and security outcomes.
Deploy, support, and maintain new and existing security technologies that are deployed within Sun Life and owned by the team.
Analyze information systems utilizing various cybersecurity techniques and lead security initiatives and enterprise level projects implementing security solutions and performing POC/POV for new technologies.
Work independently with high degree of ambiguity and deliver expected outcomes, be focused on the end deliverables, and build trust with internal clients and peers.
Implement risk driven security controls and provide SME (Subject Matter Expertise) during Audit.
Investigate and respond to security incidents, adhering to defined SLA's.
Participate in teams 24x7 on-call support and be required to join major incident management calls to provide support and consultation.
Identify risks to the business and recommend strategies to address those risks.
Manage the capacity and resiliency of security systems protecting Sun Life's internal and client data.
Collaborate and build trust with security peers, vendors, and other Sun Life teams to enhance security posture and best practices.
Serve as a change catalyst for Digital transformation, using JIRA, Confluence, estimating stories, setting definition of done, completing, and tracking story updates and assignments.
Smoothly transition and operationalize projects and products. This includes developing roles & responsibilities (RACI), completing product documentation and educating the teams who will be performing BAU (Business as usual) the day-to-day work.
Document, update, and maintain cyber security playbooks, policies and knowledge base articles used to support the established Incident Management and CSIRT processes.
Pragmatic understanding of security challenges as a combination of technology and process issues, with the ability to drive solutions across both.
Strong Infrastructure/DevOps foundation, including Linux, Windows, Active Directory, SSO, authentication and authorization protocols, AWS, Azure, databases, Splunk, ServiceNow, and Jira.
Proven expertise with cryptographic security platforms, including CyberArk MIS (Venafi), ISG Crypto Vulnerability Scanner, and HashiCorp Vault, as well as enterprise PKI, SSL/TLS certificate lifecycle management, and machine identity security.
Extensive knowledge of information security principles, industry standards, security controls, risk management frameworks (NIST, ISO 2700x), and vulnerability remediation.
Experience with cloud and container technologies, including AWS, Kubernetes, OpenShift, and EKS.
Experience with security operations, including incident response, detection engineering, endpoint security, intrusion detection, and email security technologies.
Knowledge of networking technologies, load balancers, firewalls, web application firewal