About Draganfly:
Draganfly Inc. (the “Company”) has been a recognized technology leader within the commercial UAV space for over two decades. We helped establish the commercial market & adoption of multi-rotor helicopters for public safety, agriculture, aerial imaging, & more. As a leader who helped shape the industry, Draganfly’s focus is on the sale of drone products and services, contract engineering & custom integration product development, and health monitoring products and services.
About The Role:
The Senior IT Security Engineer builds, operates, and improves security across Draganfly’s cloud-first IT environment. This hands-on role combines Microsoft 365 and cloud security engineering with incident response, automation, audit readiness, and delivery of IT Steering Committee-approved security initiatives.
This is a full-time, hybrid role based in Burnaby, British Columbia, reporting to the Director of IT.
Key Responsibilities:
Identity, Access, Endpoint & Cloud Security
- Manage Microsoft Entra ID controls, including MFA, Conditional Access, least privilege, administrative access, SSO, access reviews, service identities, and joiner/mover/leaver processes.
- Configure Microsoft 365 endpoint, email, information protection, secure sharing, retention, and DLP controls.
- Secure AWS IaaS/PaaS workloads through network controls, logging, encryption, secrets management, and configuration monitoring.
- Manage Intune compliance policies, security baselines, encryption, endpoint protection, patching, and BYOD controls.
- Automate security checks, reporting, and remediation using PowerShell and approved AI tools, and partner with Software Engineering on DevSecOps.
Detection, Incident Response & Resilience
- Investigate security incidents including risky sign-ins, compromised accounts, malicious email, endpoint alerts, and unauthorized access.
- Coordinate incident triage, containment, recovery, escalation, monitoring, and evidence preservation with managed security providers.
- Conduct vulnerability assessments, prioritize and coordinate remediation, and retest fixes.
- Support business continuity, disaster recovery testing, tabletop exercises, and crisis response.
Vendor & Technology Risk
- Manage security assessments for vendors, SaaS platforms, cloud services, and AI tools.
- Review SOC 2 reports, ISO/IEC 27001 certifications, architecture, data handling, subcontractors, and security controls.
- Assess new technologies, track risks and remediation, and partner with procurement, legal, and business owners on security requirements.
Security Governance & Risk
- Translate security policies into technical standards and procedures and support security awareness and change management.
- Maintain the security risk register, including ownership, treatment plans, evidence, and exceptions.
- Map controls and improvements to SOC 2, ISO/IEC 27001, NIST CSF, and applicable requirements.
Security Projects, Roadmap & Assurance
- Lead security projects from design and hands-on implementation through testing, troubleshooting, and operational handover.
- Deliver ITSC-approved initiatives, managing milestones, dependencies, resources, risks, stakeholders, vendors, change plans, and reporting.
- Conduct internal security audits and control testing, document findings, coordinate corrective actions, and retest remediation.
- Lead external audit readiness, including IT general controls and applicable COSO-related requirements.
Who are you really?
- Hands-on security engineer who can design, configure, troubleshoot, and improve controls.
- Uses risk, evidence, and business impact to prioritize work and make practical decisions.
- Takes ownership of projects, incidents, audits, and remediation through completion.
- Communicates clearly and collaborates effectively across technical, business, vendor, and audit teams.
Qualifications:
- Five or more years of relevant IT or information security experience, including hands-on Microsoft 365 and cloud security engineering.
- Experience implementing security controls in Azure, AWS, or GCP IaaS and PaaS environments.
- Strong knowledge of Entra ID, Conditional Access, MFA, Intune, endpoint security, cloud workloads, incident response, and vulnerability remediation.
- Practical experience applying security and audit frameworks such as SOC 2, ISO/IEC 27001, NIST CSF, COSO, or SOX.
- Experience leading security projects or control assessments, evaluating vendor risk, and using PowerShell or comparable automation.
- Clear communication, independent problem-solving, and effective cross-functional collaboration.
Preferred Qualifications
- Diploma or degree in cybersecurity, computer science, information technology, or a related field, or equivalent practical experience.
- Defense or aerospace experience involving controlled information, NIST SP 800-171, or CMMC Level 2 readiness.
- CISSP, CISM, Microsoft security certifications, AWS security credentials, or advanced Microsoft security tooling experience.
Compensation package:
- Competitive salary: $120,000 - $140,000 CAD
- Equity / Stock Options: Participation in the company’s stock option plan, providing long‑term ownership and alignment with company growth.
- Comprehensive medical and dental benefits, including a Health Spending Account (HSA).
- Matching RRSP program to support long‑term financial planning.
- Generous time‑off program, including vacation, wellness days, and the full week off between Christmas and New Year’s.
- Professional development support, including assistance toward obtaining your FAA Part 107 Remote Pilot Certificate or equivalent training required for operational roles.
Why Join Us?
At Draganfly Innovations, you’ll join a collaborative team that values innovation, curiosity, and continuous improvement. We’re in an exciting growth phase, scaling our technologies, product lines, and teams as we continue to shape the future of UAV innovation. Joining us now means becoming part of a company with deep roots in the industry - and bold ambitions for what comes next.
You’ll have the opportunity to make a meaningful impact, work on diverse and cutting‑edge projects, and grow your skills alongside passionate experts. We offer competitive compensation, strong benefits, and a supportive environment where your contributions truly matter. Here, you won’t just join a company - you’ll help build what comes next.
As part of our hiring process, all candidates must successfully complete reference checks and a criminal background check.