Position: Cloud & Application Security Engineer
Location: Onsite- Montreal, QC
Job type: Full-time/Permanent hiring
As the Cloud & Application Security Engineer, you will serve as the principal design authority responsible for protecting our enterprise applications and hybrid multi-cloud digital footprint. This is a senior technology leadership role requiring deep expertise in architecting ironclad environments across Azure, AWS, and GCP. You will be responsible for translating complex threat landscapes into scalable, programmatic security solutions, establishing advanced access controls, and embedding application security guidelines into every layer of our software development and deployment infrastructure.
Key Responsibilities
- Multi-Cloud Architecture Governance: Design, implement, and maintain enterprise security control structures across a complex hybrid footprint comprising Azure, AWS, and GCP environments.
- Zero-Trust Engineering: Architect, evaluate, and scale comprehensive Zero-Trust architectures to verify and secure every device, user, and workload transaction.
- Access & Identity Governance: Design, audit, and systematically enforce secure Role-Based Access Control (RBAC) and Identity and Access Management (IAM) policies across all platforms.
- Advanced Threat Telemetry: Configure and tune advanced analytics, threat intelligence, and security posture monitoring systems utilizing Microsoft Defender suites.
- Data Logging & Cryptography: Secure structural event logging pipelines and ensure highly secure system transmissions across enterprise endpoints utilizing TLS syslog orchestration and advanced cryptographic network protocols.
- Application Security Design: Formulate, establish, and embed industry-standard application security controls, secure development standards, and code validation parameters into the delivery lifecycle.
Required Qualifications
- Multi-Cloud Mastery: Direct, proven experience actively managing and architecting cloud security controls simultaneously across Microsoft Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).
- Security Frameworks: In-depth knowledge of modern Zero-Trust networking principles, architectural data segmentation, and continuous authorization layers.
- Telemetry Tools: Hands-on proficiency with Microsoft Defender (for Cloud/Endpoints) to run advanced behavioral analytics and security configuration assessments.
- Log Engineering: Solid practical command over centralized data auditing, security monitoring setups, and secure transmission mechanics using TLS syslog formats.
- Access Management: Advanced mastery of engineering complex cloud IAM and RBAC permission models to ensure the principle of least privilege.
- AppSec Standards: Comprehensive understanding of application security practices, code security, API protection, and industry-standard vulnerability remediation practices.