Department of Position: Technology
Reports to: Director, Technology
Existing vacancy: Yes – Open and available immediately
Company Description
For over years, Lorex has been creating security systems designed to protect your home and business. Founded and headquartered in Canada, we’ve grown to become leaders in DIY (Do It Yourself) security, offering premium solutions built on innovation, reliability, and expertise that enhance your lifestyle and protect what matters most.
Job Summary
The Cyber Security Engineer is a key member of the Cloud Technology & Security team, reporting to the Director of the department. You will own the day-to-day security of Lorex's cloud environment - vulnerability and patch management, software supply-chain/SBOM tracking, and incident response - while supporting SOC2 audit evidence and secure design reviews led by the broader security function. This is a hands-on, build-and-fix role: you'll be the one implementing and automating the controls that keep the cloud stack secure, not just reporting on gaps. In addition to security, you should be comfortable with privacy considerations, as privacy goes hand in hand with security, though you are not required to be a subject-matter expert.
Duties & Responsibilities
Cloud Security & Vulnerability Management (40%)
- Own vulnerability scanning of cloud infrastructure and services (AWS/GCP), and drive remediation to agreed SLAs
- Build and maintain Software Bill of Materials (SBOM) generation and dependency/CVE triage across services; extend existing dependency-scanning coverage to services that don't yet have it
- Implement and validate secure cloud configurations (IAM, network segmentation, encryption at rest/in transit, logging and monitoring)
- Manage patch cadence across cloud infrastructure and CI/CD pipelines; track and report on remediation status
Incident Response & Security Operations (35%)
- Build, maintain, and run the incident response process - detection, containment, eradication, recovery, and post-incident review
- Act as first responder for security incidents; escalate per the defined chain
- Monitor infrastructure, security reports, and vulnerability assessments to identify threats or weaknesses
- Collaborate with software development, DevOps, and engineering teams to integrate security requirements and testing into the delivery pipeline
SOC2 & Security Reviews Support (25%)
- Support SOC2 audit cycles - evidence-gathering, control testing, and remediation tracking for identified gaps
- Support Threat and Risk Assessments (TRAs) on Lorex products and services
- Partner with engineering teams to provide secure design and deployment guidance for new cloud services
Qualifications & Experience
- Undergraduate degree in Information Security, Computer Science/Engineering, or related field (or equivalent hands-on experience)
- 3–5 years of hands-on experience in information security engineering, with a focus on cloud environments
- Solid technical expertise in vulnerability management, patch management, cloud security controls (IAM, network security, encryption), and incident response
- Experience building/maintaining SBOM tooling (e.g., CycloneDX, SPDX) and dependency/SCA scanning (e.g., Dependabot, Snyk, npm audit)
- Experience implementing security controls in cloud environments (AWS and/or GCP)
- Experience supporting a SOC2 (Type I or II) audit cycle
- Working knowledge of monitoring/logging tooling (e.g., CloudTrail, GuardDuty, or equivalent)
- Comfortable scripting/automating (Python, Bash, or similar) for scanning, reporting, and patch tracking
- Ability to work independently, with strong problem-solving and analytical skills
- All prospective employees must pass a background check
Assets (nice-to-have, not required):
- AWS Certified Security – Specialty, GCP Professional Cloud Security Engineer, CISSP, CISA, or CCSK
- Exposure to mobile app (iOS/Android) or embedded/IoT device security
- SIEM or endpoint-protection tooling experience
- Experience with surveillance, video, or real-time communications products
Lorex welcomes and encourages applications from people with disabilities. Accommodations are available on request for candidates taking part in all aspects of the selection process.
Please note that we use AI tools as part of our recruitment process to enhance efficiency and improve candidate experience.