Senior Information Security Specialist (AI & Application Security) (Vaughan)

Senior Information Security Specialist (AI & Application Security) (Vaughan)

04 Aug
|
Martinrea International
|
Vaughan

04 Aug

Martinrea International

Vaughan

Martinrea International Inc. is a diversified and global automotive supplier, a diversified and global automotive supplier engaged in developing and manufacturing highly engineered, value-added Lightweight Structures and Propulsion Systems. We employ approximately 16,000 skilled and currently operate in 57 locations in Canada, the United States, Mexico, Brazil, Germany, Slovakia, Spain, China, South Africa, and Japan. Martinrea's vision is making lives better by being the best supplier we can be in the products we make and the services we provide.

Our Mission is to make people's lives better by:

- Delivering outstanding quality products and services to our customers.
- Providing meaningful opportunity, job satisfaction, and job security for our people.
- Providing superior long-term investment returns to our stakeholders.
- Being positive contributors to our communities.

Martinrea's success is globally shown through its core sustainable culture. Focused on entrepreneurship, lean manufacturing principles, and the Golden Rule philosophy, Martinrea believes in dignity and respect for its people, communities, customers, and investors. Our strength is in our people, embracing a diverse culture, giving employees opportunities to help grow our footprint and expand product offerings and areas of expertise with discipline, dedication and determination

We invite you to follow your dreams and explore a challenging and rewarding career at Martinrea.

Job Summary:

The Senior Information Security AI Specialist is responsible for protecting Martinrea’s AI, data, and technology environments by identifying and mitigating AI-related security risks, implementing security controls, and supporting AI governance initiatives. The role leads DevSecOps and AI security projects, collaborates with business and technology teams to strengthen the organization’s security posture, and ensures the effective deployment and management of AI security tools and processes. The position also provides operational support, incident response assistance, and participates in the on-call rotation as required.

Required Education and Experience:

- Bachelor’s degree in Information Security, Cyber Security, Computer Science, or equivalent
- 10 years of working experience in support of a large-scale, mission-critical enterprise security infrastructure
- Deep understanding of AI vulnerabilities and experience in securing LLM’s within the Cloud environments
- Understanding of AI-specific threats, including prompt injection, data leakage, data poisoning, model extraction,



model inversion, insecure output handling, supply chain compromise, and misuse of AI agents
- 5 years of experience in secure software development, DevSecOps, CI/CD pipelines, APIs, identity and access management, encryption, logging, monitoring, and vulnerability management
- Experience working with cloud platforms and modern data architectures
- Deployment experience of Azure AI Foundry and Shakudo environments and sub-services, and experience in security of cloud AI infrastructure
- Knowledge of data classification frameworks and AI-specific Data Loss Prevention (DLP) strategies, including NLP-based entity recognition for sensitive data detection and masking
- Understanding of building and securing in-house frontend for Generative AI and building Agentic AI solutions using available open source tools
- Ability to translate complex technical risks into clear business language for senior stakeholders
- Familiarity with relevant AI security and governance frameworks such as NIST AI RMF, OWASP Top 10 for LLM Applications, MITRE ATLAS, ISO/IEC 42001, ISO 27001, NCSC/CISA secure AI guidance, CSA AI Controls Matrix, and applicable AI or privacy regulations
- Significant experience in cyber security architecture, application security, cloud security, platform security, data security, or technology risk
- Practical understanding of AI, machine learning, generative AI, large language models, MLOps, cloud AI services, and AI-enabled application architectures.
- Experience designing, reviewing, or implementing security controls for complex technology environments.
- Preferred to have: CAISP, CISSP

Responsible For the Following Essential Functions:

- Define enterprise AI security reference architectures and maintain AI security principles, standards, guardrails, reference architectures, design patterns, and production readiness criteria across the AI lifecycle.
- Advise on secure architecture for AI platforms, MLOps pipelines, data pipelines, model registries, vector databases, RAG solutions, prompt orchestration layers, APIs, AI agents, and cloud-based AI services
- Conduct AI-focused risk assessments, threat modelling, architecture reviews,



and control gap assessments for new and existing AI use cases.
- Identify and support mitigation of AI-specific risks, including data leakage, prompt injection, model extraction, model inversion, training data poisoning, insecure output handling, excessive agency, insecure RAG implementations, supply chain compromise, and unauthorised access.
- Partner with the AI engineering team to embed security into AI development, MLOps, CI/CD pipelines, deployment workflows, and operational monitoring.
- Advise on secure handling of training, validation, test, and production data, including data minimisation, anonymization, access control, retention, lineage, provenance, and protection of confidential or regulated information.
- Assess security risks associated with third-party AI platforms, foundation models, SaaS AI tools, APIs, open-source models, datasets, plugins, extensions, and model marketplaces.
- Define security requirements for AI vendor due diligence, procurement, onboarding, contractual review, and ongoing supplier assurance.
- Work with security operations and incident response teams to define AI-specific logging, monitoring, detection, investigation, and response requirements.
- Monitor AI security developments, emerging threats, attack techniques, industry standards, and regulatory expectations, translating them into practical internal controls and guidance.
- Promote AI security awareness across engineering, production, data science, business, and technology teams through guidance, workshops, reusable patterns, and stakeholder engagement.
- Implement and manage DevSecOps practices across the entire Software Development Lifecycle (SDLC), ensuring a "shift-left" approach to security.
- Strong expertise in web application security, cloud-native security (Azure & AWS), and modern DevSecOps practices.
- Develop required documentation to help operationalize and automate technologies in close coordination with security operations to ensure compliance requirements are met

Work Workplace:

- Hybrid (3-4 days in Office)

Physical Demands:

- Constant communication with employees, peers, and leadership
- Overtime as required

Other Duties:

- This is not designed to contain a comprehensive list of duties and responsibilities required for this job. Duties and responsibilities may change at any time with or without notice

Disclaimer:

This does not constitute a contract of employment. The Company may exercise its employment at will right at any time.

📌 Senior Information Security Specialist (AI & Application Security) (Vaughan)
🏢 Martinrea International
📍 Vaughan

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: senior information security specialist (ai & application security) (vaughan) / vaughan

Subscribe to this job alert:

Get the latest job offers by email for: senior information security specialist (ai & application security) (vaughan) / vaughan