06 Aug
|
Hartree Partners
|
Toronto
06 Aug
Hartree Partners
Toronto
We have an opportunity for someone to join our growing information security team as an AI Security Engineer . This role blends hands‑on security engineering with AI governance, risk management, and stakeholder advisory responsibilities. You will help design, implement, and maintain controls that protect Hartree’s enterprise AI platforms, cloud and on‑premises infrastructure, applications, and data.
You will also support the development of AI security standards, use‑case governance, risk assessments, and practical guidance for teams across Hartree Group entities. AI Security Engineer Corporate Services IT Security Full‑time is a leading global merchant commodities firm facilitating the flow of energy, metals, agriculture, and environmental products across the full commodity supply chain, connecting producers and consumers. Hartree was founded in 1997 and is jointly owned by senior management and funds managed by Oaktree Capital Management, LP, and employs over 5,000 individuals worldwide.
Hartree is uniquely positioned to capitalise on opportunities across a diversified set of commodities businesses with a focus on trading, asset investments, risk management and advisory services. These businesses are supported by a centralised operating model including risk, technology, operations, finance, HR, legal and compliance, ensuring strong governance and effective execution. As a growing and evolving firm, Hartree continues to expand its commercial footprint, invest in new assets, and build recent capabilities to meet emerging market opportunities.
Establishing and implementing enterprise AI use‑case intake, inventory, and risk‑tiering processes. Defining secure technical baseline configurations for enterprise AI platforms and tools. Defining a minimum set of AI security controls.
Developing AI security training materials for workforce members. Develop and enforce an AI Security governance framework in alignment with current and emerging responsible AI practices and global AI laws, rules, and regulations.
Develop information security policies and standards for enterprise AI platforms and tools.
Define and implement technical controls and risk mitigations for enterprise AI use, including generative AI and AI agents/workflows, with a focus on preventing sensitive data leakage. Monitor emerging AI security, privacy, and regulatory developments and translate relevant changes into updates to standards, controls, and guidance. Establish a governance model for AI use cases, including intake risk tiering, approvals, inventory, and ongoing usage/cost/data monitoring.
Review AI solution designs for alignment with security, privacy, and resilience requirements and offer recommendations to strengthen controls where appropriate. Conduct risk assessments related to enterprise AI systems and help mitigate AI‑specific threats (e.g., prompt injection, sensitive data exposure, insecure agent/tool permissions, unsafe RAG/vector database access). Translate complex AI risks into clear business guidance and contribute to cyber risk reports and dashboards.
Conduct due diligence on third‑party AI capabilities and use. Develop training materials for workforce members on acceptable AI use. Define risk mitigation strategies for AI‑related cyber incidents. Drive greater use of AI within the Information Security team to improve posture and operations.
Administer information security tools and systems. Support additional security initiatives as business needs evolve. Degree in computer science, information security, cybersecurity, or a related field, or equivalent professional experience. 7+ years of professional experience in IT and Information Security.
Experience securing cloud, SaaS, data, or AI/ML platforms,
including hands‑on experience with generative AI, LLM‑based tools, or enterprise AI platforms (e.g., OpenAI ChatGPT, Anthropic Claude, Google Gemini, Microsoft Copilot).
Experience with IT GRC (e.g., policies/standards, risk register, risk assessment, control library) and data management (e.g., Working knowledge of common AI frameworks (e.g., ISO/IEC 42001:2023, NIST AI RMF) and AI laws/rules/regulations (e.g., EU AI Act) Self‑starter who works with minimal supervision. One or more industry‑recognised Information Security or AI certifications (e.g., CISSP, CISM, AAIR, Azure AI Engineer, SANS/GIAC GAIPS). Working knowledge of common Information Security frameworks (e.g., Understanding of network security, system hardening, cloud security (Azure, AWS), and security design principles.
Good understanding of secure software development techniques and security architecture. Exposure to scripting (Python, PowerShell, Bash). Multilingual capability, especially French, would be advantageous, due to Hartree’s global footprint.
We also offer competitive salary and benefits, combined with outstanding career development opportunities in one of the global leaders of commodity trading. The salary range for this position is CAD 120,000 - CAD 150,000. Employees may be eligible for a discretionary bonus in addition to base pay.
They influence the way we communicate and collaborate, and define the way we engage with our clients, partners, and communities. We provide equal opportunities to all qualified applicants without regard to race, colour, sex, gender, age, religion, ethnic or national origin, marital or civil partner status, physical or mental disability, military or veteran status, sexual orientation, gender identity or expression, genetic information or any other characteristic protected by applicable law. Any CVs/resume’s submitted without a prior agreement in place with our talent acquisition team, will be considered the property of Hartree, and no fees will be paid. #
📌 Security Engineer - Junior (Toronto)
🏢 Hartree Partners
📍 Toronto