08 Aug
|
McCormick Canada
|
Winnipeg
08 Aug
McCormick Canada
Winnipeg
About the RoleWe are looking for a versatile and highly skilled Cyber Security Engineer / IAM Specialist to play a pivotal role in securing our business and IT operations. As we are actively building and maturing our cyber security program, this role offers a unique opportunity to make a foundational impact.You will serve as our subject matter expert for Identity and Access Management (IAM) and application security, ensuring that all third-party business and IT applications are implemented with a security-first mindset. Because our cyber program is evolving, this is a highly dynamic, cross-functional role. You will have your hands in multiple domains, including security governance, vulnerability management, operational technology (OT) security, and overarching cyber architecture.Key ResponsibilitiesApplication Security & Risk ManagementSecure Implementation: Oversee the security architecture and implementation of all third-party IT and business applications (SaaS, COTS, etc.), ensuring they meet organizational security standards.Threat Modeling: Conduct comprehensive threat modeling to identify potential vulnerabilities, attack vectors, and design flaws in application deployments.Risk Mitigation: Assess risks associated with new and existing applications, providing actionable, secure solutions and compensating controls to business stakeholders.Identity & Access Management (IAM)Lifecycle Management: Design, deploy, and manage our IAM lifecycle processes, ensuring the principles of least privilege and zero trust are applied across the organization.Microsoft Ecosystem Management: Leverage the Microsoft environment (e.G., Entra ID / Azure AD) to configure and enforce Conditional Access policies, MFA, SSO, and Role-Based Access Control (RBAC).Access Auditing: Regularly audit identities, roles, and permissions to ensure compliance with internal access policies.Cyber Program Development & EngineeringVulnerability Management:
Assist in building, configuring, and maintaining vulnerability scanning workflows and coordinating remediation efforts across endpoints, servers, and applications.Operational Technology (OT) Security: Support the secure design and architecture of our OT environments, bridging the gap between standard IT infrastructure and industrial/operational systems.Governance & Compliance: Contribute to the development of foundational cyber security policies, standards, and compliance frameworks.General Cyber Support: Act as a flexible security engineering resource, guiding the secure design of various IT projects and initiatives as the overarching security program scales.Required QualificationsExperience: Proven experience as a Cyber Security Engineer, Application Security Specialist, or IAM Engineer.Microsoft Environment Expertise: Deep technical understanding of the Microsoft security ecosystem, including Azure, Entra ID (Azure AD), and enterprise Windows environments.Threat Modeling Skills: Hands-on experience performing threat modeling and risk assessments for third-party software integrations and business apps.IAM Proficiency: Strong foundational knowledge of identity protocols (SAML, OAuth, OIDC) and enterprise identity management.Broad Security Knowledge: Working understanding of broader security domains, including vulnerability management, OT/ICS security concepts, and governance frameworks.Communication: Excellent ability to translate complex cyber risks into explicit, actionable business recommendations for non-technical stakeholders.Why Join Us?This is a builder’s role. You will not just be turning the crank on existing processes; you will be instrumental in defining how we approach security across the business. If you enjoy a dynamic environment where you can touch multiple architectural aspects of cyber security, from evaluating a new SaaS application to securing OT networks, we want to hear from you.#J-18808-Ljbffr
📌 Cyber Security Engineer (Winnipeg)
🏢 McCormick Canada
📍 Winnipeg