Cloud Security Engineer (Toronto)

Cloud Security Engineer (Toronto)

19 Aug
|
Apex Systems
|
Toronto

19 Aug

Apex Systems

Toronto

Job#: 3046443 : Cloud Security Engineer Cloud Security DevSecOps Engineer (Azure Focus) Top Skills Required

- Experience updating and maintaining security policies and patterns in Azure using Terraform and/or Bicep, including Policy-as-Code concepts.
- Strong knowledge of Azure security services, specifically Microsoft Defender, Identity and Access Management (IAM), Azure Landing Zones, and network security policy configurations.
- Experience reviewing, updating, and implementing security baseline controls and security configurations for cloud workloads.
- Hands-on experience working with GitHub-based DevSecOps workflows, including reviewing and updating policy and pattern code within repositories.
- Ability to work independently in an engineering-focused environment, identifying gaps, improving security patterns, and driving solutions with minimal oversight.

Nice-to-Have Skills

- Deep experience with Microsoft Sentinel, Azure Monitor, and Defender.
- Experience with AI security initiatives, Azure AI Foundry, or securing emerging cloud AI services.
- Knowledge of Threat Modeling methodologies and secure-by-design principles.
- Experience with Wiz Cloud, Wiz Code, Runtime/Defend, and integrating Wiz findings into GitHub workflows.
- Prior experience working in highly regulated environments such as banking or financial services.

The Cloud Security DevSecOps Engineer (Azure Focus) will support the design, maintenance, and enhancement of Azure cloud security patterns, policies, and baseline controls. The role is heavily focused on security engineering, policy-as-code, and cloud platform security enablement rather than day-to-day security operations. This individual will work closely with principal architects and engineering teams to implement secure Azure configurations and continuously improve cloud-native security controls.

Responsibilities Security Engineering

- Build and maintain Azure security patterns.
- Update existing Azure security baseline controls.
- Implement new security requirements for cloud services.

Policy-as-Code
- Develop and modify Azure security policies.
- Manage governance controls using Infrastructure-as-Code methodologies.
- Maintain reusable security modules and policy templates.

Cloud Security Architecture Support

Assist principal engineers with

- Azure Foundry initiatives
- Defender deployments
- Security monitoring enhancements
- Identity architecture reviews

Continuous Improvement
- Improve cloud security automation.
- Reduce manual security processes.

Enhance cloud security guardrails. Cloud Security DevSecOps Engineer (AWS Focus) Top Skills Required

- Experience updating and maintaining AWS security policies and patterns using Terraform, including Policy-as-Code concepts.
- Strong knowledge of AWS security services, including GuardDuty, Identity Center, WAF, API Gateway, and identity federation/integration with Microsoft Entra ID.
- Experience reviewing and implementing cloud security configurations, network security controls, and micro-segmentation requirements.
- Hands-on experience working with GitHub repositories and DevSecOps practices, including updating security patterns and configuration templates.
- Ability to independently analyze security requirements, improve existing cloud security patterns, and operate effectively in a fast-changing engineering organization.

Nice-to-Have Skills

- Experience with Wiz Cloud, Wiz Code, Runtime/Defend, and CI/CD security integrations.
- Knowledge of JSON-based AWS policy templates and security automation.
- Understanding of Threat Modeling concepts and secure architecture reviews.
- Experience supporting both AWS and Azure environments in a multi-cloud security organization.
- Background in financial services, fintech, or mature cloud-native organizations with established DevSecOps practices.

The Cloud Security DevSecOps Engineer (AWS Focus) will be responsible for maintaining and enhancing AWS cloud security patterns, governance controls, and security automation capabilities. The role partners directly with security architects and platform teams to deliver scalable cloud security solutions through Policy-as-Code and Infrastructure-as-Code practices.

Responsibilities Security Engineering

- Update AWS cloud security patterns and guardrails.
- Implement infrastructure security controls.
- Maintain AWS security governance standards.

Policy-as-Code
- Modify and create security policies within IaC repositories.
- Support security configuration automation.
- Manage policy lifecycle through GitHub-based workflows.

AWS Security Controls

Maintain controls related to

- GuardDuty
- AWS Identity Center
- WAF
- API Gateway
- Network segmentation

Platform Collaboration




- Partner with engineering teams to remediate security gaps.
- Assist with cloud platform modernization initiatives.
- Support secure deployment patterns.

Cloud Security Vulnerability & CNAPP Analyst Top Skills' Details

- 5+ years of experience in Cloud Security, Security Engineering, Vulnerability Management, DevSecOps, or Infrastructure Security.
- Hands-on experience with Wiz or comparable Cloud Security Posture Management (CSPM) platforms.
- Experience conducting technical risk assessments and vulnerability analysis.
- Strong ability to influence engineering teams and drive remediation outcomes.

Our client, a top 5 Canadian Bank, is seeking a Cloud Security Risk & Remediation Engineer to help strengthen and mature enterprise cloud security practices across Azure and AWS environments. This role combines vulnerability remediation, security exception management, cloud security governance, and engineering partnership responsibilities into a single function focused on reducing organizational risk. The successful candidate will serve as a bridge between Security, Cloud Engineering, Architecture, and Development teams, driving the identification, assessment, remediation, and governance of cloud security risks. This individual must be comfortable operating in a highly collaborative environment while also independently creating processes, influencing stakeholders, and driving outcomes.

This is an ideal opportunity for someone who thrives in a "green space" environment where they can help build and mature security processes rather than simply maintain existing programs.

Vulnerability Management & Remediation

Lead cloud vulnerability management activities utilizing Wiz and related security platforms.

Analyze vulnerabilities across cloud infrastructure, containers, applications, runtime environments, and cloud-native services.

Prioritize findings based on risk, business impact, exploitability, and organizational standards.

Partner directly with engineering teams to drive remediation efforts and reduce security exposure.

Track remediation activities, metrics, trends, and risk reduction progress.

Help establish scalable vulnerability management processes and operational workflows.

Participate in response efforts for critical vulnerabilities, zero-day events, and high-priority security incidents.

Security Exceptions & Risk Assessment

Review cloud security exception requests against enterprise security standards, guardrails, and approved architectural patterns.

Assess risk associated with configuration deviations and non-standard implementations.

Evaluate compensating controls and recommend risk-based decisions regarding exception approvals or remediation requirements.

Partner with engineering and architecture teams to identify secure alternatives whenever possible.

Maintain exception documentation, governance workflows, and review processes.

Identify recurring exception patterns and recommend long-term improvements to standards, automation, or architectural guidance.

Security Engineering Partnership

Collaborate with DevSecOps and Cloud Security Engineering teams to drive shift-left security initiatives.

Support future integrations between cloud security tooling and development workflows, including GitHub-based processes.

Contribute to cloud security posture improvements across Azure and AWS environments.

Assist with threat modeling, architecture reviews, and security assessments.

Recommend automation opportunities that reduce manual remediation and exception management activities.

Help translate security requirements into actionable engineering outcomes.

Additional Skills & Qualifications

- 5+ years of experience in vulnerability management, cloud security, infrastructure security, or security engineering.
- Hands-on experience with Wiz or comparable Cloud Security Posture Management (CSPM) platforms.
- Experience remediating vulnerabilities in cloud environments.

- Strong understanding of

- Cloud infrastructure

- Containers and Kubernetes

- Identity and access management

- Application security concepts

- Security risk assessment methodologies
- Ability to engage engineering teams and drive remediation outcomes.

Employee Value Proposition (EVP)

- 100% Remote
- Opportunity to contribute to critical security functions,



including vulnerability remediation and establishing security baselines for cloud platforms.
- Exposure to Azure and AWS cloud environments, including Terraform, Bicep, Azure Landing Zones, Microsoft Defender, AWS GuardDuty, Entra ID, and Threat Modeling.
- Opportunity to work within an engineering-led DevSecOps organization and grow into more advanced engineering-focused responsibilities.
- Ability to help shape processes, standards, and structural design as the team continues to mature.
- Culture focused on ownership, initiative, problem-solving, and driving outcomes.
- Exposure to Wiz-related initiatives and cloud security automation capabilities.
- Potential for longer-term growth and future FTE opportunities.

Work Environment

- Team currently consists of three senior-level security engineers.
- Plans are underway to add two Principal-level FTEs and four contract resources.
- Team supports and partners closely with Enterprise Cloud Engineering organization.

Business Drivers A current Director has been brought in to lead the engineering team and drive DevSecOps, cloud security engineering, and Wiz/exposure management initiatives. Why the Position Is Open The Director is looking to offload operational security work from senior engineers so they can focus on higher-value engineering and strategic initiatives. Currently, senior resources are spending a significant amount of time handling operational activities such as security exception requests, creating an opportunity for contractors to take ownership of these responsibilities while supporting the team's broader cloud security objectives.

Location: Toronto, ON

Engagement Type: month contract to start

EEO Employer

Everforth Apex Systems is an Equal Employment Opportunity/Affirmative Action Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, age, sexual orientation, gender identity, national origin, disability, protected veteran status, or any other characteristic protected by law.

Everforth Apex

Systems will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact our Employee Services Department at [email protected] or (phone hidden).

Everforth Apex is a world-class IT services company that serves thousands of clients across the globe. When you join Everforth Apex, you become part of a team that values innovation, collaboration, and continuous learning.

We offer quality career resources, training, certifications, development opportunities, and a comprehensive benefits package. Our commitment to excellence is reflected in many awards, including ClearlyRateds Best of Staffing® in Talent Satisfaction in the United States and Great Place to Work® in the United Kingdom and Mexico. Everforth Apex Benefits Overview:

In terms of professional development, Everforth Apex hosts an on-demand training program, provides access to certification prep and a library of technical and leadership courses/books/seminars once you have 6+ months of tenure, and certification discounts and other perks to associations that include CompTIA and IIBA. © 2026 Everforth, Inc. All rights reserved.

Everforth Apex Systems is part of the Commercial Segment of Everforth, Inc.

NYSE: EFOR

4400 Cox Road

Suite 200

Glen Allen, Virginia 23060

Everforth Apex is an equal opportunity employer. We do not discriminate or allow discrimination on the basis of race, color, religion, creed, sex (including pregnancy, childbirth, breastfeeding, or related medical conditions), age, sexual orientation, gender identity, national origin, ancestry, citizenship, genetic information, registered domestic partner status, marital status, disability, status as a crime victim, protected veteran status, political affiliation, union membership, or any other characteristic protected by law.

Everforth

Apex will consider qualified applicants with criminal histories in a manner consistent with the requirements of applicable law. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation in using our website for a search or application, please contact our Benefits Department at [email protected] or (phone hidden). (Do not submit resumes or solicit consultants to this email address). UnitedHealthcare creates and publishes the Transparency in Coverage Machine-Readable Files on behalf of Everforth Apex.

📌 Cloud Security Engineer (Toronto)
🏢 Apex Systems
📍 Toronto

Reply to this offer

Impress this employer describing Your skills and abilities, fill out the form below and leave Your personal touch in the presentation letter.

Subscribe to this job alert:

Get the latest job offers by email for: cloud security engineer (toronto) / toronto

Subscribe to this job alert:

Get the latest job offers by email for: cloud security engineer (toronto) / toronto