Security Specialist Location: Toronto, ON Onsite Flexibility: Hybrid 2 days on-site (Wednesday and Friday), 3 days work from home; could potentially move to 4 days in office Contract Details Position Type: Contract Contract Duration: 4 months (with possibility of extension and conversion based on business needs and performance) Pay Rate: C$70.00 C$85.00 / Hour (CAD) Shift / Schedule: Monday Friday, core business hours 37.5 hours per week, 7.5 hours per day Travel Requirements: Not required Job Summary We are looking for a detail-oriented Cloud Security and AI Test Engineer to join our team.
This individual will focus on automating and validating Compliance-as-Code (CaC) policies across multi-cloud environments including GCP, Azure, and AWS.
In this role you will blend your expertise in cloud security with advanced AI tools to enhance compliance, security, and test automation, ensuring continuous validation within multi-cloud environments.
Key Responsibilities Automated Testing for Cloud Policies Design, develop, implement, and maintain AI-driven automated test frameworks for the behavior of existing compliance-as-a-code policies across cloud environments (GCP/AWS/Azure) in alignment with banking regulations Implement AI-driven test environments using Azure Foundry and Azure ML to create realistic, mock cloud setups, including network and IAM configurations to simulate and test policies effectively Utilize Azure AI Search, Azure OpenAI, and Azure Machine Learning to build intelligent validation routines that can predict policy compliance issues and recommend remediation steps Develop comprehensive positive, negative, and edge exception test cases to validate policy enforcement logic Maintain a test suite library and ensure traceability between compliance requirements, validation cases, and artifacts Collaborate with CaC policy developers, security architects, and Cloud Service Owners to understand intended behavior and failure conditions Continuous Testing & CI/CD Integration Integrate AI-assisted compliance validation into CI/CD pipelines, Git
Hub Actions, Git
Hub Workflows using Git
Hub Copilot for scripting efficiencies and M365 Copilot Studio for creating streamlined policy validation templates Automate security scanning and validation of Terraform deployments with Python Validate the enforcement of banking cloud security policies by embedding automated compliance checks into Dev
SecOps workflows and actions Cloud Security and Regulatory Compliance Enforcement Work closely with security, Dev
SecOps teams, and Cloud Compliance governance teams to define and enforce cloud security controls in accordance with regulatory mandates Validate cloud resource configurations against financial industry standards (NIST, ISO 27001, SOC 2) Reporting & Audit Readiness Implement/test logging and monitoring solutions to detect compliance violations in real time Automate/validate the generation of compliance reports and dashboards using tools like Sonar
Qube, Wiz.IO, Splunk, Dynatrace, App
Omni Ensure that all TD Standards & STIG requirements for IaaS, PaaS, SaaS CaC development, and testing activities are traceable and auditable for internal risk assessments and external regulatory audits Required Skills 8 years in Cloud Security, Dev
SecOps, AI, or Cloud Engineering roles 3 years of Technical Lead experience Strong knowledge of GCP, Azure, and AWS Jira and Confluence Proficient in Python CI/CD pipelines Proficient in Terraform Strong communication skills (written and verbal) Solid interpersonal skills Self-motivated, well organized, able to work both independently and in a team environment Attention to detail; self-starter and adaptable Preferred Skills Cloud or Dev
SecOps engineering certifications Experience with container security and Kubernetes policy enforcement Hands-on experience with Hashi
Corp Sentinel, Azure Policy, Wiz Policy, GCP Org Policy, and Open Policy Agent, Kubernetes Cloud infrastructure as code experience with Helm, ARM, JSON, YAML, REGO Banking or financial institution experience Education Requirements Degree or Diploma required; Master''s or PhD preferred Cloud or Dev
SecOps engineering certification is an asset Required Experience Minimum 8 years (open to 5 years) of overall experience in Cloud Security, Dev
SecOps, AI,
or Cloud Engineering roles Minimum 3 years of Technical Lead experience Work Environment / Physical Requirements Hybrid work model: 2 days on-site (anchor days: Wednesday and Friday), 3 days work from home; schedule could potentially move to 4 days in office Core business hours, Monday Friday, 37.5 hours per week, 7.5 hours per day No overtime; no rotation Team size: approximately 10 people Training period includes TD onboarding, knowledge transfer, virtual independent training, and shadowing team members Average of approximately 2 hours per day in meetings Interaction with both internal and external stakeholders No access to customer data Important Notes Candidates must be available for an in-person interview if selected for the second round of the interview process; candidates who cannot attend in person should not be submitted this is a hard requirement Interview process: 2 steps virtual interview followed by an in-person technical interview (approximately 1 hour) Candidates must demonstrate hands-on cloud development experience, particularly within GCP and/or Azure; experience limited to AWS only or support-level cloud experience (e.g., troubleshooting application issues) rather than hands-on cloud development is not sufficient About the Client This client is a top-10 North American bank delivering comprehensive retail, commercial, and wealth management solutions.
As one of the largest financial institutions on the continent, it serves millions of customers across Canada, the United States, Europe, and the Asia-Pacific region, operating a full-service financial platform through a global workforce of over 85,000 employees.
Teams here include retail banking advisors, commercial lenders, wealth management professionals, risk analysts, and technology specialists including cloud security engineers, Dev
SecOps practitioners, and AI/ML professionals who drive innovation across a globally recognized financial brand.
About GTT GTT is a minority-owned staffing firm and a subsidiary of Chenega Corporation, a Native American-owned company in Alaska.
We highly value diverse and inclusive workplaces and support Fortune 500 organizations across banking, financial services, technology, life sciences, biotech, utilities, and retail sectors throughout the U.S. and Canada.
Job Number: 26-08309 #LI-Onsite #LI-GTT #gttca
📌 Security Specialist (Toronto)
🏢 GTT
📍 Toronto