05 Sep
|
EQ Bank | Equitable Bank
|
Toronto
05 Sep
EQ Bank | Equitable Bank
Toronto
OverviewSenior Security Engineer with a strong Cloud Security background. The candidate will have an in-depth Zero Trust and SASE security model understanding. Responsibilities include Cloud Logs Acquisition and Analysis, Cloud Investigations, Security Engineering & Architecture, Use Case Development, Playbook Development, SIEM Log Integration, and Threat Detection Tuning.Primary responsibilities include monitoring, configuring, tuning, and maintaining ZTNA services for the Information Security Group. The role involves building interconnected systems to improve efficiency of Information Security Operations and periodic interaction with external vendors, auditors, and regulators on security, compliance, and audit events.Main ActivitiesProvide detailed analysis and recommendations after monitoring security events from sources such as IDS/IPS, DLP, Anti-Virus/Endpoint Protection, Network and Web Application FirewallsExamine, appraise, and interpret correlation metrics; develop dashboards and reportsTune rules, filters, and policies for detection-related security technologies to improve accuracy and visibilityAkamai Web Application Security: engineering, deployment, integration, and operations of Web Application Firewall security solutionsPerform hands-on Web Application Firewall deployment, configuration, policy fine-tuning and maintenanceImprove and support application security tool deployments including static analysis and runtime testing toolsProtect enterprise pipeline on Azure DevOps, and integrate applications running on AKS, PCF and Docker using Aqua Security; lead security incident response with investigations and mitigationsTrain and educate Security staff, other Technology Groups, and external partners on Zero Trust Network ArchitectureManage SIEM elements such as Log collection, Normalization, Correlation, and AggregationPerform compliance activities and support PCI DSS and other audit requirementsParticipate in evaluating, designing,
and implementing new security solutionsMaintain documentation of tools, logic, policies, and proceduresParticipate in security risks, threats, and vulnerabilities assessmentsOn-call, off-hours, and/or shift work may be requiredKnowledge/Experience RequirementsAdvanced degree in Computer Science or related field is highly preferredMinimum of eight (8) years in an information security function or roleExperience with cloud security (AWS, Azure, Google Cloud Platform)Experience with security compliance frameworks (ISO 27001, NIST, SOC 2)CISSP or similar certification is preferredAbility to work in fast-paced environments with minimal guidanceExtensive experience in security solutions including SIEM, SOAR, Firewall, Web Proxy, and WAFStrong expertise in: Strong Authentication, Endpoint Security, Internet Policy Enforcement, Web Content Filtering, PKI, DLP, IAM, Secure Wi-FiAdaptability to changing technical, regulatory, and compliance environmentsExcellent verbal and written communication; ability to interact with all employees including executivesExperience in banking/financial services is an assetTechnical knowledge of Unix/Linux, Windows, networks, servers, VMware, SQL Server, firewalls, anti-malware tools, IDS/IPS, encryption, and other IT infrastructure techStrong understanding of networking services/protocols (TCP/IP, SSH, DNS, DHCP, SMTP, SSL, etc.)Organized, structured, logical thinking and detail-oriented analyticsAbility to think creatively to solve technical problemsJob Complexities/Thinking ChallengesThe role focuses on quality control within IT infrastructure, including designing, building, and defending scalable, secure,
and robust systems; working on operational data center systems and cloud networks; understanding advanced cyber threats; and helping create strategies to protect assets.Develop and implement security strategies for cloud-based systems, including encryption, access controls, and monitoring tools. Conduct regular vulnerability assessments and penetration testing to identify and mitigate risks. Collaborate with cross-functional teams to implement security protocols for new and existing systems. Develop and execute information security plans and policies for response and recovery from security breaches. Raise awareness on information security standards, policies, and best practices. Monitor networks and systems for security breaches using detection tools for intrusions and anomalies.AccountabilityFacilitate the implementation of static scans, agile scans, pen testing, infrastructure, container, and cloud scansEnsure security controls and best practices are followed by working with product and platform teams to plan, implement, and monitor security controlsIdentify opportunities to automate internal, cloud, and platform security controls with Secure DevOps / Secure SDLC in mindProvide subject matter expertise and conduct in-depth security reviews of applications and microservicesIdentify and propose process improvements to reduce riskLead incident response, including steps to minimize impact and conduct technical/forensic investigationsWhat we offerCompetitive discretionary bonusMarket-leading RRSP match programMedical, dental, vision, life, and disability benefitsEmployee Share Purchase PlanMaternity/Parental top-upGenerous vacation policy and personal daysVirtual events to connect with colleaguesAnnual professional development allowance and Career Development programA fulfilling opportunity to join one of the top FinTechsThe incumbent will be working hybrid; in-office time at Ontario Street, Toronto, ON.Equitable
📌 Senior Security Engineer (Toronto)
🏢 EQ Bank | Equitable Bank
📍 Toronto