Cloud Security Engineer

Knk Gt — Canada · Posted ~2 hours ago

Senior Full-time Onsite

Skills

Cloud security architecture Azure AWS Oracle Cloud Infrastructure (OCI) Microsoft Defender for Cloud Microsoft Defender for Endpoint Microsoft Sentinel Azure Firewall Web Application Firewall DDoS Protection Network security EDR SIEM SASE Threat modeling CIS Benchmarks Regulatory compliance Security reporting SOC operations OCI Defender for Endpoint WAF

🔓 Log in to save this job, tailor your resume & track your apply process — 7 days free, no card needed.

Log in to add to target list

Summary ✨ AI‑Generated

A permanent cloud security engineering role focused on designing and implementing security architecture across multiple major cloud platforms. You will manage cloud-native security services, firewalls, WAF and DDoS controls, endpoint protection, SIEM integrations, security baselines, threat modeling, compliance, and reporting for security operations.

Highlights

Permanent full-time opportunity focused on multi-cloud security across major cloud platforms. The role provides substantial ownership of security architecture, threat protection, compliance controls, SOC integration, and executive-level reporting.

Description

Position: Cloud Security Engineer – Multi-Cloud (Azure/AWS/OCI) Location: Onsite- Toronto, ON Job type: Full-time/Permanent hiring Seeking a Cloud Security Engineer to design and implement comprehensive cloud security architecture across Azure, AWS, and OCI environments. You'll configure and manage Microsoft Defender for Cloud, Sentinel SIEM, Azure Firewall, WAF policies, and AWS/OCI native security services while enforcing security baselines, CIS Benchmarks, and regulatory compliance controls. This role requires deep expertise in network security, EDR solutions, SIEM/SASE integration, threat modeling, and executive-level security reporting to support SOC operations and governance. Key Responsibilities: Design and implement cloud security architecture across Azure, AWS, and OCI environmentsConfigure and manage Microsoft Defender for Cloud, Defender for Endpoint (Plan 2), and Sentinel SIEMImplement and tune Azure Firewall, WAF policies (OWASP rules), and DDoS ProtectionManage AWS security services: GuardDuty, Security Hub, Inspector, AWS Config, and MacieConfigure OCI Cloud Guard, Security Zones, and VSS (Vulnerability Scanning Service)Enforce security baselines, CIS Benchmarks, and regulatory compliance controls (e.g., Ontario public sector)Implement EDR solutions and manage endpoint security posture across hybrid environmentsDesign and review network security: NSGs, Security Groups, Security Lists, NVA traffic inspectionIntegrate SIEM/SASE solutions and support SOC operations with detection and response runbooksConduct security risk assessments, threat modelling, and architecture reviewsPrepare governance documentation, security artefacts, and executive-level security reporting Required Skills: Tools/Frameworks: Defender for Cloud, Sentinel, Defender for Endpoint, Azure Firewall/WAF/DDoS, GuardDuty, Security Hub, Inspector, Config, Macie, OCI Cloud Guard/VSS, EDR (CrowdStrike, Carbon Black, Defender), SIEM (Splunk, QRadar, Sumo), SASE (Zscaler, Prisma, Netskope), KQL, Playbooks, Analytics rules, Workbooks Database/Cloud: Azure (Landing Zones, Policy, Key Vault, Entra ID, Purview, Network Watcher), AWS (IAM, VPC, S3, KMS, CloudTrail), OCI (IAM, Networking, Object Storage, Key Management), Hybrid/Multi-cloud, IAM/RBAC/PIM, Zero Trust, Encryption, Secrets management Nice-to-Have: SASE (Zscaler, Prisma, Netskope), SC-200, AZ-500, AWS Security Specialty, OCI Security Professional, NIST, ISO 27001, SOC 2, Ontario public sector, DevSecOps, IaC security, Container security (Kubernetes, Docker), SOAR, Threat hunting, Purple team, Python, PowerShell, Terraform, Sentinel Data Lake, Graph Security API