Summary
✨ AI‑Generated
A permanent cloud security engineering role focused on designing and implementing security architecture across multiple major cloud platforms. You will manage cloud-native security services, firewalls, WAF and DDoS controls, endpoint protection, SIEM integrations, security baselines, threat modeling, compliance, and reporting for security operations.
Highlights
Permanent full-time opportunity focused on multi-cloud security across major cloud platforms. The role provides substantial ownership of security architecture, threat protection, compliance controls, SOC integration, and executive-level reporting.
Description
Position: Cloud Security Engineer – Multi-Cloud (Azure/AWS/OCI)
Location: Onsite- Toronto, ON
Job type: Full-time/Permanent hiring
Seeking a Cloud Security Engineer to design and implement comprehensive cloud security architecture across Azure, AWS, and OCI environments.
You'll configure and manage Microsoft Defender for Cloud, Sentinel SIEM, Azure Firewall, WAF policies, and AWS/OCI native security services while enforcing security baselines, CIS Benchmarks, and regulatory compliance controls.
This role requires deep expertise in network security, EDR solutions, SIEM/SASE integration, threat modeling, and executive-level security reporting to support SOC operations and governance.
Key Responsibilities:
Design and implement cloud security architecture across Azure, AWS, and OCI environmentsConfigure and manage Microsoft Defender for Cloud, Defender for Endpoint (Plan 2), and Sentinel SIEMImplement and tune Azure Firewall, WAF policies (OWASP rules), and DDoS ProtectionManage AWS security services: GuardDuty, Security Hub, Inspector, AWS Config, and MacieConfigure OCI Cloud Guard, Security Zones, and VSS (Vulnerability Scanning Service)Enforce security baselines, CIS Benchmarks, and regulatory compliance controls (e.g., Ontario public sector)Implement EDR solutions and manage endpoint security posture across hybrid environmentsDesign and review network security: NSGs, Security Groups, Security Lists, NVA traffic inspectionIntegrate SIEM/SASE solutions and support SOC operations with detection and response runbooksConduct security risk assessments, threat modelling, and architecture reviewsPrepare governance documentation, security artefacts, and executive-level security reporting
Required Skills:
Tools/Frameworks: Defender for Cloud, Sentinel, Defender for Endpoint, Azure Firewall/WAF/DDoS, GuardDuty, Security Hub, Inspector, Config, Macie, OCI Cloud Guard/VSS, EDR (CrowdStrike, Carbon Black, Defender), SIEM (Splunk, QRadar, Sumo), SASE (Zscaler, Prisma, Netskope), KQL, Playbooks, Analytics rules, Workbooks
Database/Cloud: Azure (Landing Zones, Policy, Key Vault, Entra ID, Purview, Network Watcher), AWS (IAM, VPC, S3, KMS, CloudTrail), OCI (IAM, Networking, Object Storage, Key Management), Hybrid/Multi-cloud, IAM/RBAC/PIM, Zero Trust, Encryption, Secrets management
Nice-to-Have: SASE (Zscaler, Prisma, Netskope), SC-200, AZ-500, AWS Security Specialty, OCI Security Professional, NIST, ISO 27001, SOC 2, Ontario public sector, DevSecOps, IaC security, Container security (Kubernetes, Docker), SOAR, Threat hunting, Purple team, Python, PowerShell, Terraform, Sentinel Data Lake, Graph Security API