
Cloud Security Developer
Posted Sep 1

Posted Sep 1
This is a fully remote position, open to applicants in Canada.
• Design, implement, and maintain security solutions for cloud environments to safeguard cloud-based systems and applications.
• Establish and uphold strong security measures for cloud infrastructure and applications.
• Identify, address, and validate security vulnerabilities throughout the cloud infrastructure.
• Carry out architecture and design assessments from a security viewpoint, providing actionable requirements and recommendations.
• Collaborate with security leadership, compliance, development, and engineering teams to execute security strategies effectively.
• Develop, deploy, and manage security tools such as WAFs, IDS/IPS, workload protection, GCP Security Command Center, and Azure Security Center.
• Suggest and contribute to enhancements in security and compliance for CI/CD pipelines and deployment methodologies.
• Automate infrastructure provisioning and deployment using Infrastructure as Code (IaC) tools like Terraform or Pulumi.
• Design and manage scalable processes for granting cloud access while upholding the principle of least privilege.
• Engage in incident detection and response by enhancing observability and alerting mechanisms, supporting the incident response team.
• Self-manage and prioritize tasks independently.
• Assist in audits and first-party security questionnaires.
• Lead and oversee security evaluations and threat modeling activities.
• Implement security measures within Kubernetes environments.
• Develop DevSecOps tools and integrations.
• A minimum of 5 years of experience in an infrastructure- and/or security-oriented role.
• At least 5 years of development experience, preferably with Go and TypeScript/JavaScript.
• Familiarity with common web application vulnerabilities and the OWASP Top 10 framework.
• Ability to analyze and respond to results from DAST and SAST tools (e.g., Tenable, Snyk).
• Strong grasp of DevSecOps principles and experience with CI/CD pipelines (GitHub Actions, Argo CD, Azure DevOps) for automated security testing.
• Experience in deploying and customizing security tools, including vulnerability scanners, static analyzers, web application firewalls (WAFs), intrusion detection/prevention systems (IDS/IPS), and endpoint security monitoring.
• Comprehensive understanding of cloud and network security, with extensive knowledge of Kubernetes.
• Proficiency with GCP, particularly in services such as Security Command Center, GKE, Cloud IDS, Cloud Armor, and Secret Manager.
• Proficiency with Azure, specifically in services like Security Center, Azure PaaS App Services, VMs, Azure SQL, Front Door, and Key Vault.
• Experience in writing infrastructure as code using tools such as Terraform, Pulumi, and Helm.
• Knowledge of prevalent security frameworks and benchmarks, including CIS, NIST, and MITRE ATT&CK.
• Understanding of identity and access management (IAM) principles and cloud-native IAM solutions.
• A strong passion for continuous learning and sharing knowledge.
• Bilingual in English and French.
• Employee mortgage program: exclusive preferred rates.
• Comprehensive health coverage: premium extended coverage (health, dental, and vision), including 100% coverage for prescription drugs.
• Access to a group RRSP/DPSP retirement savings plan with competitive contributions from the employer.
• Telemedicine and family support, featuring supplemental maternity and parental leave programs.
• Flexible workplace options: fully remote or from one of our offices (Montreal, Quebec City, Toronto, and more).
WorkOS
Fortive
Brown and Caldwell
Galileo
Get handpicked remote jobs straight to your inbox weekly.