
Cloud Security Engineer
Posted Jun 10

Posted Jun 10
This is a fully remote position, open to applicants in Canada.
• Design and establish cloud security measures within AWS and Google Cloud, encompassing multi-account architecture, network segmentation, data protection, and secure-by-default infrastructure practices.
• Create reusable Terraform modules, reference architectures, policy-as-code guardrails, and self-service tools that facilitate secure implementations for engineering teams.
• Manage and optimize CSPM/CNAPP tools to detect misconfigurations, vulnerabilities, toxic combinations, and coverage gaps within Fullscript’s cloud environments.
• Lead the remediation efforts for cloud vulnerabilities and misconfigurations, balancing risk, engineering workload, customer impact, and business priorities.
• Enhance IAM, secrets management, key rotation, cloud credentials, machine identities, and just-in-time access patterns across cloud and SaaS environments.
• Integrate security into CI/CD pipelines through IaC scanning, container image scanning, SBOM generation, artifact protection, and software supply chain governance.
• Collaborate with the SOC and engineering teams on cloud-native detections, logging, runbooks, incident response, post-incident reviews, and secure AI/ML workload practices.
• More than 4 years of experience in security engineering, with at least 2 years concentrated on cloud security within AWS and/or Google Cloud.
• Solid comprehension of cloud-native attack vectors, IAM vulnerabilities, network controls, data protection, key management, secrets management, and workload identity.
• Practical experience with infrastructure-as-code, preferably Terraform, and a robust understanding of securing it at scale.
• Proficiency in coding with Python, Go, or a similar language for automating detection, remediation, and security processes.
• Experience in integrating security tools into CI/CD pipelines and developer workflows without inducing unnecessary friction.
• Familiarity with at least one compliance framework such as SOC 2, HIPAA, HITRUST, PCI-DSS, or ISO 27001, along with the ability to translate requirements into technical controls.
• Excellent communication and collaboration skills, with a focus on empowering teams, influencing without authority, and assisting engineers in building securely.
• Bonus if you have:
• Experience in healthcare, fintech, or other regulated industries.
• Hands-on experience with CSPM or CNAPP tools like Wiz, Prisma Cloud, Lacework, or similar platforms.
• Expertise in securing Ruby on Rails, JavaScript, TypeScript, GraphQL, containerized workloads, or contemporary cloud-native applications.
• Experience in cloud incident response, forensics, or threat hunting.
• Experience in securing AI/ML workloads, LLM integrations, data science platforms, autonomous AI systems, or non-human identities.
• Knowledge of AI/ML model supply chain risks, AI-specific SBOMs, or controls to limit blast radius and privilege escalation.
• Contributions to open-source projects or experience in developing internal security tools.
• Flexibility to work remotely from locations that suit you best, with a preference for Ottawa, Toronto, Calgary, or Vancouver for this position.
• Flexible PTO and competitive salary, emphasizing the importance of work-life balance.
• RRSP/401k matching and stock options to help you invest in your future.
• Comprehensive benefits package with customizable coverage, paramedical services, and an HSA.
• Discounts on high-quality wellness products through Fullscript.
• Ongoing learning opportunities to enhance your skills and advance your career.
Lime
Threatscape
GFT Technologies
BeyondTrust
Get handpicked remote jobs straight to your inbox weekly.