
Cloud Security Engineer
- Toronto, ON
- Permanent
- Full-time
Experience: 7 YearsRole Summary: NearSource is seeking a skilled Cloud Security Engineer with 7 years of experience to strengthen our security posture across cloud and application environments. The selected candidate will serve as a security champion, collaborating with engineering teams to embed secure practices throughout the product lifecycle and ensure compliance with enterprise security standards.Key Responsibilities
- Monitor, evaluate, and maintain systems and procedures to safeguard infrastructure, databases, and web-based applications
- Identify, integrate, and improve information security controls while aligning with business processes and compliance standards
- Conduct vulnerability assessments and oversee remediation to enhance security posture
- Assist with security architecture reviews and lead threat modeling exercises for new features and products
- Research security trends, techniques, and emerging threats to proactively strengthen defenses
- Respond to alerts from security tools, triage incidents, and perform detailed analysis of potential security issues
- Troubleshoot and resolve security system and related infrastructure issues
- Collaborate with engineering teams to remediate vulnerabilities and implement best practices
- Promote security by design through knowledge sharing and team education
- Ensure compliance with regulations, privacy requirements, and industry standards
- 7 years of experience in security engineering or a related field
- Minimum 2 years of experience in secure coding and application development
- Strong proficiency in one or more programming languages such as Python, Ruby, or React
- Deep understanding of common application security vulnerabilities and remediation techniques
- Hands-on expertise in application security and secure software development lifecycle (SDLC) practices
- Proven experience integrating security into CI/CD pipelines
- Strong communication skills for effectively conveying vulnerabilities and remediation steps to stakeholders
- Experience across all phases of the application lifecycle
- Familiarity with infrastructure security tools and automation frameworks
- Experience conducting distributed threat modeling and architecture reviews
- Background in monitoring and improving cloud security operations
- Knowledge of regulatory compliance frameworks and privacy laws
We are sorry but this recruiter does not accept applications from abroad.