This position is listed on behalf of a partner company, who manages all applications and next steps. Our partner is looking for a Senior Security Specialist - Cloud (Global Security) based in Canada.
As a Senior Security Specialist, you will help strengthen the security of complex public cloud environments across AWS, Microsoft Azure, and Google Cloud Platform. You will combine offensive security expertise with hands-on cloud engineering to identify weaknesses and improve resilience in critical production environments. The role provides opportunities to participate in Red and Purple Team exercises while evolving security tradecraft, automation, and tooling. You will work closely with cloud security, operations, threat hunting, intelligence, SOC/incident response, and AI analytics teams. Your ability to translate sophisticated attack paths and technical risks into clear business language will be essential. This is a collaborative, high-performing environment where continuous learning, technical excellence, and meaningful security improvements are strongly encouraged.
Accountabilities:
- Assess and improve the security posture of public cloud environments across Amazon Web Services, Microsoft Azure, and Google Cloud Platform.
- Participate hands-on in Red Team and Purple Team exercises within mature production environments, identifying attack paths, vulnerabilities, and opportunities for defensive improvement.
- Develop, refine, and maintain offensive security tradecraft, automation, and tooling to support cloud security assessments and exercises.
- Build strong partnerships with Cloud Security, Cloud Operations, Threat Hunting, Threat Intelligence, SOC/Incident Response, and AI/ML analytics teams to drive practical cybersecurity improvements.
- Use cloud APIs and command-line interfaces to automate security operations, assessments, and other technical workflows.
- Collaborate with cloud operations teams, internal customers, security operations, business stakeholders, and management during information security incidents and when communicating emerging threats and trends.
- Analyze complex security and vulnerability events and provide actionable recommendations to improve cloud resilience.
- Communicate sophisticated technical concepts, attack paths, and security risks in a clear and accessible way for both technical and non-technical audiences.
- Contribute to security initiatives across cloud architecture, DevOps practices, infrastructure, applications, operating systems, networking, and platform security.
Requirements
- Strong professional experience managing and securing public cloud platforms, with hands-on expertise in AWS, Azure, or GCP.
- Demonstrated experience building systems or platforms within one or more major public cloud environments.
- Strong understanding of modern cloud-centric architectures, DevOps principles, and cloud security practices.
- Experience scripting and automating operational or security activities using cloud APIs, CLIs, or similar tools.
- Intermediate experience with orchestration and configuration management technologies such as Ansible or Puppet, as well as infrastructure-as-code tools such as CloudFormation or Terraform.
- Experience with CI/CD technologies such as Jenkins and an understanding of secure software delivery practices.
- Knowledge of PaaS/SaaS operating environments, including SLAs, load balancing, high availability, operating system patching, networking, and security management.
- Strong technical understanding of Linux and Windows platforms, as well as a broad range of hardware and software technologies.
- 3+ years of cybersecurity experience, ideally including network- and application-layer penetration testing or offensive security activities.
- Experience operating Kubernetes environments and understanding multi-tenancy and its security implications is an advantage.
- Relevant certifications in information security, AWS, Azure, or GCP are considered a plus.
- Strong analytical, problem-solving, decision-making, and strategic-thinking capabilities, with a high level of attention to detail.
- Ability to communicate complex security concepts and technical attack paths effectively to executives, business stakeholders, and broader audiences.
- Highly motivated and performance-oriented, with the ability to set ambitious goals, work through challenging problems, and consistently deliver results.
- Collaborative team player who can build, maintain, and strengthen relationships across technical, business, and security teams.
Benefits
- Comprehensive total rewards program, including bonuses and flexible benefits.
- Competitive compensation, with commissions and stock opportunities where applicable.
- Dedicated annual budget for professional training and conference attendance.
- Access to industry-leading public and private training opportunities to continuously expand technical expertise.
- Coaching, mentorship, and development opportunities supported by experienced leaders.
- Hybrid-remote working environment designed to support flexibility and work-life balance.
- Opportunity to work in complex and critical environments while collaborating with experienced offensive security professionals.
- Exposure to challenging cybersecurity initiatives and progressively greater levels of responsibility.
- Opportunity to make a meaningful and lasting impact on the security of critical technology environments.
- Dynamic, collaborative, progressive, and high-performing team environment.
- Opportunities to build strong relationships across diverse cybersecurity disciplines and expand your professional network.
- Full-time, regular salaried position based in Toronto, Canada, with a standard 37.5-hour work week.
How Jobgether works:
We use an AI-powered matching process to ensure your application is reviewed quickly, objectively, and fairly against the role's core requirements. Our system identifies the top-fitting candidates, and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews, assessments) are managed by their internal team.
We appreciate your interest and wish you the best!
Data Privacy Notice: By submitting your application, you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access, rectification, erasure, objection) at any time.
#LI-CL1