Cloud Security Engineer is responsible for researching, deploying, and maintaining security technologies that support our defense-in-depth strategy in accordance with TMX regulations and guidelines. Reporting to the Manager of Security Engineering, the Cloud Security Engineer is responsible for the design, planning, testing, implementation, and administration of industry-accepted cybersecurity principles, practices, and systems. This role ensures the protection of information assets processed, stored, or transmitted across TMX Group's multi-cloud instances. As a vital member of the Information Security Team, you will act as the key liaison between Security Engineering, Cloud Technology, and Infrastructure Support teams to drive security alignment, risk mitigation, and compliance.
- This role reports to: Manager, Security Engineering
- Job Location: Hybrid (2-3 days/week in office) - based in Toronto, ON.
Key Accountabilities- Cloud Security Operations & Operations Support: Lead the implementation, configuration, and day-to-day operation of cybersecurity technologies within TMX Group multi-cloud environments across various business units.
- Architecture & Resilient Design: Assist in designing and implementing resilient information security architecture and controls for optimal threat protection, continuous monitoring, and effective Incident Response in the cloud.
- Vulnerability Analysis & Threat Intelligence: Analyze threat and vulnerability feeds for applicability to TMX's cloud footprint; perform compensating controls analysis, validate control efficacy, and resolve false-positive finding assessment results.
- Cross-Functional Collaboration & Influence: Act as the primary liaison between Security Engineering and Cloud Infrastructure teams, influencing internal partners to ensure cloud solutions align with TMX policies, architectural standards, and security programs.
- Risk Management & Compliance Monitoring: Monitor and advise on IT-related security compliance, partnering with stakeholders to execute risk management workflows that identify, remediate, and report on cloud security risks.
- Automation & Continuous Improvement: Develop and implement key security metrics, measurement criteria, and automated governance to ensure ongoing compliance, control verification, and proactive threat mitigation.
- Stakeholder Support & Guidance: Advise internal teams on emerging cloud threats, regulatory expectations, and standard methodologies while providing mentorship to technical partners.
Must Have(s)- Cloud Platform Expertise: Hands-on experience securing at least one major cloud provider (AWS, Azure, or GCP), with deep technical knowledge of native security configurations, compute, storage, and network models.
- Identity & Access Management (IAM): Proven ability to design and manage Role-Based Access Controls (RBAC), Attribute-Based Access Controls (ABAC), federation (SAML/OIDC), Single Sign-On (SSO), and strictly enforce least privilege in multi-account enterprise architectures.
- Infrastructure as Code (IaC) & DevSecOps: Proficiency with automation tools such as Terraform or AWS CloudFormation, with experience embedding security testing directly into CI/CD pipelines to enforce automated guardrails.
- Automation & Scripting: Strong scripting/coding skills for automating repetitive security tasks, log parsing, API integrations, and automated remediation workflows.
- Data Protection & Cryptography: Advanced knowledge of data-at-rest and data-in-transit encryption, Key Management Services (KMS), Hardware Security Modules (HSM), and enterprise secrets management tools (e.g., HashiCorp Vault, AWS Secrets Manager).
- Network Security & Zero Trust: In-depth experience with VPC design, micro-segmentation, Web Application Firewalls (WAF), egress filtering, and implementing Zero Trust Architecture (ZTA) principles.
- Container & Orchestration Security: Practical experience securing containerized workloads and platforms (e.g., Kubernetes), including network policy enforcement, secrets protection, and runtime security.
- Threat Modeling & Assessment Methodologies: Strong understanding of threat modeling frameworks, impact levels, and security assessment approaches (black, gray, and white-box testing).
Salary Range: 120K/year - 123K/year CAD. Please note that the salary range included is a guideline only. The salary offered may vary based on factors, including, but not limited to, the successful candidate's relevant knowledge, skills, and experience.
The recruiting efforts for this role are intended to fill a vacant position.