We’re seeking someone to join our team as a Lead Cybersecurity Operations professional to drive advanced application security, offensive security, AI security testing, and security automation initiatives that strengthen the Firm’s resilience against evolving cyber threats.
In the Technology division, we leverage innovation to build the connections and capabilities that power our Firm, enabling our clients and colleagues to redefine markets and shape the future of our communities. This is a Lead Cybersecurity Ops position at Vice President level, which is part of the job family responsible for monitoring, detecting, and responding to security incidents to ensure the organization's systems and data are protected from actual and potential threats or breaches.
What You'll Do in the Role:
-Collaborate with software development, platform engineering, cloud engineering, and security architecture teams to continuously enhance the security posture of applications, platforms, APIs, and emerging technologies while ensuring the effective implementation of security controls.
-Lead advanced security testing initiatives, including AI-assisted penetration testing, autonomous vulnerability discovery, and intelligent security validation frameworks.
-Design and implement AI/ML-powered security automation solutions to improve testing coverage, accelerate vulnerability identification, and streamline remediation workflows.
-Serve as a Subject Matter Expert (SME) in Application Security, AI Security, and Offensive Security, providing guidance throughout the Software Development Lifecycle (SDLC) to ensure secure-by-design application releases.
-Evaluate, configure, operate, and optimize automated security testing tools, including SAST, DAST, API Security, IaC Security, Container Security, and AI-powered testing platforms.
-Perform advanced manual penetration testing and security assessments of Web Applications, APIs, Mobile Applications, Cloud-Native Applications, GenAI/LLM-enabled systems, and Blockchain/Web3 environments.
-Validate vulnerabilities through manual exploitation, develop proof-of-concept exploits, document attack chains, business impact, and remediation guidance, and communicate findings to technical and executive stakeholders.
-Research emerging attack techniques, AI security threats, blockchain vulnerabilities, and novel exploitation methods, while partnering with development teams to integrate security testing into CI/CD pipelines.
What You'll Bring to the Role
-Bachelor's degree in Cyber Security, Computer Science, Information Systems, Engineering, Mathematics, or a related field, or 10+ years of equivalent Information Security experience.
-Extensive experience performing manual penetration testing of web applications, APIs, mobile applications, cloud-native applications, and distributed systems.
-Strong understanding of Application Security principles, threat modeling, secure coding practices, vulnerability remediation strategies, and security testing methodologies.
-Experience testing AI/ML systems, Generative AI applications, Large Language Models (LLMs), Prompt Engineering security controls, RAG architectures, AI agents, and AI-powered security tooling.
-Knowledge of Blockchain, Smart Contracts, Web3 security architecture, decentralized applications (dApps), cryptographic protocols, and blockchain attack vectors.
-Proficiency with Burp Suite, API security testing methodologies (REST, SOAP, GraphQL, OpenAPI), and modern security testing platforms.
-Development experience with Java and/or modern programming languages such as Python, JavaScript, Go, or C#, including scripting and automation capabilities.
-Strong understanding of authentication, authorization, cryptography, identity and access management, cloud security controls, and effective communication of technical findings to both technical and executive audiences.
Regional Disclosures
All our positions are located in Montreal, Quebec. We offer a hybrid work environment, combining remote work and attendance in the office.
Knowledge of French and English is required.