Cybersecurity Engineer - 405 EN

FinDev Canada

$96K — $128K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Post-secondary degree in Computer Science, Information Security, Engineering, or a related field.
  • Minimum 7 years of hands-on experience in cybersecurity engineering or similar roles.
  • Demonstrated breadth across multiple security domains such as application and cloud security.
  • Experience embedding security into software delivery life cycles and agile workflows.
  • Proficiency with cloud security, preferably Azure, with AWS or GCP experience valued.
  • Strong communication skills to translate technical risks for various audiences.
  • Collaborative and able to operate independently with a curiosity for learning.

Responsibilities

  • Partner with teams to integrate security across EDC's technology stack.
  • Identify security gaps and prioritize remediation plans with platform owners.
  • Design security tooling and standards to enhance EDC's security posture.
  • Contribute to threat modeling and assess new technologies for security impacts.
  • Embed as a security partner within agile teams for secure design and deployment.
  • Conduct security reviews and provide actionable feedback on project documentation.
  • Assess and address security risks associated with AI/ML applications.

Benefits

  • Hybrid work model with office attendance requirements evolving from two to three days per week.
  • Relocation assistance available for eligible candidates.
  • Opportunities for continuous learning and professional growth in a dynamic team environment.
  • Work within a team that values transparent communication and collaboration.
  • Engage with cutting-edge technologies and practices in cybersecurity.
Full Job Description
Application deadline: September 25, 2026 12:00PM ET

Position: Cybersecurity Engineer

Employment Type: Permanent

Compensation Details:
  • Cyber Security Specialist 18: Salaries typically range from $96,557 to $128,742 annually, based on qualifications and experiences, plus a performance-based incentive.
Location:
  • Export Development Canada operates under a hybrid work model, with employees currently required to work from the office two days per week. Effective September 2026, this requirement will increase to three days per week and will be implemented gradually through a phased approach based on employee location. (subject to change).
  • This role can be performed from EDC's headquarters in Ottawa or from one of our Community Hubs located in Toronto or Montreal.
  • Relocation assistance is available for candidates who meet the eligibility criteria.


Internal Employees, please consult the ServiceNow article entitled Internal movements - what you need to know.

Team Overview:

The Digital & Technology Solutions (DTS) group under the leadership of the Chief Information Officer was established in 2023 with the mission of empowering our customers and colleagues to take on the world, by seamlessly delivering secure and reliable digital experiences. Digital & Technology Solutions has set out to achieve the following objectives for EDC:
  • Define, execute, and sustain the integrated technology target state, target data model and technology operations required to enable EDC's 2030 business transformation.
  • Establish and manage the rolling 3 Year Digital Roadmap that sequences the technology outcomes required to achieve the technology target state and facilitate its execution across all domains in the organization.
  • Keep pace with industry trends and emerging technologies, ensuring EDC has access to the digital technology tools it needs to stay relevant in the market and grow Canadian global trade.
  • Lead and ensure integrated digital, data, infrastructure, and cybersecurity implementations to create excellent customer, user, and employee experiences.

This is your opportunity to join a cybersecurity team with a business-first mindset. We're looking for a technically versatile Cybersecurity Engineer to work broadly across EDC's technology stack - an "inch deep, mile wide" generalist who elevates security posture enterprise-wide while partnering directly with delivery teams to co-create solutions that are both secure and business-enabling.

You will not be expected to be a deep specialist in every security domain. Success in this role comes from strong security fundamentals, curiosity, sound judgment, and the ability to learn quickly while partnering with experts across the organization.

You will be part of a growing team of cybersecurity professionals who value transparent communication, innovation, and collaboration with diverse internal and external stakeholders - while remaining equally committed to managing information security risk and delivering on our planned security program obligations.

We encourage applications from candidates who may not meet every listed qualification but bring strong security fundamentals, relevant experience, and a willingness to grow. This role is designed to evolve with the individual as the security program and technology landscape mature.

What you will be doing:

Security Engineering & Posture Improvement:
  • Partner with infrastructure, cloud, and application teams to embed security controls across EDC's technology stack - from cloud-native services and APIs to on-premise systems and SaaS platforms.
  • Identify security gaps and vulnerabilities across the environment, prioritize remediation, and develop tactical plans to address them in collaboration with platform owners.
  • Design and implement security tooling, hardening standards, and automation to continuously improve EDC's security baseline.
  • Contribute to threat modelling, security architecture reviews, and the assessment of emerging technologies before adoption.
  • Monitor the threat landscape and evaluate how new attack techniques may affect EDC's environment, translating findings into actionable improvements.

Secure Delivery Enablement:
  • Embed as a security partner within delivery squads and agile teams, providing hands-on guidance during design, development, and deployment to ensure security is built in - not bolted on.
  • Conduct security reviews of project documentation, architecture diagrams, code changes, and configuration decisions, providing constructive, actionable feedback.
  • Champion secure-by-default patterns, DevSecOps practices, and shift-left security thinking across engineering teams.
  • Develop and maintain security standards, guidelines, and reusable patterns that enable teams to move quickly without compromising security posture.
  • Act as a trusted advisor to product and engineering stakeholders, translating security risks into business language and helping teams make informed risk-based decisions.

AI, Machine Learning (ML) & Emerging Technology Security:
  • Assess and address security risks specific to AI/ML workloads, including model integrity, data pipeline security, prompt injection, and the secure deployment of AI-enabled applications.
  • Support EDC's evolving approach to AI security through risk assessments, security reviews, governance input, and collaboration with platform and delivery teams.
  • Apply AI and ML tools to enhance security operations where appropriate - including anomaly detection, automated threat hunting, intelligent alert triage, or other practical security use cases.
  • Explore and evaluate AI-assisted security tooling to improve team effectiveness and coverage across the environment.
  • Keep pace with industry trends and emerging technologies, ensuring EDC's security practices evolve alongside the technology landscape.

Cross-Functional Collaboration & Communication:
  • Collaborate across the Digital & Technology Solutions group and with business stakeholders to align security practices with strategic objectives and EDC's 2030 transformation roadmap.
  • Communicate complex security concepts clearly to both technical and non-technical audiences, influencing and persuading at multiple levels.
  • Contribute to KPI and metrics development to track and demonstrate improvements in security posture over time.
  • Support continuous improvement initiatives and contribute to the evolution of the EIS team's operating model and security program.
What we are looking for:
  • Post-secondary degree in Computer Science, Information Security, Engineering, or a related field and equivalent practical experience.
  • Minimum 7 years of hands-on experience in cybersecurity engineering, application security, cloud security, or a comparable technical security role.
  • Demonstrated breadth across multiple security domains, such as application security, cloud security, identity, network security, endpoint security, data protection, or vulnerability management.
  • Strength in several security areas, combined with working knowledge across others. Candidates are not expected to be experts in every domain.
  • Experience partnering with software delivery or platform engineering teams - embedding security into SDLC processes, CI/CD pipelines, and agile workflows.
  • Proficiency with cloud security, with Azure preferred and AWS or GCP experience valued, including experience securing cloud-native architectures and services.
  • Hands-on experience with a broad and diverse security toolset, which may include SIEM, vulnerability management, DAST/SAST, secrets management, identity platforms, endpoint security, cloud security tools, or similar technologies.
  • Familiarity with AI/ML security considerations, including securing AI-powered applications and/or using AI tools to enhance security operations.
  • Experience with AI security may include hands-on work, architectural review, governance, risk assessment, proof-of-concept activity, or close collaboration with AI platform teams.
  • Strong communication skills with the ability to translate technical security risk into clear business impact for a range of audiences.
  • Collaborative, curious, and comfortable with ambiguity - able to operate independently while knowing when to engage stakeholders and escalate.
What will make you stand out:
  • Professional certifications such as CISSP, CCSP, CEH, OSCP, Azure Security Specialty, Microsoft Professional Certifications, or equivalent.
  • Experience with AI/ML platforms, LLM security, or securing data science and analytics pipelines.
  • Exposure to platforms such as Copilot Studio, Databricks, SaaS embedded AI or similar enterprise AI services.
  • Familiarity with Salesforce, ServiceNow, and other enterprise SaaS security patterns.
  • Knowledge of Canadian regulatory and compliance frameworks applicable to federal Crown corporations.
  • Experience with scripting or coding, such as Python, PowerShell, or Bash, for security automation.
  • Bilingual in both official languages (English and French).
Eligibility:

EDC is committed to Fair Employment Practices and preference will be given to a candidate who is able to work legally in Canada at the time of application (Canadian Citizens or Permanent Residents). Candidates must meet the requisite government security screening requirements.

This position is open to individuals who meet all the essential criteria outlined above and submit their applications by the closing date. Ready to make a difference? This is your chance to join a dynamic, growing team and leave your mark on our organization, development finance, and the world.

Apply today!

Want to learn more about EDC? Check our website at https://www.edc.ca

Similar Jobs

More Jobs at FinDev Canada

More Information Technology Jobs

Find similar Cybersecurity Engineer - 405 EN jobs: