Senior Cyber Security Engineer

CAAT Pension Plan

$125K — $157K *
Information Technology
8 - 10 years of experience
Job Overview by Ladders

Qualifications

  • 8+ years of experience in cybersecurity roles including application security and vulnerability management.
  • Bachelor's degree in Computer Science or related field.
  • Security certifications such as CISSP, CCSP, or Security+ are essential.
  • Familiarity with security standards like ISO 27001, NIST, and CIS.
  • Deep knowledge of various security technologies and operating systems.
  • Strong problem-solving and analytical abilities.
  • Expertise in MITRE ATT&CK and MITRE ATLAS frameworks.

Responsibilities

  • Lead efforts to enhance cloud security adherence to regulatory standards.
  • Deploy and manage advanced security tools and platforms including SIEM and WAF.
  • Collaborate with software engineering teams to integrate security into the development lifecycle.
  • Oversee the Vulnerability Management Program and proactive threat intelligence.
  • Conduct risk assessments and support penetration testing and compliance audits.
  • Develop incident response plans and security playbooks.
  • Utilize Azure Sentinel for incident monitoring and advanced threat investigation.

Benefits

  • Opportunities for professional development and skill enhancement.
  • Comprehensive wellness program prioritizing physical, mental, and financial health.
  • Collaborative and creative work environment recognized as among the best cultures in Canada.
  • Meaningful work contributing to Canadians' retirement security.
Full Job Description

About the Role:

We are seeking a Senior Cybersecurity Engineer for our Information Technology team. The Senior Cyber Security Engineer will play a critical role within the Security Operations team, responsible for safeguarding the organization's IT infrastructure, applications, and data against cyber threats. The role requires deep expertise in security monitoring, incident response, vulnerability management, and cloud security, ensuring the organization's security posture remains strong. The successful incumbent will bring hands-on experience with security tools and platforms such as Splunk Enterprise Security, Azure Cloud Security, CrowdStrike, Rapid7 InsightVM, Imperva WAF, and Data Loss Prevention (DLP) solutions. They will drive proactive threat detection, incident response, and security enhancements, working closely with cross-functional teams to implement robust security measures.

As the Newest Member of our Team, You’ll:

  • Provide SME leadership to improve Cloud security posture, ensuring adherence to regulatory standards and best practices across all infrastructure and services.

  • Deploy and manage WAF, DLP (endpoints, cloud, email), XDR/ EDR platforms, Cloud Security tools (CrowdStrike CNAPP, Tenable CSPM) and SIEM and SOAR (Azure); lead Incident Response efforts while integrating AI/ML threat detection to safeguard against evolving AI based and data-centric risks.

  • Partner with software engineering teams to embed secure coding, conduct application security testing (SAST &DAST), and reinforce application-layer defenses throughout the SDLC.

  • Manage and enhance the Vulnerability Management Program using Tenable; provide SME-level threat intelligence to proactively track emerging vulnerabilities and drive the implementation of security patches, configuration changes, and targeted mitigations.

  • Conduct regular risk assessments, support penetration testing (external & internal), and compliance audits to enforce adherence to industry frameworks (ISO 27001, NIST, CIS, GDPR, SOC 2), while actively supporting all security audit and regulatory requirement initiatives.

  • Develop and continuously refine security playbooks, incident response plans, and threat-hunting methodologies to strengthen detection capabilities and organizational resilience.

  • Monitor, analyze, and respond to incidents via Azure Sentinel; provide SME-level support to analysts using CrowdStrike and Azure Sentinel for advanced threat investigations, while crafting SIEM use cases tailored to the current threat landscape.

  • Lead IR efforts—including containment, eradication, and forensic analysis—while executing a strategic vision to develop innovative approaches that accelerate threat response and remediation and continuously refine incident response plans and threat-hunting methodologies.

  • Harden CAAT environments against AI/ML-based attacks; provide technical mentorship to junior security engineers and analysts; and clearly communicate security risks and mitigation strategies to stakeholders.

  • Lead the documentation of security incidents, technical project requirements, runbooks, and standard operating procedures to institutionalize knowledge across teams as an SME.

  • Ensure adherence to industry standards (ISO 27001, NIST, CIS, GDPR, SOC 2) and actively support security audits and regulatory compliance initiatives.

  • Communicate security risks and mitigation strategies to stakeholders, collaborate cross-functionally with IT, development, and operations to embed security across the organization, and manage multiple concurrent projects while applying strong analytical and problem-solving skills, working autonomously with excellent written and verbal communication.

  • Integrate secure coding practices into the SDLC; conduct SAST, DAST, and IAST; perform secure code reviews; and provide tailored remediation guidance to development teams.

  • Manage WAF and related security solutions against OWASP Top 10 threats (SQLi, XSS, insecure deserialization); enforce API security (authentication, authorization, encryption) alongside OAuth, JWT, and MFA; and conduct threat modeling and risk assessments to identify application weaknesses.

  • Embed security controls into CI/CD pipelines to automate vulnerability scanning and compliance checks; utilize SCA to track and mitigate thirdparty dependency risks; implement secrets management to eliminate hardcoded credentials; and enforce zerotrust principles across DevOps workflows.

  • Partner with development teams as an Application Security SME to foster a securityfirst culture, promoting proactive ownership of security controls throughout software development.

  • Rapidly acquire skills in fastmoving domains (AI, ML, Quantum); understand attacker exploit techniques and remediation methods; maintain expertise across infrastructure, network, endpoint, and mobile security; and provide technical mentorship to junior security engineers and analysts.

To Succeed, You Bring:

  • A minimum of eight (8) years of practical experience in various cybersecurity areas such Application Security, Vulnerability Management, Incident Response, Cloud Security.

  • A degree in the field of computer science.

  • A Relevant security certification such as CISSP, CCSP, Security+, CEH, CompTIA Security, etc.

  • Understanding of security standards and frameworks such as ISO27001, NIST and CIS, etc.

  • Strong knowledge of technical configurations from various operating systems and security solutions (Windows, Linux, Mac, IDS / IPS, DLP, SIEM, SOAR, WAF, VPNs, firewalls, encryption, etc.)

  • Excellent problem-solving and analytical skills to identify and resolve security issues effectively.

  • Excellent understanding of MITRE ATT&CK and MITRE ATLAS frameworks.

  • Good understanding of cloud security concepts and experience securing cloud-based infrastructure is an asset.

  • Proven project management and organizational skills, specifically managing multiple, concurrent projects.

  • Excellent written and verbal communication coupled with an ability to work with minimal supervision.

The target hiring salary for this position is $125,800 to $157,200. Placement within our salary range will be based on factors such as internal equity, market conditions, and the candidates experience, skills, and qualifications relevant to the role.

At CAAT, we believe innovation, passion, and purpose are ingredients for a great work environment. Were incredibly proud of our people and the remarkable impact they have as catalysts for change. Were committed to attracting and keeping great talent, which means competitive compensation, exceptional benefits, and an environment where people can grow and thrive. When you work with CAAT, youll enjoy:

  • Opportunities to Build a Better You: We never stand still. As we grow, so do you. Enjoy a place that provides endless opportunities to learn and master your skills while cultivating new ones.

  • Comprehensive & Holistic Care: Be at your best with a Total Rewards program that feeds and prioritizes your physical, mental, and financial wellness. From flexible work arrangements, comprehensive benefits to wellness incentives, and a defined benefit pension plan we have you covered.

  • A Place to Collaborate and Win: Weve built a lively environment where creativity and open communication thrive. Its why were consistently recognized as one of Canadas Most Admired Corporate Cultures, one of Greater Torontos Top Employers, and one of the Best Places to Work.

  • Work that Truly Matters. Youre giving Canadians the opportunity for better retirement security, and organizations the chance to do more.

If you believe that Canadians deserve a future where a secure lifetime retirement income contributes to their financial and overall well-being, then CAAT could be the right fit for you. Start your journey with us today. Apply now.

Learn more about us by visiting

Vacancy:

This posting is for an existing vacancy

Similar Jobs

More Jobs at CAAT Pension Plan

More Information Technology Jobs

Find similar Senior Cyber Security Engineer jobs: