Canada Job Openings
EY
Cloud Application Security Engineer
Toronto
September 2, 2024
EY's people in more than 150 countries are committed to operating with integrity, quality and professionalism in the provision of audit, tax, transaction and consulting services. We strive to help all of our people achieve their professional and personal goals through an inclusive environment that values everyone's contributions, appreciates diversity of thought, fosters growth, and provides continuous opportunities for development. Recognized as one of Canada's top employers, EY continually strives to be a great place to work.
The opportunity
Join our Financial Services Cybersecurity team in Toronto as a Cloud Application Security Engineer. You’ll gain insights into the unique cybersecurity integration challenges in financial services, strategies to secure emerging technologies, and evolving regulatory expectations. You’ll work alongside respected industry professionals, learning about and applying leading cyber risk management and strategy practices at our financial services clients.
This position falls within our Consulting team, which helps our clients enhance the effectiveness of operations functions by assisting them as they shift their emphasis from transaction-level control, processing and reporting to more value driven, decision support and analytics.
Your key responsibilities:
- Security Architecture and Design: Collaborate with development teams to design secure cloud application architectures, considering best practices and industry standards. Assess and recommend appropriate security controls, such as encryption, access controls, and authentication mechanisms.
- Threat Modeling: Conduct threat modeling exercises to identify potential security risks and vulnerabilities in cloud applications. Assess the impact and likelihood of threats and prioritize security mitigations based on risk analysis.
- Secure Development Lifecycle (SDL): Promote and enforce secure coding practices throughout the software development lifecycle. Provide guidance on secure coding techniques, secure code reviews, and vulnerability remediation.
- Cloud-specific Security Controls: Implement and configure security controls specific to cloud environments, such as web application firewalls (WAF), cloud access security brokers (CASB), and container security solutions. Ensure these controls are properly integrated and effectively protect cloud applications.
- Security Testing: Conduct security assessments, penetration testing, and vulnerability scanning of cloud applications to identify and remediate security weaknesses. Perform static and dynamic application security testing (SAST/DAST) and provide recommendations for secure coding and configuration.
- Identity and Access Management (IAM): Implement secure IAM practices for cloud applications, including role-based access control (RBAC), multi-factor authentication (MFA), and privileged access management (PAM). Regularly review and update access permissions to ensure least privilege access.
- Compliance and Regulatory Requirements: Ensure cloud applications comply with relevant industry regulations and standards, such as GDPR, HIPAA, or PCI DSS. Work closely with compliance teams to address security and privacy requirements and support audit activities.
- Security Monitoring and Logging: Configure logging and monitoring mechanisms to detect and respond to security events in cloud applications. Implement log analysis tools and security information and event management (SIEM) solutions to gain visibility into application activities and potential threats.
- Security Awareness and Training: Develop and deliver security awareness programs for development teams, educating them about secure coding practices, common vulnerabilities, and emerging threats specific to cloud applications. Foster a security-conscious culture within the organization.
- Cloud Provider Security Assessment: Conduct security assessments of cloud service providers to evaluate their security controls and compliance with security standards. Assess vendor security documentation, perform due diligence, and make informed decisions regarding cloud service providers.
- Stay Current with Cloud Security Trends: Stay updated with the latest trends, emerging threats, and evolving security technologies in the cloud computing domain. Continuously enhance knowledge and skills through professional development, attending conferences, and participating in relevant training programs.
To qualify for the role you must have:
- Cloud Security Expertise: In-depth knowledge of cloud security principles, concepts, and best practices. Familiarity with major cloud service providers (such as AWS, Azure, Google Cloud) and their security offerings. Understanding of cloud-specific security challenges and solutions.
- Application Security Knowledge: Strong understanding of application security principles, secure coding practices, and common vulnerabilities such as OWASP Top 10. Knowledge of secure development frameworks and methodologies (e.g., Secure SDLC, Dev Sec Ops).
- Cloud Application Architecture: Proficiency in designing and architecting secure cloud applications. Understanding of cloud-native architectures, microservices, serverless computing, and containerization. Knowledge of how security controls can be effectively integrated into cloud application designs.
- Security Assessment and Testing: Experience in conducting security assessments and vulnerability testing of cloud applications. Familiarity with tools and techniques for static and dynamic application security testing (SAST/DAST), penetration testing, and vulnerability scanning.
- Cloud Compliance and Regulations: Knowledge of industry regulations and compliance standards, such as GDPR, HIPAA, PCI DSS, or SOC 2. Understanding of how to design and implement cloud applications that comply with these standards.
- Identity and Access Management (IAM): Proficiency in designing and implementing secure IAM practices for cloud applications. Knowledge of IAM concepts, authentication protocols, role-based access control (RBAC), and federated identity management.
- Secure Development Practices: Strong understanding of secure coding practices and principles. Familiarity with programming languages commonly used in cloud applications (e.g., Java, Python, Java Script) and how to mitigate common security vulnerabilities in code.
- Communication and Collaboration: Strong communication skills to effectively collaborate with development teams, security teams, and other stakeholders. Ability to articulate complex security concepts to both technical and non-technical audiences.
- Continuous Learning: A passion for staying updated with the latest cloud security trends, emerging threats, and evolving technologies. Willingness to acquire new skills and certifications to enhance expertise in cloud application security.
What We Look For
We’re interested in intellectually curious people with a genuine passion for cybersecurity. If you have the confidence in your technical abilities to grow into a leading expert here, this is the role for you.
What We Offer
At EY, our Total Rewards package supports our commitment to creating a leading people culture - built on high-performance teaming - where everyone can achieve their potential and contribute to building a better working world for our people, our clients and our communities. It's one of the many reasons we repeatedly win awards for being a great place to work.
We offer a competitive compensation package where you’ll be rewarded based on your performance and recognized for the value you bring to our business. In addition, our Total Rewards package allows you decide which benefits are right for you and which ones help you create a solid foundation for your future. Our Total Rewards package includes a comprehensive medical, prescription drug and dental coverage, a defined contribution pension plan, a great vacation policy plus firm paid days that allow you to enjoy longer long weekends throughout the year, statutory holidays and paid personal days (based on province of residence), and a range of exciting programs and benefits designed to support your physical, financial and social well-being. Plus, we offer:
- Support and coaching from some of the most engaging colleagues in the industry
- Learning opportunities to develop new skills and progress your career
- The freedom and flexibility to handle your role in a way that’s right for you
Diversity and Inclusion at EY
Diversity and inclusiveness are at the heart of who we are and how we work. We’re committed to fostering an environment where differences are valued, policies and practices are equitable, and our people feel a sense of belonging. From our actions to combat systemic racism and our advocacy for the LGBT+ community to our innovative Neurodiversity Centre of Excellence and Accessibility initiatives, we welcome and embrace the diverse experiences, abilities, backgrounds and perspectives that make our people unique and help guide us. Because when people feel free to be their authentic selves at work, they bring their best and are empowered to build a better working world.
New Job Alerts
Loblaw Companies Limited
Specialist, Communications, Retail
Brampton
FULL TIME
November 14, 2024
View Job DescriptionCanadian Cancer Society
Signature Programs, Cops for Cancer Coordinator
Vancouver
FULL TIME
November 14, 2024
View Job DescriptionIntelcom Courier Canada
Représentant du Service à la Clientèle aux Opérations
Drummondville
FULL TIME
November 14, 2024
View Job DescriptionNOVA Chemicals Corporation
Internal Controls Analyst (Hybrid)
Calgary
November 14, 2024
View Job DescriptionNova Scotia Health Authority
Leader Patient Flow and Operations - Access and Flow
Truro
FULL TIME
November 14, 2024
View Job DescriptionPTW Energy Services Ltd.
Electrician - 3rd/4th Year Apprentices and Journeypersons
Whitecourt
November 14, 2024
View Job DescriptionLooking for similar job?
Amazon Web Services Canada, Inc.
Engenharia de suporte em nuvem II: Big Data (português) // Cloud Support Engineer II: Big Data (Portuguese), Premium Support Team
Toronto
FULL TIME
August 29, 2024
View Job DescriptionAmazon Web Services Canada, Inc.
Cloud Support Engineer - Linux (Portuguese), Premium Support Team
Toronto
FULL TIME
August 29, 2024
View Job DescriptionAmazon Web Services Canada, Inc.
Engenharia de suporte em nuvem II: Análise de dados (português) // Cloud Support Engineer II: Analytics (Portuguese), Premium Support Team
Toronto
FULL TIME
August 29, 2024
View Job DescriptionCat Amania
Architecte de solution Cloud – Spécialiste DevOps – Hybride – Montréal / Canada
Montreal
FULL TIME
September 2, 2024
View Job DescriptionCat Amania
Ingénieurs Cloud – Sécurité (H/F)
Montreal
FULL TIME
September 2, 2024
View Job DescriptionEpsilon Solutions Ltd
Network Cloud Architect
Mississauga
FULL TIME
August 28, 2024
View Job DescriptionSee What’s New: EY Job Opportunities
EY
Consultant / Manager confirmé Sustainability / Développement Durable - Lyon (H/F)
Lyon
November 1, 2024
View Job DescriptionEY
Manager/Senior Manager Climate Change & Sustainability - Mesure d'Impact (H/F)
November 1, 2024
View Job Descriptioney
Consultant(e)s stagiaires ou alternant(e)s en Restructuring (F/H) - Lyon\
Lyon
October 11, 2024
View Job Descriptioney
Consultant stagiaire en investissements publics & Transitions territoriales - Paris
October 11, 2024
View Job DescriptionNew Job Alerts
Loblaw Companies Limited
Specialist, Communications, Retail
Brampton
FULL TIME
November 14, 2024
View Job DescriptionCanadian Cancer Society
Signature Programs, Cops for Cancer Coordinator
Vancouver
FULL TIME
November 14, 2024
View Job DescriptionIntelcom Courier Canada
Représentant du Service à la Clientèle aux Opérations
Drummondville
FULL TIME
November 14, 2024
View Job DescriptionNOVA Chemicals Corporation
Internal Controls Analyst (Hybrid)
Calgary
November 14, 2024
View Job DescriptionNova Scotia Health Authority
Leader Patient Flow and Operations - Access and Flow
Truro
FULL TIME
November 14, 2024
View Job DescriptionPTW Energy Services Ltd.
Electrician - 3rd/4th Year Apprentices and Journeypersons
Whitecourt
November 14, 2024
View Job Description