Senior Security Engineer
The Senior Security Engineer will develop security requirements and design and implement security solutions while collaborating with business and technology teams. They will also provide technical leadership and ensure compliance with security standards.
- Hybrid
- Victoria, BC
- Posted Jul 17, 2026
- Apply by Aug 16, 2026
- 1 position
Job summary
About the job About Us British Columbia Investment Management Corporation (BCI) offers an exceptional opportunity to work at a world-class organization while living in a west coast setting. With $313.7 billion of gross assets under management, as of March 31, 2026, British Columbia Investment Management Corporation (BCI) is the provider of investment management services for British Columbia’s public sector and one of the largest asset managers in Canada. BCI seeks investment opportunities around the world and across a range of asset classes that convert savings into productive capital. Our investment returns play a significant role in helping our institutional clients build a financially secure future for their beneficiaries. BCI is working with an external recruitment firm. Please do not submit your application directly to BCI. Applications submitted through this site will not be reviewed. To explore this opportunity, please contact IT | IQ (Senior Security Engineer). Only qualified candidates who match the requirements will be contacted. Closing Date: Open Until Filled ITIQ, in partnership with British Columbia Investment (BCI) is seeking an experienced Senior Security Engineer to join the Security Engineering and Operations team. Reporting to the Senior Manager, Cyber Security Engineering & Operations, the Security Engineer is responsible for security processes, technologies, and projects with various levels of complexity. The Security Engineer will be instrumental in developing security requirements and designing and implementing security solutions. The Security Engineer collaborates and communicates with business and technology teams in an Agile hybrid environment and enables the effective and efficient delivery of secure, quality products. At all levels, the Security Engineer may be assigned to one or more focus areas requiring additional specialized expertise and responsibilities. WHAT YOU BRING Bachelor’s degree in technology, engineering, computer science, or a related field A minimum of 5 years of experience in progressively senior technical roles with responsibility focused on information security processes, products, and projects Very strong knowledge in engineering secure systems Experience with securing cloud environments (MS Azure) Must have excellent documentation, customer-service, listening, communication and problem-solving skills Must be able to implement programs, security technologies and solutions to measure and sustain the security posture of large, complex environments Experience with Agile methods (Scrum) and DevOps practices is an asset Professional certifications such as Global Information Assurance Certification (GIAC), Certified Information Systems Security Professional (CISSP), Offensive Security Certified Professional (OSCP), Certified Information Security Manager (CISM) or equivalent experience is essential TECHNICAL SKILLS AND REQUIREMENTS Must have some combination of strong hands-on experience with at minimum 4 or 5 of the following skills or technologies: Identity and access management systems for hybrid environments Secure coding practices Systems engineering Ethical vulnerability research and threat modeling Windows, UNIX, and Linux operating systems security, virtualization technology security, container security and serverless computing security Privileged access management systems for hybrid environments EDR and/or other endpoint protection technologies Firewall, intrusion protection and intrusion detection systems Zero Trust system design Cloud Native Application Protection Platform (CNAPP) systems Secure application design principles Data Classification and DLP solutions Enterprise vulnerability management, including vulnerability assessment, remediation, and reporting Incident response Various networking technologies, including subnetting, NAC, DNS, encryption technologies and standards, VPNs, VLANs, VoIP and other network routing methods Phishing and social engineering YOUR DAY TO DAY - WHAT YOU GET TO DO Development of new and innovative ways to solve existing production security issues as well as evaluate new technologies and processes that enhance security capabilities Develops technical security requirements for new products, tools and services envisioned for implementation at BCI Help and guide projects during solution design phase Collaborates and coordinates with application, operations, and product teams to provide guidance on the development of secure product designs that meet security requirements Architects, analyzes, and recommends security controls and procedures in business processes related to the use of information systems and assets, and monitors for compliance Provides technical leadership, mentoring and coaching to team members and creates a culture of customer-centricity, accountability, and high performance Ability to communicate complex security issues and develop security user stories in language that non-technical stake holders can understand Ability to deliver and test security solutions in alignment with industry security standards Ability to respond to information security issues at each stage of a project’s lifecycle Proactively identifies risks and issues and proposes solutions to remove barriers Performs validation and tuning of security testing tools to provide accurate and actionable results that drive improvements to BCI’s overall security posture Performs security monitoring of solutions and participates as a subject matter expert in security incident response scenarios Ensures that all application and infrastructure solutions are stable, secure, and compliant with security standards and policies Undertakes special projects or assignments as required Ability to document designs as well as produce technical reports in support of security initiatives Performs other related duties as required WORK LOCATION There is a strong preference for Victoria, BC; however, we will consider Vancouver, BC for the right candidate, with the expectation of occasional travel to Victoria. We are an in-person collaborative organization with the flexibility to work remotely one day a week. Candidates must be in Victoria, BC or Vancouver, BC or willing to relocate. Relocation Options are available for interested candidates outside of the region. SALARY RANGE The annualized base salary range for this role is CAD $135,000 to $160,000 at the senior level, and CAD $125,000 to $150,000 if you have fewer than the required years of experience. Our recruitment process requires that the successful candidate agrees to undergo a criminal record search, education and designation verification; to provide a declaration of no previous or current criminal status; and to comply with our corporate Code of Ethics & Professional Conduct. Interested in joining our team and want to learn of other career opportunities with BCI? Create a profile and sign up for job alerts at: https://bci.wd10.myworkdayjobs.com/BCI_Careers.
What you’ll do
The Senior Security Engineer will develop security requirements and design and implement security solutions while collaborating with business and technology teams. They will also provide technical leadership and ensure compliance with security standards.
Requirements
Candidates must have a bachelor's degree in a related field and at least 5 years of experience in information security. Strong knowledge of secure systems engineering and experience with cloud environments are essential.
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Information Security
- Cloud Security
- Secure Coding Practices
- Systems Engineering
- Vulnerability Management
- Incident Response
- Identity and Access Management
- Ethical Vulnerability Research
- Data Classification
- DevOps Practices
- Agile Methods
- Endpoint Protection
- Firewall Technologies
- Zero Trust Design
- Networking Technologies
- Security Monitoring
Job areas
- Technology
- Security & Safety
- Finance & Accounting
- Engineering
- Data & Analytics
Additional details
- Minimum education
- Bachelor’s degree
- Minimum experience
- 5+ years
- Apply by
- Aug 16, 2026
- Posting language
- English
- Working hours
- 40 hours per week
- Office presence
- 4 days per week
- Seniority
- Mid-Senior level
