Cloud Security Engineer
The Cloud Security Engineer is responsible for designing, deploying, and maintaining security technologies across multi-cloud environments to ensure the protection of information assets. This role acts as a liaison between security and infrastructure teams to drive compliance, risk mitigation, and automated governance.
- Hybrid
- Toronto, ON
- Posted Sep 4, 2026
- 1 position
More jobs you can apply to directly
Similar opportunities posted by employers hiring on Jobs.ca, with no external application form.
Job summary
Venture outside the ordinary - TMX Careers The TMX group of companies includes leading global exchanges such as the Toronto Stock Exchange, Montreal Exchange, and numerous innovative organizations enhancing capital markets. United as a global team, we’re connecting cross-functionally, traversing industries and geographies, moving opportunity into action, advancing global economic growth, and propelling progress. Through a rich exchange of ideas, meaningful collaboration, and a nimble operating model, we're powering some of the nation's most critical systems, fueling capital formation and innovation, bringing increased opportunity to business visionaries, product ingenuity to consumers, and career exploration to our team. Ready to be part of the action? The Cloud Security Engineer is responsible for researching, deploying, and maintaining security technologies that support our defense-in-depth strategy in accordance with TMX regulations and guidelines. Reporting to the Manager of Security Engineering, the Cloud Security Engineer is responsible for the design, planning, testing, implementation, and administration of industry-accepted cybersecurity principles, practices, and systems. This role ensures the protection of information assets processed, stored, or transmitted across TMX Group’s multi-cloud instances. As a vital member of the Information Security Team, you will act as the key liaison between Security Engineering, Cloud Technology, and Infrastructure Support teams to drive security alignment, risk mitigation, and compliance. This role reports to: Manager, Security Engineering Job Location: Hybrid (2–3 days/week in office) – based in Toronto, ON. Key Accountabilities Cloud Security Operations & Operations Support: Lead the implementation, configuration, and day-to-day operation of cybersecurity technologies within TMX Group multi-cloud environments across various business units. Architecture & Resilient Design: Assist in designing and implementing resilient information security architecture and controls for optimal threat protection, continuous monitoring, and effective Incident Response in the cloud. Vulnerability Analysis & Threat Intelligence: Analyze threat and vulnerability feeds for applicability to TMX’s cloud footprint; perform compensating controls analysis, validate control efficacy, and resolve false-positive finding assessment results. Cross-Functional Collaboration & Influence: Act as the primary liaison between Security Engineering and Cloud Infrastructure teams, influencing internal partners to ensure cloud solutions align with TMX policies, architectural standards, and security programs. Risk Management & Compliance Monitoring: Monitor and advise on IT-related security compliance, partnering with stakeholders to execute risk management workflows that identify, remediate, and report on cloud security risks. Automation & Continuous Improvement: Develop and implement key security metrics, measurement criteria, and automated governance to ensure ongoing compliance, control verification, and proactive threat mitigation. Stakeholder Support & Guidance: Advise internal teams on emerging cloud threats, regulatory expectations, and standard methodologies while providing mentorship to technical partners. Must Have(s) Cloud Platform Expertise: Hands-on experience securing at least one major cloud provider (AWS, Azure, or GCP), with deep technical knowledge of native security configurations, compute, storage, and network models. Identity & Access Management (IAM): Proven ability to design and manage Role-Based Access Controls (RBAC), Attribute-Based Access Controls (ABAC), federation (SAML/OIDC), Single Sign-On (SSO), and strictly enforce least privilege in multi-account enterprise architectures. Infrastructure as Code (IaC) & DevSecOps: Proficiency with automation tools such as Terraform or AWS CloudFormation, with experience embedding security testing directly into CI/CD pipelines to enforce automated guardrails. Automation & Scripting: Strong scripting/coding skills for automating repetitive security tasks, log parsing, API integrations, and automated remediation workflows. Data Protection & Cryptography: Advanced knowledge of data-at-rest and data-in-transit encryption, Key Management Services (KMS), Hardware Security Modules (HSM), and enterprise secrets management tools (e.g., HashiCorp Vault, AWS Secrets Manager). Network Security & Zero Trust: In-depth experience with VPC design, micro-segmentation, Web Application Firewalls (WAF), egress filtering, and implementing Zero Trust Architecture (ZTA) principles. Container & Orchestration Security: Practical experience securing containerized workloads and platforms (e.g., Kubernetes), including network policy enforcement, secrets protection, and runtime security. Threat Modeling & Assessment Methodologies: Strong understanding of threat modeling frameworks, impact levels, and security assessment approaches (black, gray, and white-box testing). Salary Range: 120K/year - 123K/year CAD. Please note that the salary range included is a guideline only. The salary offered may vary based on factors, including, but not limited to, the successful candidate’s relevant knowledge, skills, and experience. The recruiting efforts for this role are intended to fill a vacant position. In the market for… Excitement - Explore emerging technology and innovation, as well as ventures and digital finance that shape the future of global markets! Experience the movement of the market while grounded in the stability of close to 200 years of success. Connection - With site hubs in some of the world’s most multicultural cities, we leverage our size and structure to create rich connections and belonging while experiencing powerful global impact through our work. Impact - More than a platform, we use our talents to power mission-critical systems that drive global economic advancement, innovation, and growth. As well, our employee-led Team Impact spreads social good via our giving strategy. Wellness - From empathetic leadership to a culture of flexibility and balance, we believe wellness at work creates the maximum yield and a stronger “we”. Plus, with a cloud-first and hybrid workstyle, as well as generous time-off and leaves, we support a life well lived! Growth - From a growth mindset in our work, to expansion in our business, TMX is home to action-takers energized by the achievement of ambitious growth. Ready to enrich your career with impactful work, leaders who truly care, and the flexibility and programs to help you thrive as part of #TeamTMX ? Apply now. Please note that our company is not currently sponsoring work permit applications and the applicant must be authorized to work in the country where this position is located. TMX is committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate. We provide accommodations for applicants and employees who require it.
What you’ll do
The Cloud Security Engineer is responsible for designing, deploying, and maintaining security technologies across multi-cloud environments to ensure the protection of information assets. This role acts as a liaison between security and infrastructure teams to drive compliance, risk mitigation, and automated governance.
Requirements
Candidates must have hands-on experience securing major cloud platforms like AWS, Azure, or GCP and proficiency in infrastructure as code tools such as Terraform. Strong knowledge of identity management, network security, and container orchestration is required to support a defense-in-depth strategy.
Benefits
• Generous time-off • Leaves • Flexible workstyle • Wellness programs
Listed skills
- Microsoft AzurePreferred
- KubernetesPreferred
- Amazon Web ServicesPreferred
- Google CloudPreferred
- TerraformPreferred
Other relevant skills
Identified from the job description. Confirm important requirements above.
- Cloud Security
- AWS
- Azure
- GCP
- IAM
- Terraform
- CloudFormation
- DevSecOps
- Scripting
- Cryptography
- Network Security
- Zero Trust Architecture
- Kubernetes
- Threat Modeling
- Vulnerability Analysis
- Compliance Monitoring
- Empathy
- Influencing Skills
- Cross-Functional Collaboration
- Ingenuity
- Defense In Depth
- Pipelines
- Zero Trust Architecture (ZTA)
- Influencing Without Authority
- CI/CD
- Multi-Cloud
- Cyber Threat Intelligence
- Workflow Management
- Growth Mindedness
- AWS CloudFormation
- Emerging Technologies
- Resilience
- Risk Mitigation
- Infrastructure as Code (IaC)
- Hashicorp Vault
- IT Security Architecture
- Access Controls
- Application Programming Interface (API)
- Amazon Web Services
- Automation
- Microsoft Azure
- Management
- Capital Markets
- Cloud Computing
- Cloud Infrastructure
- Continuous Improvement Process
- Continuous Monitoring
- Cyber Security
- Information Privacy
- Encryption
Job areas
- Technology
- Security & Safety
- Software
- Finance & Accounting
- Engineering
- Cloud Security Engineer
- Cyber Security Engineer
- Database and Network Professionals Not Elsewhere Classified
- Information Security Engineers
- Computer Occupations, All Other
Additional details
- Minimum experience
- 5+ years
- Posting language
- English
- Working hours
- 40 hours per week
- Office presence
- 3 days per week
