Security Engineer, DevOps at Curinos Inc | Toronto | Rezi

Security Engineer, DevOps at Curinos Inc

Security Engineer, DevOps

Curinos Inc · Toronto

Today

Security Engineer, DevOps

Curinos Inc · Toronto

14 hours ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now

About the Role

Curinos is seeking an experienced Senior Security Engineer to enhance its Information & Security team. This role focuses on advancing security capabilities in an AWS-native environment, covering cloud security posture management, vulnerability management, threat detection, application security, and incident response. The engineer will design and implement security solutions, reduce risk, and mentor junior team members.

Responsibilities

  • Manage daily security operations and engineering activities in cloud and hybrid environments.
  • Prioritize work based on risk severity, timelines, and dependencies.
  • Partner with Information Security, IT, and Engineering teams to identify and verify remediation.
  • Continuously improve detection and response capabilities.
  • Monitor and respond to findings in AWS Security Hub and Amazon GuardDuty.
  • Tune and author detections to improve signal quality and reduce false positives.
  • Define remediation standards for engineering teams.
  • Manage cloud security posture using a CNAPP platform, setting risk prioritization criteria.
  • Drive remediation with asset owners and identify root causes for recurring findings.
  • Manage the vulnerability management lifecycle using an enterprise platform.
  • Perform assessments, apply risk-based prioritization and SLAs, and drive findings to resolution.
  • Coordinate penetration tests and remediation of their results.
  • Design and embed application security controls within development pipelines.
  • Partner with product and platform engineers to design remediation solutions.
  • Communicate implications and timing of security decisions.
  • Recommend enhancements to code resiliency.
  • Operate and improve endpoint and network detection and response tooling.
  • Develop and tune detections for endpoint and network security.
  • Lead telemetry and threat investigations end-to-end.
  • Coordinate response for security incidents.
  • Lead investigation and response for high-severity security incidents.
  • Lead root-cause analysis and drive post-incident corrective actions.
  • Define and report security posture metrics and KPIs.
  • Explain complex security findings to technical peers, leaders, and external stakeholders.
  • Respond to technical questions from auditors, clients, and vendors.
  • Automate security operations using scripting and infrastructure-as-code.
  • Develop reusable tooling to improve team efficiency and consistency.
  • Stay current with emerging threats, CVEs, and platform changes.
  • Evaluate new security tooling and methodologies through proofs-of-concept.
  • Recommend adoption of new security tools and methodologies.
  • Consult with engineering, IT, and infrastructure teams on security matters.
  • Champion secure-by-design practices.
  • Mentor and provide technical guidance on security matters to junior team members.
  • Advise engineering teams on secure design.

Requirements

  • Deep hands-on expertise designing and operating AWS native security services (Security Hub, GuardDuty, CloudTrail, IAM, VPC).
  • Proficiency in detection tuning and guardrail design for AWS.
  • Strong working knowledge of AWS infrastructure and services to assess architecture for security risk and design remediations.
  • Hands-on proficiency in cloud posture management using a CNAPP platform.
  • Experience identifying misconfigurations, prioritizing risk, driving remediation, and recommending preventative controls.
  • Proficiency driving the vulnerability management lifecycle, including scanning, risk-based prioritization, SLA definition, and driving remediation to closure across a mixed asset inventory.
  • Hands-on experience operating and tuning endpoint and network detection tooling.
  • Experience authoring detections, leading investigations, and coordinating response for endpoint and network security.
  • Experience designing and integrating application security controls (SCA, SAST, secure pipelines) into engineering workflows.
  • Experience partnering with developers on remediation.
  • Solid hands-on experience securing Linux and Kubernetes environments, including hardening, monitoring, and leading remediation.
  • Practical experience applying and helping mature NIST 800-53, CIS Benchmarks, and/or ISO 27001 controls.
  • Experience supporting audits and assessment responses.
  • Proficiency building automation and security-as-code (e.g., Terraform, Python) to operationalize and scale security controls.
  • Ability to mentor junior team members and act as a domain subject-matter expert.
  • 5–8 years of hands-on experience in security operations, security engineering, or related roles.
  • Demonstrated experience driving security workstreams end-to-end.
  • 5+ years hands-on experience with AWS Cloud Services.
  • Hands-on experience with Linux systems administration.
  • Experience with Automation & Infrastructure as Code (Terraform), including designing and maintaining reusable modules.
  • Deep hands-on experience across several of the following areas: AWS security services, cloud security posture management, vulnerability management, endpoint detection and response, network threat detection, or application security tooling.
  • Ability to act as subject-matter expert in at least one of the listed security areas.
  • Strong, hands-on command of cloud security principles in AWS (IAM, networking, logging, encryption).
  • Hands-on experience with AWS CloudWatch (Logs, Metrics, Alarms, APM, and infrastructure monitoring) for visibility and alerting.
  • Familiarity with observability and metrics tooling used to support monitoring, alerting, and security visibility.
  • Experience applying and helping mature security frameworks (NIST 800-53, CIS Benchmarks, ISO 27001), including supporting audits and assessments.
  • Proficiency in Python and/or Bash for building and maintaining security automation and tooling.
  • Bachelor’s degree in computer science, Information Security, or a related field, or equivalent practical experience.
  • Senior-level certification preferred (e.g., AWS Security Specialty or CCSP).
  • Hands-on or foundational certs a plus (e.g., Certified Kubernetes Security Specialist (CKS), Security+, CySA+).
  • Demonstrated experience mentoring or providing technical guidance to other engineers.

Skills

  • AWS cloud security
  • AWS cloud infrastructure
  • CNAPP / cloud posture management
  • Vulnerability management
  • Endpoint and network threat detection
  • Application security tooling
  • Linux
  • Kubernetes
  • Security frameworks (NIST 800-53, CIS Benchmarks, ISO 27001)
  • Security automation & IaC
  • Technical leadership
  • AWS Security Hub
  • Amazon GuardDuty
  • AWS CloudTrail
  • AWS IAM
  • AWS VPC
  • Terraform
  • Python
  • Bash
  • AWS CloudWatch
  • Observability and metrics tooling
  • Certified Kubernetes Security Specialist (CKS)
  • Security+
  • CySA+

Location

  • Canada (Remote/Hybrid)

Work Type

  • Hybrid
  • Remote

Experience Level

  • Senior
  • 5-8 years of hands-on experience
  • 5+ years hands-on experience with AWS Cloud Services

Education Level

  • Bachelor’s degree in computer science, Information Security, or a related field, or equivalent practical experience
  • Senior-level certification preferred (e.g., AWS Security Specialty or CCSP)
  • Hands-on or foundational certs a plus (e.g., Certified Kubernetes Security Specialist (CKS), Security+, CySA+)

Salary/Compensations

  • 110,000-150,000 CAD (plus Bonus)

Benefits

  • Competitive benefits, including a range of Financial, Health and Lifestyle benefits
  • Flexible working options, including home working, flexible hours and part time options
  • Unlimited PTO policy
  • Floating holidays
  • Volunteering days
  • A day off for your birthday
  • Learning and development tools
  • Work with industry leading Subject Matter Experts and specialist products
  • Regular social events and networking opportunities
  • Collaborative, supportive culture
  • Active DE&I program
  • Employee Assistance Program (EAP) providing expert third-party advice on wellbeing, relationships, legal and financial matters
  • Access to counselling services

About the Company

  • Curinos empowers financial institutions to put customers at the center of every decision.
  • Our AI-first platform transforms proprietary data, advanced analytics and deep financial services expertise into timely recommendations - delivered right where teams work.
  • The result: confident decisions, stronger customer relationships, and lasting, profitable growth.

Equal Opportunity

  • Curinos is proud to be an Equal Opportunity Employer.
  • We do not discriminate on the basis of race, color, ancestry, national origin, religion or religious creed, mental or physical disability, medical condition, genetic information, sex (including pregnancy, childbirth, and related medical conditions), sexual orientation, gender identity, gender expression, age, marital status, military or veteran status, citizenship, or other protected characteristics.