Information Security Engineer (Cloud) - Contract

NumerisToronto, OntarioOn-siteContractMid level, 2–5 yearsListed 2 hours ago

Apply now

About this role

Numeris is seeking a hands-on Cloud Security Engineer to build, configure, tune, and operate our security technologies, with a primary focus on Microsoft 365 E5.
This is a deeply technical role, not a deployment coordination or project management position. You will work directly in the platforms, investigate security events, write queries and automation, troubleshoot controls, and continuously improve our security capabilities across Microsoft 365, Azure, and AWS.

What you will do

- Cloud Security Posture & Hardening (AWS, Azure & M365):
- Monitor and operate Cloud Security Posture Management (CSPM) tooling to identify high-priority misconfigurations, network exposures, and toxic risk combinations across AWS and Azure.

- Continuously monitor and improve Microsoft Secure Score, driving actionable configuration enhancements across Entra ID, Defender, and Purview.

- Partner directly with internal DevOps, Infrastructure, and Systems teams to translate posture findings into clear remediation tasks, track remediation timelines, and verify fixes.

- Implement and maintain cloud hardening baselines, data boundaries, and security guardrails—including over-permissioning reviews and sensitivity controls supporting Microsoft 365 Copilot and multi-cloud environments.

Cyber Risk, Change Assessment & Request Handling:

- Manage security intake by evaluating, triaging, and responding to day-to-day security requests, access exceptions, and technical risk inquiries from business and technical teams.

- Perform technical cyber risk assessments for new vendors, cloud architectures, and third-party SaaS integrations.

- Review proposed infrastructure and IT change requests (CAB) to evaluate security impacts, network perimeter exposure, and identity/access risks.

- Document risks, track exceptions, and collaborate with system owners to establish practical compensating controls and standard operating procedures (SOPs).

Vulnerability Management & Operations Support:

- Coordinate vulnerability management workflows: prioritize vulnerabilities using risk and exploitability context, assign remediation tasks to asset owners, and validate patches.

- Provide operational administration for core security tooling (Defender suite, Entra ID, Purview, KnowBe4).

- Author and maintain operational runbooks, security guidelines, and triage procedures to streamline day-to-day security workflows.

- Support security operations with alert triage, investigation assistance, and operational incident follow-ups as needed.

What you have

- 3+ years of hands-on experience in cybersecurity, cloud security analysis, vulnerability management, or security operations (SOC/SecOps).

- Direct operational experience working within Microsoft 365 security portals (Entra ID, Microsoft Defender, Purview).

- Practical familiarity with AWS and/or Azure core security principles (IAM, security groups, resource hardening).

- Proven experience managing security request intake, evaluating risk exceptions, and authoring standard operating procedures (SOPs), runbooks, and process documentation to improve operational consistency.

- Demonstrated ability to collaborate constructively with internal technical teams (IT, DevOps, Engineering) to facilitate and track vulnerability/misconfiguration fixes.

Technical Knowledge:

- Solid working understanding of Cloud Security Posture Management (CSPM) concepts and SaaS security hygiene.

- Familiarity with identity security controls (MFA, Conditional Access, least-privilege RBAC).

- Strong understanding of technical risk assessments, IT change management processes, and request ticketing workflows.

- Baseline understanding of data protection and permission governance for modern AI productivity tools.

Soft Skills & Core Competencies:

- Collaborative Influence: Ability to build positive relationships with DevOps, IT, and software engineering teams, driving remediation through partnership rather than acting as a blocker.

- Pragmatic Risk Prioritization: Strong analytical judgment to filter through alert noise, distinguish critical business risks from low-impact findings, and avoid "alert fatigue."

- Clear & Empathetic Communication: Skill in translating technical cyber risks into clear, business-friendly language for non-technical stakeholders and system owners.

- Curiosity & Adaptability: A proactive mindset for learning emerging platforms, evaluating new cloud features, and staying updated on evolving AI and SaaS security practices.

- Organizational Discipline: Ability to juggle multiple intake requests, triage queues, and remediation follow-ups systematically without letting tasks slip through the cracks.

Preferred Certifications (Asset):

- Microsoft SC-200, SC-300, or AZ-500

- CompTIA Security+ or CySA+

- AWS Certified Cloud Practitioner or Solutions Architect Associate

What's in it for you?

- Be part of an evolutionary journey in the audience measurement and data space; work on exciting projects, add value & make a positive impact to our Company.

- Competitive salary and benefits package (Health, Dental, Vision and Personal Spending Account - employer paid premiums).

- Flexible Work location (on-site offices in Toronto and Montreal, remote – work from home, hybrid as required per role).

- Continuous learning and development via Percipio, our Learning Management System.

- Be part of additional programs such as MentorMe, which helps our employee’s network, and grow within the organization.

- Leadership Training offerings for new and emerging leaders.

- Culture of great teams, coworkers and supportive leadership.

- Perkopolis: Participation in a program that provides exclusive discounts on products and services to employees. Perks include shopping discounts, movie tickets, services, event/show tickets and much more!

Values
 
Stronger Together:
We succeed through collaboration with each other and with the industry. Unity drives our impact.
Innovation with Intent:
We embrace change and challenge convention. Our innovation is purposeful, driven by insights, guided by strategy, and focused on delivering meaningful future-proofed solutions.
People First:
We prioritize the well-being, growth and voices of our people. We actively listen, support development, and create space where everyone can succeed.
Excellence in Motion:
We pursue continuous improvement in everything we do, from our processes to our time to market. With a growth mindset and a commitment to excellence, we bring solutions to life with precision and purpose.
 
Numeris is an equal opportunity employer
We are committed to creating an accessible environment for all our employees and foster a culture that focuses on diversity, equity, inclusion and belonging. We believe that a diverse workforce helps everyone contribute in meaningful ways towards our shared success.