3 days ago
Responsibilities
- Design, develop, test, and deploy cloud and application security solutions across AWS, Azure, and GCP.
- Implement and integrate security products, configure secure baselines, and conduct Kubernetes and cloud security architecture reviews and remediation.
- Build production-quality code and infrastructure, including secure CI/CD pipelines, infrastructure-as-code modules, and cloud landing zones.
- Configure identity, access, encryption, networking, monitoring, and other security controls while aligning cloud environments with security practices and compliance requirements.
- Conduct security assessments and threat modeling to identify vulnerabilities, misconfigurations, and compliance gaps.
- Deliver cloud and application security strategy engagements and advise clients on improving their security practices.
- Integrate automated security tools and secure coding practices into software development lifecycles and CI/CD pipelines.
- Prepare reports, presentations, technical documentation, runbooks, ADRs, and other client deliverables communicating security findings and recommendations.
- Lead technical workstreams and engineering pods, mentor associates, review code, and collaborate with cloud engineers, developers, risk advisors, data architects, and business consultants.
- Contribute to pre-sales through proofs of concept, demos, prototypes, RFP technical content, and solution architecture artifacts.
- Embed with customers to deploy and operationalize security or AI products, build custom integrations and telemetry sources, and convert customer feedback into product improvements.
Requirements
- Bachelor’s degree in Computer Science, Software Engineering, Cybersecurity, or a related STEM discipline.
- At least 3 years of relevant hands-on experience in software development, security engineering, DevSecOps, or cloud security; the posting states 3–6+ years.
- Hands-on experience with at least one major cloud platform, including IAM, networking, KMS, native security services, and Terraform.
- Depth in cloud security or application security, including relevant Kubernetes, container security, CSPM/CNAPP, secure SDLC, SAST/DAST/SCA, API security, threat modeling, secure code review, secrets management, or supply-chain security experience.
- Familiarity with security platforms such as Microsoft Defender, Google SecOps/Chronicle, CrowdStrike, Splunk, or Sentinel.
- Understanding of cloud security concepts, secure application development, OWASP Top 10 vulnerabilities, and remediation practices.
- Proficiency in one or more scripting or programming languages such as Python or Java.
- Experience conducting security architecture reviews or implementing security controls for cloud services and applications.
- Experience in project-based or consulting environments and the ability to communicate technical findings in business terms.
- Knowledge of NIST CSF, ISO 27001, CSA Cloud Controls, or comparable security standards and frameworks is advantageous.
- Professional certifications such as CCSP, AWS or Azure Solutions Architect, CISSP, CKS, or relevant cloud, application, or cybersecurity certifications are preferred.
- Experience with AI security, LLM application development, prompt engineering, RAG, LangChain, LangGraph, MCP server development, PyTorch, HuggingFace, MLOps, AI red-teaming, or LLM observability is preferred.
- Experience working directly in customer environments and debugging Linux, Kubernetes, networking, and distributed systems is preferred.
- Bilingual French and English capability is indicated in the job title.
Benefits
- Hybrid work environment with exact team expectations discussed during the interview.
- Competitive compensation package, inclusive benefits, wellbeing support, and flexibility programs.
- Eligible employees may participate in variable incentive pay programs.
- Accommodation is available throughout the application, interview, and employment process.
- The posting indicates that PwC Canada does not offer work visa sponsorship for this role.
Tech Stack
Categories
Forward Deployed
About PwC
At PwC, we help clients drive their companies to the leading edge. We’re a tech-forward, people-empowered network with more than 370,000 people in 149 countries. Across audit and assurance, tax and legal, deals and consulting we help build, accelerate and sustain momentum. Find out more at www.pwc.com. PwC: Audit and assurance, consulting and tax services PwC refers to the PwC network and/or one or more of its member firms, each of which is a separate legal entity. Content on this page has been prepared for general information only and is not intended to be relied upon as accounting, tax or professional advice. Please reach out to your advisors for specific advice.