
Principal Cloud Security Engineer
BMO Financial Group28 days ago
Base Salary
$122k - $228k/yr
Responsibilities
- Assess, design, implement, automate, and document security solutions and controls for AWS and Microsoft Azure.
- Develop cloud security patterns, roadmaps, baseline controls, policies as code, and CI/CD-integrated security practices.
- Review and approve security-sensitive code and changes involving IAM roles, policies, security groups, and related controls.
- Define and implement security frameworks for AI/ML systems across data ingestion, training, deployment, and monitoring.
- Assess and mitigate AI threats including adversarial attacks, model inversion, data poisoning, prompt injection, model theft, jailbreaking, and data leakage.
- Secure AI/ML platforms and tools, including model registries, feature stores, training environments, inference endpoints, and MLOps pipelines.
- Implement data security posture management and controls for databases, data lakes, data warehouses, sensitive data, and file-sharing platforms.
- Lead cybersecurity risk assessments, provide security guidance for technology projects, and advise on cloud, AI, and data security risks.
- Assist with investigation and remediation of security incidents, including AI model compromise and data breaches.
- Serve as a cloud security subject matter expert and collaborate with information security, product, software development, data science, AI engineering, and cloud engineering teams.
- Lead workshops, influence senior leadership, articulate complex security concepts, and mentor less experienced team members.
Requirements
- A university degree in Engineering, Computer Science, Information Technology, or a related field.
- 7–10 years of experience developing and implementing security architectures and/or engineering across cloud, data, and/or AI security domains.
- Security certifications such as CISSP, CCSP, CCSK, AWS Certified Security Specialty, or Microsoft Certified: Azure Security Engineer Associate.
- Knowledge of cloud architecture, cloud operations, cloud IAM, security automation, orchestration, and cloud-native security tools.
- Knowledge of CSA CCM, ISO 27001, ISO 27017, and NIST CSF security control and compliance frameworks.
- Working knowledge of AI/ML frameworks and platforms and familiarity with OWASP Top 10 for LLMs, MITRE ATLAS, and NIST AI RMF.
- Experience with DLP, data classification, data access governance, DSPM, encryption, tokenization, and key management.
- Familiarity with PIPEDA, GDPR, and CCPA and experience securing cloud data platforms such as Snowflake, Databricks, AWS Redshift, or Azure Synapse.
- Strong networking, packet analysis, cryptography, IAM, scripting, programming, API, webhook, and Infrastructure as Code security skills.
- Experience with Python, PowerShell, Bash, Node.js, Checkov, tfsec, Prisma Cloud, Wireshark, Burp Suite, nmap, Nessus, and Metasploit.
- Preferred knowledge or certifications in AI security or data security, including CDAI, CompTIA AI+, CDPSE, or CIPP.
- Strong communication, leadership, research, analytical, problem-solving, relationship-building, workshop facilitation, and stakeholder-influence skills.
Benefits
- Health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans.
- Training, coaching, manager support, and network-building opportunities.
- Salaried position with a stated base salary range of $122,400.00–$228,000.00.
- Opportunity to shape cloud, AI, and data security strategy at a major Canadian financial institution.