Sun Life

Senior Security Platform Engineer (Security Visibility)

Toronto, Ontario Canada
AWS Azure
Search for More Jobs Talk to a recruiter now 💪
Description

You are as unique as your background, experience and point of view. Here, you’ll be encouraged, empowered and challenged to be your best self. You'll work with dynamic colleagues - experts in their fields - who are eager to share their knowledge with you. Your leaders will inspire and help you reach your potential and soar to new heights. Every day, you'll have new and exciting opportunities to make life brighter for our Clients - who are at the heart of everything we do. Discover how you can make a difference in the lives of individuals, families and communities around the world.

Job Description:

About the role:

The Senior Security Platform Engineer (Security Visibility) is responsible for effectively planning, designing, implementing, and monitoring security technologies and projects that support Sun Life’s security policies and procedures.  Your primary responsibilities will be Supporting in Scope Platform and Products and developing use case scenarios, enhancing the security of Sun Life’s corporate and production systems.  You will work closely with Enterprise Infrastructure, IT operations, Enterprise Architecture, and application development teams to identify risks to the business and lead security solutions to protect customer and financial information. 

The successful candidate must be able to interpret complex information, adapt as needed and have a deep understanding of security risks, data impact and controls to help mitigate the risk and provide countermeasures. 

A Senior Security Platform Engineer is a leader who is expected to participate fully in the planning of the work and to seek opportunities for process improvement. The successful candidate is strong in multiple Information Security domains and is expected to lead the efforts to solve complex security problems.

What will you do:

  • Deploy and manage one or more security platforms and tools: Perimeter, Endpoints, Crypto, Cloud, Email Security, and Security Visibility:
  • Email and Anti Malware Security Technologies
  • Cloud platforms security (CNAPP)
  • Intrusion Detection/Prevention System
  • Endpoint Security Solutions (Netskope, CrowdStrike, Semperis)
  • Web Application Firewalls (WAF)
  • Cryptography, Certificate and Key Management (Hashicorp, Venafi, ISG)
  • Security Visibility (SIEM)
  • Analyze information systems utilizing various cybersecurity techniques and lead security initiatives and enterprise level projects implementing security solutions and performing POC/POV for new technologies.
  • Able to work independently with high degree of ambiguity and deliver expected outcomes, be focused on the end deliverables, and build trust with internal clients and peers. 
  • Responsible to deploy, support and maintain new and existing security technologies that are deployed within Sun Life and owned and supported by the team.
  • Implement risk driven security controls and provide SME (Subject Matter Expertise) during Audit.
  • Investigate and respond to security incidents, adhering to defined SLA’s. Participate in teams 24x7 on-call support and be required to join major incident management calls to provide support and consultation.
  • Identify risks to the business and recommend strategies to address those risks.
  • Manage the capacity and resiliency of security systems protecting Sun Life’s internal and client data.
  • Collaborate and build trust with security peers, vendors, and other Sun Life teams to enhance security posture and best practices.
  • A change catalyst for Digital transformation, using JIRA, Confluence, estimating stories, setting definition of done, completing and tracking story updates and assignments.
  • Smoothly transition and operationalize projects and products. This includes developing roles & responsibilities (RACI), completing product documentation and educating the teams who will be performing BAU (Business as usual) the day-to-day work.
  • Document, update and maintain cyber security playbooks, policies and knowledge base articles used to support the established Incident Management and CSIRT processes.
  • Continuously improve operational and security platform processes.

What you need to succeed:

  • An Information Technology University degree/college diploma in related discipline(s) or equivalent work experience.
  • Minimum 5-7 years Information security and engineering experience with enterprise level security technologies in the one or more areas of: Perimeter, Endpoints, Crypto, Cloud, Email Security, Security Visibility, and Automation and Orchestration.
  • Minimum 3 year experience in successfully leading global information security projects.
  • Preferred:  Certification(s) in data network engineering and/or security:  CCNP/CCNP-Security, CCSP, CISSP, GIAC-GCIA, GIAC-GCED, CompTIA, or equivalent security certification.
  • Experience in managing 3rd party security service providers in delivering security services.
  • Broad exposure to multiple security disciplines and in-depth exposure in Incident Response or Detection Engineering.
  • Knowledge of a broad range of security controls and risk management frameworks NIST & (ISO) 2700x standards.
  • Experience with end-point detection and response, intrusion detection, certificate management, email security and web content filtering technologies.
  • Experience designing secure networks and endpoint systems.
  • Experience planning, researching, and developing security policies, standards, and procedures.
  • Experience in a system administration role supporting multiple platforms and applications.
  • Experience with Windows and Linux based operating systems.
  • Experience in deploying enterprise level technology via managed projects using Scrum and Kanban methodologies.
  • Knowledge of networking technologies, firewalls, web application firewalls and intrusion detection and prevention systems.
  • Knowledge of AWS cloud technologies.
  • Knowledge of disaster recovery, technologies, and methods.
  • Strong oral and written communicator with the ability to communicate security technical issues to peers and management.

Individual skills:

  • Problem Solving – Identifies and resolves problems in a timely manner; Gather and analyzes information skillfully; Develops alternative solutions. Exceptional troubleshooting skills.
  • Analytical – Synthesizes complex or diverse information; collects and researches data.
  • Critical Thinking – Uses logic and reasoning to identify alternative solutions/approaches to problems.
  • Technical Skills – Pursues training and development opportunities; Shares expertise with others; Sound knowledge of security technologies for both Cloud and On Premise.
  • Strong leadership and teamwork skills - Motivates others to perform well; effectively influences actions of others; accepts feedback from others.
  • Ability to communicate complex approach to various stakeholders resulting in successful outcomes.
  • Ability to communicate effectively with senior management and user community, both written and oral.
  • Pragmatic understanding of security problems, as a mix of technology and process issues, with the ability to pursue solutions at both layers within the organization. 

Additional skills:

  • Proven experience in Data Centre Routing and Switching Technologies – Layer 2 (VLANs, Rapid PVST, SPAN), Firewalls, Layer 3 (OSPF, BGP, MPLS) are a must.
  • Proven experience with Infrastructure Visibility related technologies – SIEM, IDS/NDR, Threat simulation tools.
  • Strong practical knowledge of AWS and Microsoft Azure cloud technologies and services.
  • Extensive knowledge of Information Security principles, protocols, practices, and industry standards 
  • Solid understanding of existing and emerging Information Security technologies. 
  • Self- Starter, strategic thinker in maturing deployed security technologies to ensure full capabilities are explored to meet enterprise security requirements.
  • Strong hands-on technical skills in both security risks and implementing solutions.
  • Strong investigative mindset with acute attention to detail, sense of ownership, urgency, and drive.

The Base Pay range is for the primary location for which the job is posted.  It may vary depending on the work location of the successful candidate or other factors.  In addition to Base Pay, eligible Sun Life employees participate in various incentive plans, payment under which is discretionary and subject to individual and company performance.  Certain sales focused roles have sales incentive plans based on individual or group sales results. 

Diversity and inclusion have always been at the core of our values at Sun Life. A diverse workforce with wide perspectives and creative ideas benefits our clients, the communities where we operate and all of us as colleagues. We welcome applications from qualified individuals from all backgrounds.

Persons with disabilities who need accommodation in the application process or those needing job postings in an alternative format may e-mail a request to thebrightside@sunlife.com.

At Sun Life we strive to create a flexible work environment where our employees are empowered to do their best work. Several flexible work options are available and can be discussed throughout the selection process depending on the role requirements and individual needs.

We thank all applicants for showing an interest in this position. Only those selected for an interview will be contacted.

Salary Range:

82,000/82 000 - 135,000/135 000

Job Category:

IT - Technology Services

Posting End Date:

26/09/2024
Sun Life
Sun Life
Finance Financial Services FinTech Service Industry

0 applies

0 views

Other Jobs from Sun Life

Lead Software Engineer- Pega

Toronto, Ontario Canada

Senior BI Developer

Gurgaon, India

DevSecOps Engineer 4

Manila, Philippines

There are more than 50,000 engineering jobs:

Subscribe to membership and unlock all jobs

Engineering Jobs

60,000+ jobs from 4,500+ well-funded companies

Updated Daily

New jobs are added every day as companies post them

Refined Search

Use filters like skill, location, etc to narrow results

Become a member

🥳🥳🥳 389 happy customers and counting...

Overall, over 80% of customers chose to renew their subscriptions after the initial sign-up.

To try it out

For active job seekers

For those who are passive looking

Cancel anytime

Frequently Asked Questions

  • We prioritize job seekers as our customers, unlike bigger job sites, by charging a small fee to provide them with curated access to the best companies and up-to-date jobs. This focus allows us to deliver a more personalized and effective job search experience.
  • Salaries for the engineering jobs on our site range from $100K-$200K. On average, senior engineer positions on our EchoJobs are about $160K.
  • The EchoJobs positions have been sourced and vetted from the top companies to work for in the US as a software engineer, including LinkedIn and other reputable job sites. We also have syndicated jobs from companies that have just raised funding, as well as those that have great unique products and culture. From all of these sources, our founder, Morgan, has also resourced the company's authenticity in terms of their website, public appearance, and more.
  • Yes, our users asked us for just this, so now our search filters allow you to search for your top jobs via location, as well as by onsite, remote, or both. Approximately 30% of our jobs are remote, so you’ve got the best options for you!
  • We have not yet implemented this option, but are considering doing so in the future. For the moment, you would need to cancel your subscription, and resubscribe when you wanted to come back.
  • We add new jobs to EchoJobs every day! We scan our sources for the newest jobs, verify them, and post them to EchoJobs within minutes. We add about 2,000-3,000 new jobs for you each day!
  • From starting your job search to getting hired, the entire job search process can take us software engineers anywhere between 3-6 months. However, at EchoJobs, we’re striving to shorten this duration by finding the best, newest jobs for you, so you can do less job searching, and more applying.
  • We’d recommend checking EchoJobs daily, as we add new jobs to the site each day. Additionally, if you got a chance to read our previous email on “what makes EchoJobs different from any other job search tools,” we also recommended that you set a job alert based on your job filters, so if you get emails on those new jobs, you could be checking more than once per day.
  • If you decide to continue with us after the 1-month trial, we definitely recommend this, as we all know it usually takes 3-6 months to find a quality job as a software engineer these days. So to best support you, we just adjusted our membership options at EchoJobs to monthly, 3 months, or 12 months (this option is more for passive job seekers looking a little bit for the future if they want to come back to work or make a job switch potentially. This lets you see what’s out there in case an even better fit job becomes available.)
  • EchoJobs is truly the only job site of its kind. We want to be THE spot for you to find the best job for you, and haven’t encountered any other company doing this. Other job sites are in niches besides software engineering or focus on a small portion of engineering jobs (like a specific coding language). In the words of Morgan, our founder, “I think what makes EchoJobs different is the amount of jobs, frequency that we add new jobs (we add 2,000-3,000 new jobs daily!), and the powerful search engines to find exactly the job you want more easily and efficiently. We can provide you with the most jobs that are vetted by us, we’ll continually find more new jobs for you, and we make it easier for you to apply and get hired.

What Fellow Engineers Say