Senior Cloud Security Engineer
ComPsych Corporation Canada · CA$150K–CA$200K/yr
Mental Health Care · 1,001-5,000 employees
About the role
The Senior Cloud Security Engineer is responsible for securing cloud environments, applications, and AI systems through design, policy as code, and automated guardrails. They will also lead detection, response, and vulnerability management efforts while ensuring compliance with global privacy and security standards.
What they look for
Requirements
Candidates should have 6 to 9 years of security engineering experience with deep expertise in AWS, Azure, and cloud security domains. A bachelor's degree in Computer Science or a related field is required, along with strong skills in data protection, application security, and AI risk mitigation.
Benefits
Full description
About ComPsych
ComPsychⓇ is the worldwide leader in organizational mental health, well-being, and absence management, dedicated to igniting human potential in workplaces across the globe. For over 40 years, we have combined the best in technology with unmatched human expertise to help individuals and their organizations thrive. Our GuidanceResourcesⓇ and AbsenceResourcesⓇ solutions deliver end-to-end mental health, well-being, work-life, health navigation, and absence support to more than 75,000 customers worldwide, touching more than 160 million lives across 200 countries. Visit compsych.com to find out why 40% of the Fortune 500 choose ComPsych for their mental health and absence management needs.
About the Role
This is a fully remote role, with 6 to 9 years of security engineering experience as a guideline rather than a hard requirement. ComPsych is modernizing how it secures the business as it migrates to the cloud and builds AI into its products, and the Senior Cloud Security Engineer is accountable for raising the bar across every security domain, network, application, cloud, data, and AI. The role covers the full security lifecycle, from designing controls, policy as code, and guardrails to directing AI assisted build and validation work, through owning detection, response, and vulnerability management, while keeping human judgment on what ships and how the team responds. Because ComPsych’s platform carries behavioral health data for millions of members, this engineer helps ensure that security and privacy scale with the business rather than slowing it down. Candidates with different levels of experience and strong equivalent experience are encouraged to apply.
What You'll Do
- Secure the cloud, by design and in code. Own cloud security posture management across configuration, workloads, and entitlements (CSPM, CWPP, and CIEM); identity and access management and least privilege, including federation and single sign on, secrets management, privileged access, and workload and non human identities; network segmentation; container security; encryption and key management; and guardrails delivered as policy as code across our cloud environments (AWS primary, Azure), so the secure path is the default for every team.
- Build application security into the pipeline. Shift security left in CI/CD with static, dynamic, and dependency and software supply chain scanning, threat modeling, secrets management, and secure by design reviews, so product teams ship safely by default.
- Engineer network security for a cloud first estate. Design segmentation and zero trust access, firewalls and web application firewalls, and traffic inspection across cloud and hybrid networks, automated and observable rather than manually maintained.
- Protect the data and engineer privacy in. Lead data classification, encryption and tokenization, key management, and data loss prevention, with privacy by design for PHI and ePHI and awareness of data residency and cross border handling across our domestic and international footprint.
- Secure the AI systems we build. Design guardrails, data protection, and abuse and misuse controls for AI, machine learning, and generative AI, addressing risks like prompt injection, model and data poisoning, and sensitive data leakage, and build the monitoring to catch them.
- Own detection, response, and vulnerability management. Tune SIEM and cloud native detections, drive event correlation and incident response, run vulnerability scanning and coordinate penetration testing, and turn findings into fixes with real remediation timelines.
- Advance information security and make secure the easy default. Maintain security baselines and configuration compliance, and the controls, logging, and audit evidence that keep us compliant, coaching engineers across teams rather than gatekeeping.
- Perform other duties as assigned
What We're Looking For
- Education: Bachelor’s degree in Computer Science or a related field; security certifications such as CISSP or a cloud security specialty are a plus.
- 6 to 9 years of security engineering experience with hands on cloud experience, as a guideline rather than a hard requirement.
- Agentic AI tools are your primary surface for security engineering, analysis, detection, and automation, and you apply hard judgment to what they produce, not an occasional assist.
- Senior level breadth across network security, application security, cloud security, information security, and the emerging discipline of AI security, with real depth in several of them.
- You build controls as code, including policy as code, infrastructure as code, automation, and detections, and you have operated them in production, including carrying on call and incident load.
- Cloud security depth in AWS (primary) and Azure: identity and access management and least privilege, identity federation and single sign on, secrets management, privileged access, and workload and non human identities; network security; container security including image scanning and runtime protection; key management and encryption; and cloud security posture management across configuration, workloads, and entitlements (CSPM, CWPP, and CIEM).
- Data protection and privacy engineering: data classification, encryption, tokenization, and key management, data loss prevention, and privacy by design for regulated health data, with data residency awareness across domestic and international operations.
- Application and product security depth: secure software development lifecycle, threat modeling, static, dynamic, and software composition analysis, secrets and software supply chain security, and API security.
- Detection, response, and vulnerability management depth: SIEM and cloud native detection, log and event correlation, vulnerability scanning and management, and coordinating penetration testing and remediation to closure.
- AI security awareness and a point of view: securing AI and generative AI systems against risks like prompt injection, data and model poisoning, and data leakage, with familiarity with references like the OWASP Top 10 for LLM Applications and MITRE ATLAS a plus.
- You build to the frameworks we operate under, domestic and international: HIPAA, HITRUST, SOC 2, NIST, ISO 27001, ISO 42001, and GDPR.
- Self-starter with ability to multi-task and work autonomously
- Excellent organizational and project management skills
- Effective interpersonal and communication skills
Other Requirements
- Consistent and reliable high-speed internet and workspace free from distraction, disruption, or noise is required
- Ability to be present on camera during work-related trainings, meetings, and/or events
- Must be able to sit or stand at a desk for prolonged periods while working on a computer
Pay Range
USD $150,000.00 - USD $200,000.00 /Yr. Compensation and Benefits
- Full benefits package, including Paid Time Off (PTO), medical, dental, vision, 401(k) with match, robust EAP, wellness program, and much more
- The salary range for this position is $150,000 - $200,000 (CAD). The base salary range represents the anticipated low end and high end of the range for this position. The actual compensation will be influenced by a wide range of factors including, but not limited to previous experience, education, pay market/geography, and scheduled hours.
EEO
ComPsych is an equal opportunity employer. All applicants will be considered for employment regardless of race, color, age, genetics, religion, gender, sexual orientation, gender identity, national origin, disability or protected veteran status and any other characteristic protected by federal, state or local laws. ComPsych Corporation maintains a drug free workplace.
ComPsych Corporation and its affiliates is committed to the responsible and transparent handling of your personal data. Information collected during the recruitment process will be used to assess your application and, where applicable, to prepare and administer an offer of employment. Your personal data will be processed in accordance with the privacy laws applicable in your country or jurisdiction of residence, which may include the California Consumer Privacy Act (CCPA), the EU General Data Protection Regulation (GDPR), Canada's Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation, and other applicable national or local privacy laws. For full details on what personal data we collect, how we use it, your rights as an Applicant, and how to contact us with privacy-related questions, please review the relevant Applicant Data Privacy Notices: US Applicant Data Privacy Notice & Canada Data Privacy Notice.
Similar roles
-
Staff Software Security Engineer
Anthropic London, England, United Kingdom · £255K–£325K/yr
-
Security Engineer - Blue Team
Incognia Confidential Brazil
-
Information Security Engineer | Corporate Technology
Red Ventures Charlotte, North Carolina, United States · $100K–$150K/yr
-
Application Security Engineer - Assistant Vice President
iCapital Salt Lake City, Utah, United States · $100K–$130K/yr
-
Consultant Cloud Security Engineer [CloudSec] - F/H/N
OCTO Technology Paris, Ile-de-France, France · €60K–€75K/yr
-
Cybersecurity Detection Engineer
Spektrum Mons, Wallonia, Belgium