
Senior Security Platform Engineer Security (Akamai Security)
- Toronto, ON York, ON
- 84.000-138.000 $ par an
- Permanent
- Temps-plein
- Analyze information systems utilizing various cybersecurity techniques and lead security initiatives and enterprise level projects implementing security solutions and performing POC/POV for new technologies.
- Able to work independently with high degree of ambiguity and deliver expected outcomes, be focused on the end deliverables, and build trust with internal clients and peers.
- Responsible to deploy, support and maintain new and existing security technologies that are deployed within Sun Life and owned and supported by the team.
- Implement risk driven security controls and provide SME (Subject Matter Expertise) during Audit.
- Investigate and respond to security incidents, adhering to defined SLA’s. Participate in teams 24x7 on-call support and be required to join major incident management calls to provide support and consultation.
- Identify risks to the business and recommend strategies to address those risks.
- Manage the capacity and resiliency of security systems protecting Sun Life’s internal and client data.
- Collaborate and build trust with security peers, vendors, and other Sun Life teams to enhance security posture and best practices.
- A change catalyst for Digital transformation, using JIRA, Confluence, estimating stories, setting definition of done, completing and tracking story updates and assignments.
- Smoothly transition and operationalize projects and products. This includes developing roles & responsibilities (RACI), completing product documentation and educating the teams who will be performing BAU (Business as usual) the day-to-day work.
- Document, update and maintain cyber security playbooks, policies and knowledge base articles used to support the established Incident Management and CSIRT processes.
- Continuously improve operational and security platform processes.
- An Information Technology University degree/college diploma in related discipline(s) or equivalent work experience
- Minimum 5-7 years Information security and engineering experience with enterprise level security technologies in the one or more areas of: Perimeter, Endpoints, Crypto, Cloud, Email Security, Security Visibility, and Automation and Orchestration
- Minimum 3 year experience in successfully leading global information security projects.
- Preferred: Certification(s) in data network engineering and/or security: CCNP/CCNP-Security, CCSP, CISSP, GIAC-GCIA, GIAC-GCED, Comptia, or equivalent security certification
- Experience in managing 3rd party security service providers in delivering security services.
- Broad exposure to multiple security disciplines and in-depth exposure in Incident Response or Detection Engineering
- Knowledge of a broad range of security controls and risk management frameworks NIST & (ISO) 2700x standards
- Experience with end-point detection and response, intrusion detection, certificate management, email security and web content filtering technologies.
- Experience designing secure networks and endpoint systems.
- Experience planning, researching, and developing security policies, standards, and procedures.
- Experience in a system administration role supporting multiple platforms and applications.
- Experience with Windows and Linux based operating systems.
- Experience in deploying enterprise level technology via managed projects using Scrum and Kanban methodologies.
- Knowledge of networking technologies, firewalls, web application firewalls and intrusion detection and prevention systems.
- Knowledge of AWS cloud technologies.
- Knowledge of disaster recovery, technologies, and methods.
- Strong oral and written communicator with the ability to communicate security technical issues to peers and management.
- Security Content Platform Leadership: Serve as the subject matter expert for Akamai’s security products, including Web Application Firewall (WAF), Kona Site Defender, Bot Manager, and Prolexic DDoS protection.
- Architect and Optimize: Design and implement scalable and secure architectures for web applications using Akamai’s security solutions. Continuously tune and enhance Akamai configurations for optimal security and performance.
- Threat Detection & Response: Lead the monitoring, identification, and mitigation of real-time security threats, including bot attacks, DDoS campaigns, and web-based exploits. Develop response playbooks and automated remediation workflows.
- Custom Rule Development: Oversee the development and fine-tuning of custom rules and policies for Akamai WAF, tailoring security controls to evolving threats while maintaining application performance.
- Security Automation: Lead efforts to automate security processes and policy management using tools and scripting languages (e.g., Python, Bash). Implement automation for the continuous deployment of security updates.
- Cross-Functional Collaboration: Act as a liaison between security, DevOps, application development, and infrastructure teams to align Akamai security solutions with business requirements and performance objectives.
- Mentorship & Leadership: Provide technical mentorship and guidance to junior engineers and security team members, sharing best practices and driving continuous improvement in security operations
- Incident Management & Forensics: Lead post-incident investigations, ensuring root cause analysis is performed, lessons are learned, and appropriate remediation steps are taken.
- Reporting & Compliance: Ensure compliance with relevant regulations (e.g., PCI-DSS, GDPR) through robust security configurations and reporting mechanisms. Prepare and deliver detailed security metrics and reports to senior leadership.
- Continuous Improvement: Stay updated on the latest web security threats, Akamai product advancements, and industry best practices. Continuously evaluate and recommend improvements to existing security architectures.
- Project Leadership: Lead key security projects, including large-scale migrations, upgrades, and the introduction of new Akamai features or services. Ensure timely delivery and adherence to high standards of security.
- We’re honored to be recognized as a 2024 Best Workplaces in Ontario by Great Place to Work® Canada.
- We’re proud to be recognized as a company with a 2023 Most Trusted Executive team by Great Place to Work® Canada.
- Wellness programs that support the three pillars of your health – mental, physical, and financial
- The opportunity to move along a variety of career paths with amazing networking potential.
- As a hybrid organization, you and your leader use business and Client needs to choose where you work, at home or in the office.