Senior Cloud Security Analyst

Toronto - 100 Adelaide St W

TMX

TMX operates global markets, builds digital communities and analytic solutions that facilitate the funding, growth and success of businesses, traders and investors.

View company page

Venture outside the ordinary - TMX Careers

The TMX group of companies includes leading global exchanges such as the Toronto Stock Exchange, Montreal Exchange, and numerous innovative organizations enhancing capital markets.  United as a global team, we’re connecting cross-functionally, traversing industries and geographies, moving opportunity into action, advancing global economic growth, and propelling progress. Through a rich exchange of ideas, meaningful collaboration, and a nimble operating model, we're powering some of the nation's most critical systems, fueling capital formation and innovation, bringing increased opportunity to business visionaries, product ingenuity to consumers, and career exploration to our team.

Ready to be part of the action?

The Information Security Office (ISO) at TMX is responsible for researching, deploying and maintaining Security Technologies that support our defense in depth strategy in accordance with TMX regulations and guidelines. This includes cloud deployments and tie-ins to threat intelligence and audit reporting capabilities.

Reporting to the Senior Manager of Security Operations, the Cloud Security Specialist is responsible for the design, planning, testing, implementation, and administration of industry-wide accepted Cyber Security principles, practices, and information systems to ensure the protection of information assets processed, stored, or transmitted in the TMX Group cloud instances, across various cloud services providers.

The successful candidate will also evaluate the effectiveness of Information Security solutions and processes in place, monitor for and identify security risks and exposures, determine the causes of security investigations, incidents, as well as assess, and implement procedures to prevent future incidents. As a member of the Information Security Team, the Cloud Security Specialist will be the liaison between Security Operations and the Cloud Technology and Infrastructure Support teams.

Job Responsibilities: 

  • Lead the implementation, configuration, and daily operation of Cyber Security technologies that are implemented within the TMX Group cloud environments.
  • Manage and support Security technology across various business units for TMX Group Limited.
  • Monitor and advise on Information Security compliance related to IT to ensure Security controls are functioning appropriately within the TMX cloud environments.
  • Support the ongoing Security control processes within the enterprise which includes security technologies, networks, information systems, and endpoints in the cloud.
  • Influences internal partners to ensure they build solutions consistent with the organization's planned policies, programs, architectural recommendations, and Information Security standards within the cloud.
  • Manage requirements documentation, analyzes opinions, and proposes solutions that leverage resources for highly sophisticated projects within the cloud.
  • Assist in the design and implementation of resilient Information Security architecture and technologies for optimal threat protection, monitoring and Incident Response within the cloud
  • Analyze threat and vulnerability feeds data for applicability to TMX’s cloud environment including the identification and resolution of false positive findings in assessment results, as well as perform compensating controls analysis and validate efficacy of existing controls.
  • Understanding of threat models, impact levels, and the different approaches and methodologies i.e. black/gray/white box testing.
  • Develop innovative and secure solutions and provide mentorship for TMX Group stakeholders.
  • Work with Security and IT stakeholders to implement a risk management program that allows for the identification and remediation of Information Security risks within the cloud.
  • Advise the organization about Information Security threats, technologies and related regulatory requirements in scope of cloud functions.
  • Develop and implement Information Security metrics, measurement criteria and reporting to ensure compliance and continuous improvement for cloud tools and environments.
  • Assesses information technology control elements to mitigate IT risks regarding the confidentiality, integrity and availability of business information.

Preferred Qualifications:

  • 5+ years of experience with Amazon Web Services (AWS) platform capabilities, best practices with architectures, and security tool-sets.
  • 3+ years Security System administration and engineering experience in cloud infrastructure.
  • 2+ years of SOC experience, or responding to traditional or cloud based cyber security investigations.
  • CCSP, CISSP, certifications strong assets.
  • Strong experience with AWS WAF & Shield, AWS BotControl, AWS Cloudformation, AWS Athena, AWS CloudTrail, AWS S3, AWS GuardDuty, AWS IAM.
  • Strong experience with Palo Alto NGFW technologies, including firewalls, Prisma, and SD-WAN.
  • Strong experience with other cloud technologies such as Terraform, Ansible, Hashicorp Vault.
  • Experience utilizing or implementing the MITRE ATT&CK framework.
  • Experience with Splunk, CrowdStrike, Qradar, McAfee, F5, Nexpose, Fortinet technologies.
  • Experience with Google Compute Platform (GCP) and Microsoft Azure Cloud is an asset.
  • Experience in cloud based, incident response and forensics a strong asset.
  • Experience with UEBA and other Security Analytics Platforms.
  • Linux and/or Windows administration and troubleshooting experience
  • Programming / scripting experience, preferably with a diversity of languages
  • General networking skills required (Layer 2 & 3 switches, OSI Model, TCP/IP, SNMP, etc.)
  • Strong interpersonal communication skills and the ability to communicate with clients, vendors and partners, and across all levels of the organization.
  • Excellent oral and written communications for the development of the security program, strategy, guidelines, policies, standards and for presentations to technical and non-technical audiences at all levels of the organization.
  • Ability to build and work with multi-disciplinary teams to achieve goals and to meet deadlines in a fast-paced environment.
  • Works well under pressure and time constraints and can prioritize competing priorities appropriately.

In the market for…

Excitement - Explore emerging technology and innovation, as well as ventures and digital finance that shape the future of global markets! Experience the movement of the market while grounded in the stability of close to 200 years of success.

Connection - With site hubs in some of the world’s most multicultural cities, we leverage our size and structure to create rich connections and belonging while experiencing powerful global impact through our work.

Impact - More than a platform, we use our talents to power mission-critical systems that drive global economic advancement, innovation, and growth. As well, our employee-led Team Impact spreads social good via our giving strategy.

Wellness - From empathetic leadership to a culture of flexibility and balance, we believe wellness at work creates the maximum yield and a stronger “we”. Plus, with a cloud-first and hybrid workstyle, as well as generous time-off and leaves, we support a life well lived! 

Growth - From a growth mindset in our work, to expansion in our business, TMX is home to action-takers energized by the achievement of ambitious growth.

Ready to enrich your career with impactful work, leaders who truly care, and the flexibility and programs to help you thrive as part of #TeamTMX ? Apply now.

TMX is committed to creating and sustaining a collegial work environment in which all individuals are treated with dignity and respect and one which reflects the diversity of the community in which we operate. We provide accommodations for applicants and employees who require it.

Apply now Apply later
  • Share this job via
  • or

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  9  2  0

Tags: Analytics Ansible AWS Azure CCSP CISSP Cloud Compliance CrowdStrike Finance Firewalls Forensics GCP IAM Incident response Linux MITRE ATT&CK Monitoring NGFW QRadar Risk management S3 Scripting SOC Splunk Strategy TCP/IP Terraform Threat intelligence White box Windows

Perks/benefits: Career development Equity / stock options

Regions: Asia/Pacific North America
Countries: Australia Canada

Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.