The IT Security Engineer is responsible for safeguarding the organization's information systems, infrastructure, applications, and data by designing, implementing, monitoring, and improving security controls across on-premises and cloud environments. The role supports security operations, incident response, vulnerability management, risk and compliance activities, and provides technical guidance to ensure the organization's cybersecurity posture, resilience, and operational effectiveness.
Key responsibilities
Design, implement, and maintain security controls across enterprise technologies, ensuring security requirements are integrated throughout the system lifecycle.
Review architectures, configurations, and technology changes to ensure alignment with security standards, business requirements, and best practices.
Assess control effectiveness and recommend improvements to strengthen security and reduce risk.
Monitor, investigate, and respond to security events, incidents, and vulnerabilities, including coordinating remediation and recovery activities.
Conduct security assessments, vulnerability reviews, and coordinate third-party penetration testing activities; prioritize, track, and validate remediation of identified findings.
Perform incident investigations, root cause analysis, reporting, and post-incident reviews to improve security resilience.
Conduct security risk assessments and support the development and maintenance of security policies, standards, procedures, and documentation.
Support internal and external audits, compliance activities, third-party security reviews, and remediation of identified findings.
Maintain security risk, exception, and corrective action records and monitor alignment with organizational and regulatory requirements.
Provide security guidance, awareness, and training to employees and technical teams.
Support business continuity, disaster recovery, cyber resilience, and crisis management planning and testing.
Monitor emerging threats and contribute to process improvements, automation, reporting, and other initiatives that enhance security effectiveness.
Occasional travel and after-hours support may be required for critical incidents, system maintenance, testing activities, and business continuity needs.
Qualifications, Job Function, Technical Knowledge, and Skills
A bachelor's in computer science or IT Security or a combination of equivalent professional training and security industry certifications, combined with a minimum of three years related work experience in a position(s) with increasing responsibility may be accepted.
Experience in information technology that encompasses a variety of roles, such as working with SIEM, Data Loss Protection, Vulnerability Management, Forensics, IDS/IPS, privilege and identity management as well as software and security architectures, and industry standards such as NIST, CIS Controls and Benchmarks, and ISO 27001. Experience with security tools such as Microsoft XDR (EDR/MDR) and Qualys vulnerability management is preferred.
Thorough knowledge of information security principles and practices.
Knowledge of industry standard processes (SDLC, CMMI, Change Mgmt, ITIL, OWASP), methodologies, standards, best practices and encryption methods and techniques.
Understanding of network and host-based intrusion detection (NDS/HDS), non-repudiation, access control, network security, threat modelling, SSL / TLS, Digital Signatures, auditing architectures, application vulnerabilities and Public Key Infrastructure (PKI) is desired.
Understanding of methods and models within information security & compliance to include risk analysis and mitigation, policies, regulatory environment, technologies, architecture, and best-practices.
Strong communication, analytical, problem-solving, and critical-thinking skills.
Demonstrated attention to detail, organizational skills, and ability to manage competing priorities.
Ability to work independently and collaboratively in a team environment.
Proven ability to exercise sound judgment and maintain confidentiality when handling sensitive information.
Excellent verbal and written English communication skills.
- Previous Canadian work experience or experience working directly with Canadian industries.
DP World (Canada) Inc. fosters diversity, inclusion and belonging across our organization. We are a proud equal opportunity employer with a commitment to creating a respectful, inclusive, and barrier free workplace. We welcome and encourage applications from people with disabilities. Accommodation may be available upon request for candidates taking part in all aspects of the selection process. We welcome applicants to advise us on your preferred pronouns in your application
All aspects of employment, including the decision to hire and promote, are based on applicants’ qualifications, merits, competence, and performance without regard to any characteristic related to diversity.
No phone calls or agencies please. We thank all applicants for their interest; however, only short-listed candidates will be contacted for an interview, testing and pre-employment medical examination. To be eligible for hire, you must be legally entitled to work in Canada and must successfully obtain Transport Canada Security Clearance.