Senior IT Security Engineer
VancouverFull-timeCA$110k–CA$130kPosted Mar 17, 2026
Back to all rolesSenior IT Security Engineer ApplyJob detailsDepartment / IT SecurityVancouverFull-time$110,000 CAD - $130,000 CADWork model: Hybrid (in office twice per week)Location: VancouverPosition Type: Full-time, PermanentIndustry: Commodities & EnergyAbout us:Founded in 1995, Zema Global Data Corporation empowers organizations to simplify complexity, reduce risk, and make faster, more confident decisions that drive measurable results. Over the past two years, Zema Global has accelerated its growth through strategic investment and acquisition to strengthen our global leadership. Together we’re helping our customers gain a Decisioning Advantage – one bold idea at a time. With a presence across global energy, commodity, and financial markets, Zema Global empowers customers to simplify complexity, reduce risk, and make faster, more confident decisions that drive measurable results.At Zema Global, we Think Big, Make It Happen, and Win as One. We thrive on collaboration, creativity, and respect, united by a shared drive to innovate and deliver meaningful impact for our customers and communities. If you’re inspired by solving complex challenges and contributing to a culture that values purpose and performance, we invite you to join us.Position overview:The Senior Security Engineer is a key contributor to securing a cloud-first, DevSecOps driven environment, responsible for embedding security into cloud platforms, with a strong focus on automation, scalability, and resilience.Working closely with Engineering, DevOps, this role ensures the integration of security into CI/CD pipelines, cloud infrastructure, and application architectures while supporting compliance with SOC 2 and ISO 27001.This position involves a combination of hands-on execution and strategic advisory responsibilities and essential to enabling secure growth, maintaining customer trust, and ensuring the organization meets its security and compliance commitments without compromising delivery.Key Responsibilities:Design and implement cloud-native security controls across AWS infrastructure, platforms, and applications to protect systems and data while enabling scalable business growth.Perform regular risk analysis across cloud environments and responsible for the definition and implementation of remediation activities, in a timely and coordinated mannerOperate and enhance security monitoring and response capabilities through the deployment and continuous improvement of SIEM and SOAR solutions to enable timely detection, investigation, and response to security eventsWork with the SMEs to ensure security is embedded into CI/CD pipelines and development workflows by implementing automated security testing, policy enforcement, and secure-by-default configurations aligned with DevSecOps principles.Advise SMEs to ensure application security is embedded into the development lifecycle by supporting SAST, DAST, and secure code reviews, and by working directly with developers to remediate OWASP Top 10 risks.Continuously assess and improve AWS cloud security posture by implementing and maintaining CSPM controls to identify misconfigurations, reduce exposure, and enforce security best practices.Align technical security controls with CIS benchmarks and frameworks to strengthen baseline security configurations and support consistent, repeatable security outcomesPartner with engineering, platform, and IT teams to provide security architecture guidance, threat modelling, and secure design reviews that balance risk management with delivery velocity.Act as the first point of escalation during the security incident detection and response to security events, also supporting investigations, and coordinating timely remediation to reduce risk and business impact.Lead vulnerability management and remediation validating efforts, by prioritizing risks, verifying fixes, and working with IT & DevOps teams to ensure timely and effective resolution.Support penetration testing and remediation...