Sign up to access all features of our service.
  • Job search
  • Favorites
  • Create a CV
    New
  • Salaries
  • Subscriptions

Principal Cloud Security Engineer

$103.2k - $192k per year
Full-time
Application Deadline:

07/30/2026

Address:
33 Dundas Street West

Job Family Group:

Technology

Description

We are seeking an enthusiastic and passionate professional for a Senior Cloud, AI & Data Security Engineer role who wants to design and implement security solutions for systems and services across AWS, Azure, and AI/ML platforms . We need someone who can establish the highest standards that meet and exceed security governance solutions and practices, provide assurance to management and auditors, and ensure sustained protection by embedding controls in operational and DevOps (CI/CD) practices with a focus on automation.

We are looking for someone who has a high level of technical security expertise and who takes seriously the responsibility of monitoring, detecting, protecting, and maintaining the security of data, AI/ML systems, cloud platforms, and networks .

You are a leader with a strong technical background. You have demonstrated strength in:
  • Developing and implementing secure cloud and AI/ML architectures using a risk-based cybersecurity and data privacy strategy
  • Defining security patterns, roadmaps, and operating models that leverage collaboration
  • Facilitating industry-standard information security governance
  • Advising senior leadership on cybersecurity, AI risk , and privacy risks, threats, and investment strategies
  • Documenting appropriate policies and procedures to manage information security risks, including those unique to AI/ML systems and sensitive data assets
As a qualified candidate, you will be part of the team driving BMO's Cloud, AI, and Data Security implementation. As a member of this team, you should possess the ability to inspire yourself and all of our team. Based on your previous experiences, you will inject new knowledge and skills into an already high-performing team, thus elevating our efforts to new heights.

Your Responsibilities

Cloud Security
  • Assess, design, implement, automate, and document security solutions, controls, and processes for Amazon Web Services (AWS) and Microsoft Azure cloud platforms
  • Develop and maintain security patterns for cloud platforms and services; assess all cloud patterns to ensure adherence to best security practices and controls
  • Design and implement security baseline controls for Cloud Services for integration into the CI/CD process
  • Build and deliver policies as code , automating security controls and best practices
  • Review and approve code and changes with security implications (e.g., IAM Roles and Policies, Security Groups, etc.)
  • Be the cloud security subject matter expert for the Cloud Engineering group and its partners in any IaaS, PaaS, and SaaS implementations
AI & Machine Learning Security
  • Define and implement a security framework for AI/ML systems , covering the full model lifecycle from data ingestion and training to deployment and monitoring
  • Assess and mitigate AI-specific threats including adversarial attacks, model inversion, data poisoning, prompt injection, and model theft
  • Evaluate and secure AI/ML platforms and tools (e.g., Amazon SageMaker, Azure Machine Learning, Hugging Face, OpenAI APIs) against organizational risk standards
  • Collaborate with data science and AI engineering teams to integrate security controls into MLOps pipelines , ensuring model integrity, access controls, and auditability
  • Monitor emerging AI threat landscapes and regulatory developments (e.g., EU AI Act, NIST AI RMF) and translate these into actionable organizational controls
Data Security
  • Implement and manage data security posture management (DSPM) tools to continuously monitor sensitive data exposure across cloud environments
  • Establish controls for structured and unstructured data stores , including databases, data lakes, data warehouses (e.g., Snowflake, AWS S3, Azure Data Lake), and file sharing platforms
  • Drive the adoption of data-centric security practices within application development and analytics teams
General Security Leadership
  • Provide subject matter expertise on architecture, authentication, and systems security based on a clear understanding of the engineering stack, services, and data flow
  • Lead focused and continuous cybersecurity risk assessments of new and existing technologies - including AI/ML systems and data platforms - to identify risks and appropriate controls that balance security and operability
  • Provide effective and pragmatic cybersecurity guidance upfront in major technology projects to enable the business to innovate securely
  • Assist in the investigation and remediation of security incidents and issues, including those involving AI model compromise or data breaches
  • Work closely with Information Security, product, and software development teams to assess cybersecurity risk and recommend solutions in cloud, AI, and data environments
Your Mindset
  • You are a self-starter , driven, and can handle multiple projects and priorities
  • You are passionate about driving the DevSecOps and MLSecOps mindset and culture in a fast-paced, challenging environment where you get the opportunity to work with the latest tools and technologies
  • You understand the intersection of security, AI, and data , and actively seek to build bridges between these disciplines
  • You are actively looking to improve the solutions you implement, understand the efficacy of collaboration, and are keen to work in a team of CI/CD, infrastructure, AI, and data specialists
  • You are energized by the rapidly evolving AI threat landscape and bring intellectual curiosity and practical judgment to navigating ambiguity
  • As a member of this team, you will inject new knowledge and skills into an already high-performing team, elevating our collective efforts to new heights
Required Core Skills

Foundational
  • A university degree in Engineering, Computer Science, Information Technology , or a related field
  • 7-10 years of experience developing and implementing security architectures and/or engineering, with demonstrated breadth across cloud, data, and/or AI security domains
  • Security certifications such as CISSP, CCSP, CCSK , or any Cloud Security Specialty certification (e.g., AWS Certified Security Specialty, Microsoft Certified: Azure Security Engineer Associate)
  • Emerging/preferred: Certifications or demonstrated knowledge in AI security (e.g., CDAI, CompTIA AI+, or equivalent vendor-specific AI security training) or data security (e.g., CDPSE, CIPP)
Cloud Security
  • Demonstrated knowledge of cloud architecture, cloud operations, cloud-based identity and access management, security automation, and orchestration
  • Extensive experience with cloud-native security solutions and tools (e.g., AWS Security Hub, AWS GuardDuty, Microsoft Defender for Cloud, Azure Sentinel)
  • Knowledge of technical security control environments and compliance frameworks including CSA CCM, ISO 27001, ISO 27017, and NIST CSF
AI & ML Security
  • Working knowledge of AI/ML development frameworks and platforms (e.g., TensorFlow, PyTorch, SageMaker, Azure ML) and associated security risks
  • Familiarity with the OWASP Top 10 for LLMs , MITRE ATLAS , and NIST AI Risk Management Framework (AI RMF)
  • Understanding of MLOps pipeline security , including securing model registries, feature stores, training environments, and inference endpoints
  • Knowledge of Generative AI security risks , including prompt injection, jailbreaking, data leakage via LLMs, and supply chain risks in AI model dependencies
Data Security
  • Experience implementing data loss prevention (DLP) , data classification , and data access governance solutions in enterprise environments
  • Knowledge of DSPM tools and practices
  • Understanding of data encryption at rest and in transit , tokenization, and key management for large-scale data environments
  • Familiarity with data privacy regulations (e.g., PIPEDA, GDPR, CCPA) and their technical implementation requirements
  • Experience securing cloud-based data platforms such as Snowflake, Databricks, AWS Redshift, Azure Synapse, or equivalent
Technical Skills
  • Firm grasp of networking protocols and operations ; comfortable with packet analysis tools such as Wireshark, Burp Suite, nmap, Nessus, and Metasploit
  • Knowledge of theoretical and applied cryptography , key management, and cryptographic algorithms (RSA, AES, TLS, PKI, etc.)
  • Knowledge of Identity and Access Management (IAM) concepts including SSO, SAML, federated identity, RBAC, and OAuth/OIDC
  • Strong scripting and programming skills with experience in Python, PowerShell, Bash, Node.js , and API/webhook development
  • Experience with Infrastructure as Code (IaC) security scanning tools (e.g., Checkov, tfsec, Prisma Cloud)
Interpersonal & Leadership
  • Demonstrable internal and external relationship-building skills with the ability to clearly articulate complex security concepts across a diverse corporate culture
  • Ability to lead in-depth workshops across a broad range of topics including cloud compliance, AI risk, and data governance
  • Strong ability to influence decision-making at senior leadership levels
Other Skills
  • Strong interpersonal, communication, and leadership skills
  • A critical thinker with strong research, analytical, and problem-solving skills
  • Self-motivated with a positive attitude and an ability to work independently and within a team
  • Ability to communicate complex technical concepts to a broad range of internal and external stakeholders, including business, legal, compliance, and technology leaders
  • Strong time management skills with the ability to manage multiple workstreams and mentor less experienced team members
Why Join Us?

This is a rare opportunity to shape the cloud, AI, and data security strategy of one of Canada's largest financial institutions at a time when these domains are converging and rapidly evolving. You will work at the forefront of emerging threats, influence enterprise-wide security standards, and collaborate with world-class teams across technology, risk, and innovation.

Job Type: Full-time

Salary :

$103,200.00 - $192,000.00

Pay Type:

Salaried

The above represents BMO Financial Group's pay range and type.

Salaries will vary based on factors such as location, skills, experience, education, and qualifications for the role, and may include a commission structure. Salaries for part-time roles will be pro-rated based on number of hours regularly worked. For commission roles, the salary listed above represents BMO Financial Group's expected target for the first year in this position.

BMO Financial Group's total compensation package will vary based on the pay type of the position and may include performance-based incentives, discretionary bonuses, as well as other perks and rewards. BMO also offers health insurance, tuition reimbursement, accident and life insurance, and retirement savings plans. To view more details of our benefits, please visit:

About Us

At BMO we are driven by a shared Purpose: Boldly Grow the Good in business and life. It calls on us to create lasting, positive change for our customers, our communities and our people. By working together, innovating and pushing boundaries, we transform lives and businesses, and power economic growth around the world.

As a member of the BMO team you are valued, respected and heard, and you have more ways to grow and make an impact. We strive to help you make an impact from day one - for yourself and our customers. We'll support you with the tools and resources you need to reach new milestones, as you help our customers reach theirs. From in-depth training and coaching, to manager support and network-building opportunities, we'll help you gain valuable experience, and broaden your skillset.

To find out more visit us at .

BMO is committed to an inclusive, equitable and accessible workplace. By learning from each other's differences, we gain strength through our people and our perspectives. Accommodations are available on request for candidates taking part in all aspects of the selection process. To request accommodation, please contact your recruiter.

Note to Recruiters: BMO does not accept unsolicited resumes from any source other than directly from a candidate. Any unsolicited resumes sent to BMO, directly or indirectly, will be considered BMO property. BMO will not pay a fee for any placement resulting from the receipt of an unsolicited resume. A recruiting agency must first have a valid, written and fully executed agency agreement contract for service to submit resumes.
Vacancy posted 21 hours ago
Similar jobs that could be interesting for youBased on the Principal Cloud Security Engineer in Toronto, ON vacancy
  • $103.2k - $192k per year

     ...an enthusiastic and passionate professional for a Senior Cloud, AI & Data Security Engineer role who wants to design and implement security solutions...  ...demonstrated strength in: Developing and implementing secure cloud and AI/ML architectures using a risk-based cybersecurity... 
    Principal
    Full time
    Contract work
    Part time
    Toronto, ON
    21 hours ago
  •  ...drive to change the world — we'd love to have you apply. About the team and role: The Cloud Security team is focused on protecting Robinhood's AWS cloud and providing engineers with foundational security capabilities. It is a major contributor to the company's least privilege... 
    Suggested
    Full time

    Robinhood

    Toronto, ON
    12 days ago
  •  ...safe, simple, smart and accessible. Using secure data and networks, partnerships and...  ...Title and Summary Lead Information Security Engineer (Cloud) Who is Mastercard? Mastercard is a...  ...container scanners, static code analysis engines). If you are looking for a challenge that... 
    Suggested

    Mastercard

    Toronto, ON
    3 days ago
  •  ...include:  • Assessing and implementing Cloud security solutions for clients • Reviewing security...  ...to the cloud and operating it in a secure and private way. We offer cyber capabilities...  ...Degree or Diploma in Computer Science, Engineering, Management Information Systems or... 
    Suggested
    Permanent employment
    Flexible hours

    Deloitte

    Toronto, ON
    15 hours ago
  • $220k - $300k per year

     ...America. We are seeking a visionary Principal Software Engineer to join our Engineering team. In this...  ...platform, ensuring it is highly scalable, secure, and capable of processing large-scale...  .... ~ Extensive experience with cloud platforms such as AWS or Azure. ~ Deep... 
    Principal
    Long term contract

    Owl.co

    Toronto, ON
    15 days ago
  • $103.2k - $192k per year

     ...Group: Technology Lead the design and maturity of end-to-end cloud security across multi-cloud environments (AWS, Azure, GCP), with...  ...recovery and ensure resolution. Core Accountability Own secure cloud architecture aligned to Zero Trust principles Act as enterprise... 
    Full time
    Contract work
    Part time
    Immediate start
    Toronto, ON
    6 days ago
  •  ...Job Responsibility: Principal Mechanical Engineer - TOR0030 Company : Worley Primary Location : CAN-ON-Toronto Job : Mechanical Schedule : Full-time Employment Type : Employee Job Level : Experienced Job Posting : Nov 27, 2023 Unposting Date : Dec 27... 
    Principal
    Full time
    Internship
    Work at office
    Local area

    Worley

    Toronto, ON
    1 day ago
  •  ...Principal Software Engineer The global capital markets are among the largest markets in the world valued at $50T+ and growing. Transactions in these markets are complex. Critical, nuanced legal terms are woven into lengthy documents. These documents must be digested and... 
    Principal
    Long term contract
    Full time
    Work at office
    Local area
    Flexible hours
    2 days per week
    3 days per week

    Thomson Reuters

    Toronto, ON
    1 day ago
  •  ...connectivity solutions that unlock the full potential of AI and cloud infrastructure. Our Intelligent Connectivity Platform...  ...data-driven applications at . We are looking for Principal Design Verification Engineers with proven experience in all aspects of verification in... 
    Principal
    Full time
    Immediate start
    Flexible hours

    Astera Labs

    Toronto, ON
    12 days ago
  • $69k - $114k per year

     ...through mentoring and on the job coaching Deloitte Global is the engine of the Deloitte network. Our professionals reach across...  ...What will your typical day look like? We are seeking a hands on Cloud Security Lead who excels at deep technical analysis, research, and practical... 
    Permanent employment
    Remote work
    Flexible hours
    Toronto, ON
    2 days ago
  •  ...Snowflake's Support team is expanding! We are looking for a Cloud Support Engineer to join our team who likes working with data and solving a wide...  ...connectivity issues. Understanding of cloud computing security concepts Snowflake is growing fast, and we're scaling our... 
    Weekend work

    Snowflake

    Toronto, ON
    7 days ago
  • $180k - $220k per year

     ...Xello is looking for a Principal Engineer __ Who are you? As our Principal Engineer, you'll be the visionary architect behind Xello's technological...  ...direction across teams, guiding architecture toward scalable, secure, and maintainable systems. Partner with engineering leaders... 
    Principal
    Long term contract
    Full time
    Remote work
    Flexible hours

    Xello

    Toronto, ON
    23 days ago
  • $180k - $275k per year

     ...As a pioneer in industry cloud and one of the fastest-growing enterprise SaaS companies (surpassing $3B in revenue last year)...  ...directly contribute to global health. The Opportunity: As a Principal Software Engineer at Veeva, you will develop and guide the creation of highly... 
    Principal
    Internship
    Work at office
    Local area
    Remote work
    Flexible hours

    Veeva Systems

    Toronto, ON
    2 hours ago
  •  ...organization. We expect every engineer to use AI tools and agentic...  ...seeking a passionate and resilient Principal Graphics Engineer to own a...  .../Linux graphics, browser engines, and WebGL/WebGPU. The role demands...  ...and the surrounding browser security/sandboxing model.... 
    Principal
    Internship

    Parallelz

    Toronto, ON
    23 days ago
  •  ...connectivity solutions that unlock the full potential of AI and cloud infrastructure. Our Intelligent Connectivity Platform...  ...modern data-driven applications at . We are seeking a Principal Digital Design Engineer with deep expertise in high-performance controller and... 
    Principal
    Full time
    Flexible hours

    Astera Labs

    Toronto, ON
    12 days ago
  • $74.27k - $137.93k per year

     ...Working Arrangement Hybrid The opportunity The Cloud Platform Engineer will be working on automated provisioning of Azure cloud resources...  ...will streamline processes, enhance performance & fortify security measures, enabling the organization to be faster, easier & better... 
    Long term contract
    Full time
    Temporary work
    Internship
    Manual labor
    Local area
    Flexible hours

    Manulife

    Toronto, ON
    12 days ago
  • $180k - $275k per year

     ...Systems is a mission-driven organization and pioneer in industry cloud, helping life sciences companies bring therapies to patients...  ...customers, employees, and communities. The Role As Principal Software Engineer for a new product within Veeva, you will be a founding... 
    Principal
    Internship
    Work at office
    Local area
    Remote work
    Work from home
    Flexible hours

    Veeva Systems

    Toronto, ON
    2 hours ago
  •  ...Responsibility: Overview DNAstack is looking for an experienced engineer to manage a federated network of software instances. Here,...  ...of challenging problems, and to deploy and manage robust, secure, and scalable cloud-based systems. You will have the opportunity to work... 
    Full time
    Internship
    Work at office
    Remote work
    Shift work

    DNAstack

    Toronto, ON
    1 day ago
  • $50 - $70 per hour

    About the job Mercor connects elite creative and technical talent with leading AI research labs. Headquartered in San Francisco, our investors include Benchmark , General Catalyst , Peter Thiel , Adam D'Angelo , Larry Summers , and Jack Dorsey . Position...
    Principal
    Remote job
    Contract work
    Summer work

    Mercor

    Toronto, ON
    18 days ago
  •  ...solutions for the future. We are looking for a Senior AWS Cloud Engineer with proven experience in the financial technology industry to...  ...o Architect, build, and manage highly available, scalable, and secure cloud infrastructures using AWS services. o Ensure the scalability... 
    Permanent employment
    Full time
    Work at office
    Monday to friday

    OTT Financial Group

    Toronto, ON
    3 days ago
  • $72k - $138k per year

     ...from deep subject matter experts through mentoring and on the job coaching Summary As a Cloud Engineer, you will play a critical role in designing, building, and operating secure, scalable, and cloud-native solutions across public cloud platforms. In this 1-year fixed... 
    Temporary work
    Fixed term contract
    Flexible hours
    Toronto, ON
    6 days ago
  •  ...Infrastructure Technology team. We are looking for a Senior Infrastructure Cloud Engineer who brings experience specifically in working with Microsoft...  .... Weigh business needs against technology of offerings, security concerns and provide recommendations which are practical and... 
    Full time
    Local area
    Remote work

    CIBC

    Toronto, ON
    7 days ago
  •  ...Hours per day or Week: 7.25 hours per day Security Level: CRJMC Must Have Design,...  ...Terraform modules and configurations for all cloud infrastructure. Author and maintain...  ...for secrets management and always ensure secure handling of credentials. Develop idempotent... 
    Hourly pay
    Permanent employment
    Remote work
    Shift work

    S M Software Solutions Inc

    Toronto, ON
    23 days ago
  •  ...DevOPS / Cloud Engineer – Senior Requisition ID: RQ11125 Client: Central Agencies Cluster...  ...-Time Contract | 100% Allocation Security Clearance: CRJMC Position Overview...  ...including: Least privilege access Secure logging Secrets management Vulnerability... 
    Full time
    Contract work

    SereneAid

    Toronto, ON
    12 days ago
  • Position Summary We are seeking a highly skilled Senior DevOps/Cloud Engineer to design, build, deploy, and maintain robust hybrid...  ...public cloud and on-premises environments, and implementing modern security safeguards to protect infrastructure from vulnerabilities.... 
    Contract work
    Monday to friday

    Randstad

    Toronto, ON
    15 days ago
  • $132.69k - $182.69k per year

     ...This role is primarily responsible for Cloud architecture and design keeping in consideration the security of the environment. It also covers secure deployment of SaaS applications for...  ...from advanced medical devices, to highly engineered aviation systems, to next-generation... 
    Temporary work
    Internship
    Work at office
    Local area
    Remote work
    Night shift

    Celestica International LP

    Toronto, ON
    12 days ago
  • $215k - $235k per year

     ...experience. If U.S.-based, any variation in that range can be discussed in the intro call. This role reports to Steve Boyle, Director of Engineering. In this role, you'll be expected to: Translate next-generation system architecture into working hardware — owning detailed... 
    Principal
    Full time
    Internship
    Work at office
    Relocation
    Flexible hours

    Synex Medical

    Toronto, ON
    28 days ago
  •  ...Role: AWS Serverless Cloud Engineer Location: Toronto Office Hybrid: 2 days in office a week Qty: 2 Skills: Digital...  ...AWS Infrastructure knowledge – VPC, EC2, S3, Lambda, NACL, Security Group and networking etc Must know AWS CDK. Cloud formation... 
    Contract work
    Work at office
    2 days per week

    Astra North Infoteck Inc.

    Toronto, ON
    21 days ago
  •  ...Job Responsibility: We are looking for "Senior AWS DevOps Engineer" in Canada. Full-time Permanent/T4 (hourly) - 100% Remote Responsibilities...  ...for enterprise and business applications in the enterprise cloud environment. The public cloud infrastructure for enterprise and... 
    Hourly pay
    Permanent employment
    Full time
    Remote work

    Techedin

    Toronto, ON
    3 days ago
  •  ...Snr. Integration Engineer – Interac e-Transfer Modernization 1. Project Summary / Objective Vancity is upgrading its Interac e-Transfer...  ...reliable and consistent payment processing. • Implement secure APIs using industry standards such as OAuth2, OIDC, and mTLS, in... 
    Contract work

    Astra North Infoteck Inc.

    Toronto, ON
    1 day ago

Do you want to receive more vacancies?

Subscribe and receive similar vacancies to Principal Cloud Security Engineer. Be the first to apply!