A university degree in Engineering, Computer Science, Information Technology, or a related field
7-10 years of experience developing and implementing security architectures and/or engineering, with demonstrated breadth across cloud, data, and/or AI security domains
Security certifications such as CISSP, CCSP, CCSK, or any Cloud Security Specialty certification (e.g., AWS Certified Security Specialty, Microsoft Certified: Azure Security Engineer Associate)
Demonstrated knowledge of cloud architecture, cloud operations, cloud-based identity and access management, security automation, and orchestration
Extensive experience with cloud-native security solutions and tools (e.g., AWS Security Hub, AWS GuardDuty, Microsoft Defender for Cloud, Azure Sentinel)
Knowledge of technical security control environments and compliance frameworks including CSA CCM, ISO 27001, ISO 27017, and NIST CSF
Working knowledge of AI/ML development frameworks and platforms (e.g., TensorFlow, PyTorch, SageMaker, Azure ML) and associated security risks
Familiarity with the OWASP Top 10 for LLMs, MITRE ATLAS, and NIST AI Risk Management Framework (AI RMF)
Understanding of MLOps pipeline security, including securing model registries, feature stores, training environments, and inference endpoints
Knowledge of Generative AI security risks, including prompt injection, jailbreaking, data leakage via LLMs, and supply chain risks in AI model dependencies
Experience implementing data loss prevention (DLP), data classification, and data access governance solutions in enterprise environments
Knowledge of DSPM tools and practices
Understanding of data encryption at rest and in transit, tokenization, and key management for large-scale data environments
Familiarity with data privacy regulations (e.g., PIPEDA, GDPR, CCPA) and their technical implementation requirements
Experience securing cloud-based data platforms such as Snowflake, Databricks, AWS Redshift, Azure Synapse, or equivalent
Firm grasp of networking protocols and operations; comfortable with packet analysis tools such as Wireshark, Burp Suite, nmap, Nessus, and Metasploit
Knowledge of theoretical and applied cryptography, key management, and cryptographic algorithms (RSA, AES, TLS, PKI, etc.)
Knowledge of Identity and Access Management (IAM) concepts including SSO, SAML, federated identity, RBAC, and OAuth/OIDC
Strong scripting and programming skills with experience in Python, PowerShell, Bash, Node.js, and API/webhook development
Experience with Infrastructure as Code (IaC) security scanning tools (e.g., Checkov, tfsec, Prisma Cloud)