Cybersecurity Technical Lead
Job Summary
We are banking at another level.
Choosing BDC as your employer means working in a healthy inclusive and skilled workplace that puts forward the best conditions to bring together unique teams where employees are empowered to act. It also means being at the centre of ambitious economic and financial projects to see further and to do things differently to fuel the success of Canadian entrepreneurs.
Choosing BDC as your employer also means:
Flexible and competitive benefits including an Employee Savings and Investment Plan where BDC matches part of your voluntary contributions a Defined Benefit Pension Plan a $750 wellness and health care spending account to name a few
In addition to paid vacation each year five personal days sick days as necessary and our offices are closed from December 25 to January 1
A hybrid work model that truly balances work and personal life
Opportunities for learning training and development and much more...
Explore the BDC Way in our Culture Book
POSITION OVERVIEW
The Cybersecurity Technical Lead is a senior member of the Business and Product Security Posture (BPSP) team this role provides technical leadership in driving securitybydesign provides consistent and riskbased guidance mentors Squad members and influences technology decisions across the organization.
The Cybersecurity Technical Lead plays a key role in strengthening BDCs cloud and platform security posture across the main Cloud providers (public and privet Cloud) ensuring that solutions are designed built and maintained following industryleading security standards.
This role collaborates closely with Software Development teams Solution Architects CloudOps Platform Engineering Product Owners and business stakeholders to drive a secure-by-design approach across cloud and on-premises environments. Operating within an Agile framework the Technical Lead contributes to Quarterly Planning and Quarterly Alignment exercises providing technical and security leadership to ensure strategic priorities architectural direction and risk considerations are aligned with business objectives product roadmaps and delivery commitments.
Primary accountability: industrialize security controls across cloud platforms CI/CD pipelines and Kubernetes-based environments by defining and implementing automated guardrails Policy-as-Code controls IaC security validations security gates and secure-by-default deployment patterns.
The Cybersecurity Technical Lead is also responsible for supporting applied AI security initiativesincluding LLM risk management AI governance integration safe AI enablement and secure Copilot usage.
In this capacity Technical Lead complements the existing AppSec/SSDLC Technical Lead enabling BPSP to deliver comprehensive end-to-end product and platform security expertise across the organization. Reporting to a Product Owner the Technical Lead will be responsible for translating business priorities and product objectives into secure and scalable technical solutions. The role will work closely with stakeholders across business technology and security functions to ensure that security and technology decisions align with product strategy delivery roadmaps and organizational objectives embedding security throughout the product lifecycle.
CHALLENGES TO BE MET
1. Leadership & Collaboration
- Design and implement an end-to-end security posture by defining a structured approach and establishing the monitoring and oversight mechanisms required to maintain and measure the organizations security posture.
- Mentor engineers in CloudSec PlatformSec and Applied AI security practices.
- Represent BPSP in architecture reviews cloud design sessions and AI enablement initiatives.
- Provide support to the Product Manager regarding product and platform security capabilities alongside the SSDLC/AppSec Tech Lead (complementary domains).
- Drive measurable maturity improvements by reducing manual control dependency and enabling continuous compliance through automated reusable security patterns.
2. Cloud Security
- Support the definition and implementation of cloud security architecture standards and guardrails across enterprise cloud environments.
- Provide security advisory and operational governance support to environment owners to help maintain secure and well-controlled cloud environments.
- Strengthen foundational cloud security capabilities including identity and access management data protection secrets management encryption and certificate lifecycle practices.
- Promote secure design patterns for hybrid cloud containerized and platform-based services where applicable.
- Support the implementation and continuous improvement of security monitoring logging posture management and control validation capabilities.
- Partner with platform infrastructure and engineering teams to define secure baselines for shared technology environments.
- Reduce configuration drift and improve resilience through reusable guardrails automation infrastructure validation and continuous control practices.
- Define and support security checkpoints and deployment guardrails to help prevent non-compliant changes before production release.
3. Platform & Kubernetes Security
- Establish and promote secure platform standards for containerized and platform-based workloads including access control workload isolation image integrity and runtime protection.
- Define and maintain reusable secure templates policy controls infrastructure validation practices and deployment guardrails for platform workloads.
- Collaborate with platform engineering product and technology teams to embed secure-by-default capabilities across key enterprise platforms including server database application middleware and integration platforms where applicable.
4. Artificial Intelligence Security
- Support the safe adoption of M365 Copilot and Azure OpenAI services (oversharing prevention data boundaries classification).
- Identify LLMrelated risks (prompt injection output manipulation data leakage) and recommend mitigations.
- Integrate AI Governance requirements (model inventory risk assessments) into SSDLC processes in partnership with AAAI/Data Governance.
- Collaborate with AAAI and Engineering teams to embed practical guardrails for AI initiatives (nonresearch applied focus).
5. Supporting Responsibility Penetration Testing & Vulnerability Assessment
Support penetration testing and vulnerability assessment activities by defining scope scenarios and priorities based on threat models and risk while keeping the roles primary focus on Cloud DevSecOps and platform security industrialization.
Validate findings ensure accurate severity rating and track remediation.
Provide expertise to interpret and communicate results to technical and non-technical stakeholders.
6. Supporting Responsibility Governance & Advisory
Provide targeted expert security advisory to IT product and business teams where it supports cloud platform SSDLC and AI security outcomes.
Contribute to security risk assessments and threat modeling exercises with emphasis on translating findings into automated and repeatable technical controls.
Review and validate compliance evidence for internal controls audits and regulatory requirements.
Develop and promote security policies standards and guidelines
Define and produce metrics
WHAT WE ARE LOOKING FOR
Technical Expertise
- 10 years in Information Security with a focus on cloud and platform security.
- Strong expertise in Azure and AWS security (primary BDC clouds) and familiarity with GCP security concepts.
- Solid experience with Kubernetes security EKS and Tanzu/RTF.
- Hands-on experience with IaC: Terraform (primary) and CloudFormation (secondary); Policy-as-Code using OPA/Conftest; IaC security scanning; and CI/CD security automation.
- Understanding of applied AI security and enterprise AI governance (nonresearch).
- Strong knowledge of security architecture cloud security frameworks and secure design patterns.
- Solid understanding of network security identity security and application security.
- Hands-on experience with vulnerability scanning tools (e.g. Qualys).
- Strong understanding of CI/CD pipelines DevSecOps practices automated security gates secrets management and code security tools (SAST/DAST/SCA) including tuning triage and false-positive reduction.
- Experience with penetration testing methodologies (OWASP PTES).
- Familiarity with secure configuration benchmarks (CIS NIST).
- Experience with threat modeling (STRIDE) is an asset.
- undefined
Experience
- Team spirit and interpersonal skills
- Sense of priorities and understanding of problems of criticality and of the impact
- Ability to translate complex security issues into clear guidance for technical and business audiences.
- Strong influencing skills; able to lead without direct authority.
- Excellent analytical and problem-solving skills.
- Collaboration with CloudOps Platform/DevOps Data/AAAI and Architecture.
- Ability to prioritize risks and manage multiple workstreams.
- Comfortable coaching security analysts
- Ability to share information with peers and transfer knowledge
- Ability to manage multiple requests and priorities head-on
- Ability to translate theoretical aspects into tactical realities and specificities of IT operations and to integrate these theoretical elements into this reality
- Ability to communicate effectively in both official languages (French and English)
Education/Certifications
- Certifications such as CISSP CCSP OSCP GWAPT or Azure/AWS Security certifications are strong assets.
#INDHP
Proudly one of Canadas Top 100 Employers and one of Canadas Best Diversity Employers we are committed to fostering a diverse equitable inclusive and accessible environment where all employees can thrive and feel empowered to bring their whole selves to work. If you require an accommodation to complete your application please do not hesitate to contact us at .
While we appreciate all applications we advise that only the candidates selected to participate in the recruitment process will be contacted.
Required Experience:
Senior IC
About Company
We are BDC, the Business Development Bank of Canada and the financial institution devoted to Canadian entrepreneurs. We help create and develop strong Canadian businesses through financing, advisory services and capital, with a focus on small and medium-sized enterprises.