Information Security Engineer (Cloud) - Contract
OtherInformation Security Engineer
1 views0 saves0 applied
Quick Summary
Overview
Numeris is Canada’s most trusted and authoritative source for broadcast measurement and consumer behaviour data. As well, the industry leading intelligence provider to broadcasters, advertisers,
Technical Tools
OtherInformation Security Engineer
Numeris is Canada’s most trusted and authoritative source for broadcast measurement and consumer behaviour data. As well, the industry leading intelligence provider to broadcasters, advertisers, and agencies. We have been recognized for over 75 years as providing the gold standard in audience intelligence.
We have great people who do exceptional work. We take pride in building an environment of continuous learning and career advancement opportunities. Our teams are collaborative, curious, and dedicated to creating quality experiences. We love what we do, enjoy each other’s company, and support initiatives to give back to our communities. We are looking for people to help us shape the future of Numeris, and have a lot of fun along the way.
Numeris is seeking a collaborative, detail-oriented Cloud Security Analyst to support our multi-cloud posture, vulnerability management lifecycle, and cybersecurity risk governance.
In this role, you will bridge technical security tooling, operational governance, and day-to-day security service delivery. You will monitor and strengthen security posture across AWS, Azure, and Microsoft 365, evaluate change requests for cyber risk, conduct security risk assessments, manage intake for security requests, and partner with internal engineering and IT teams to drive identified risks, vulnerabilities, and hardening recommendations through to remediation.
Cloud Security Posture & Hardening (AWS, Azure & M365):
-
Monitor and operate Cloud Security Posture Management (CSPM) tooling to identify high-priority misconfigurations, network exposures, and toxic risk combinations across AWS and Azure.
-
Continuously monitor and improve Microsoft Secure Score, driving actionable configuration enhancements across Entra ID, Defender, and Purview.
-
Partner directly with internal DevOps, Infrastructure, and Systems teams to translate posture findings into clear remediation tasks, track remediation timelines, and verify fixes.
-
Implement and maintain cloud hardening baselines, data boundaries, and security guardrails—including over-permissioning reviews and sensitivity controls supporting Microsoft 365 Copilot and multi-cloud environments.
-
Manage security intake by evaluating, triaging, and responding to day-to-day security requests, access exceptions, and technical risk inquiries from business and technical teams.
-
Perform technical cyber risk assessments for new vendors, cloud architectures, and third-party SaaS integrations.
-
Review proposed infrastructure and IT change requests (CAB) to evaluate security impacts, network perimeter exposure, and identity/access risks.
-
Document risks, track exceptions, and collaborate with system owners to establish practical compensating controls and standard operating procedures (SOPs).
-
Coordinate vulnerability management workflows: prioritize vulnerabilities using risk and exploitability context, assign remediation tasks to asset owners, and validate patches.
-
Provide operational administration for core security tooling (Defender suite, Entra ID, Purview, KnowBe4).
-
Author and maintain operational runbooks, security guidelines, and triage procedures to streamline day-to-day security workflows.
-
Support security operations with alert triage, investigation assistance, and operational incident follow-ups as needed.
Cyber Risk, Change Assessment & Request Handling:
Vulnerability Management & Operations Support:
-
3+ years of hands-on experience in cybersecurity, cloud security analysis, vulnerability management, or security operations (SOC/SecOps).
-
Direct operational experience working within Microsoft 365 security portals (Entra ID, Microsoft Defender, Purview).
-
Practical familiarity with AWS and/or Azure core security principles (IAM, security groups, resource hardening).
-
Proven experience managing security request intake, evaluating risk exceptions, and authoring standard operating procedures (SOPs), runbooks, and process documentation to improve operational consistency.
-
Demonstrated ability to collaborate constructively with internal technical teams (IT, DevOps, Engineering) to facilitate and track vulnerability/misconfiguration fixes.
-
Solid working understanding of Cloud Security Posture Management (CSPM) concepts and SaaS security hygiene.
-
Familiarity with identity security controls (MFA, Conditional Access, least-privilege RBAC).
-
Strong understanding of technical risk assessments, IT change management processes, and request ticketing workflows.
-
Baseline understanding of data protection and permission governance for modern AI productivity tools.
-
Collaborative Influence: Ability to build positive relationships with DevOps, IT, and software engineering teams, driving remediation through partnership rather than acting as a blocker.
-
Pragmatic Risk Prioritization: Strong analytical judgment to filter through alert noise, distinguish critical business risks from low-impact findings, and avoid "alert fatigue."
-
Clear & Empathetic Communication: Skill in translating technical cyber risks into clear, business-friendly language for non-technical stakeholders and system owners.
-
Curiosity & Adaptability: A proactive mindset for learning emerging platforms, evaluating new cloud features, and staying updated on evolving AI and SaaS security practices.
-
Organizational Discipline: Ability to juggle multiple intake requests, triage queues, and remediation follow-ups systematically without letting tasks slip through the cracks.
-
Microsoft SC-200, SC-300, or AZ-500
-
CompTIA Security+ or CySA+
-
AWS Certified Cloud Practitioner or Solutions Architect Associate
Technical Knowledge:
Soft Skills & Core Competencies:
Preferred Certifications (Asset):
Values
We succeed through collaboration with each other and with the industry. Unity drives our impact.
We embrace change and challenge convention. Our innovation is purposeful, driven by insights, guided by strategy, and focused on delivering meaningful future-proofed solutions.
We prioritize the well-being, growth and voices of our people. We actively listen, support development, and create space where everyone can succeed.
We pursue continuous improvement in everything we do, from our processes to our time to market. With a growth mindset and a commitment to excellence, we bring solutions to life with precision and purpose.
We are committed to creating an accessible environment for all our employees and foster a culture that focuses on diversity, equity, inclusion and belonging. We believe that a diverse workforce helps everyone contribute in meaningful ways towards our shared success.
Location & Eligibility
Where is the job
Toronto, Canada
Hybrid — some on-site time required
Who can apply
CA
Listing Details
- Posted
- October 5, 2026
- First seen
- October 5, 2026
- Last seen
- October 5, 2026
Posting Health
- Days active
- 0
- Repost count
- 0
- Trust Level
- 73%
- Scored at
- October 5, 2026
Signal breakdown
freshnesssource trustcontent trustemployer trust
Browse Similar Jobs
Newsletter
Stay ahead of the market
Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.
A
B
C
D
No spam. Unsubscribe at any time.