Cloud Security Specialist
Operations · Full-time
Burnaby, BC, Canada
CAD 119k-136k / year + Equity
Join Fortinet, a cybersecurity pioneer with over two decades of excellence, as we continue to shape the future of cybersecurity and redefine the intersection of networking and security. At Fortinet, our mission is to safeguard people, devices, and data everywhere
The Fortinet Team is looking for a Cloud Security Specialist to join the Information Security team within our R&D organization. This is a highly technical, hands-on role, working directly with product development, DevOps and cloud operation teams to secure Fortinet’s cloud products and service infrastructure across the development lifecycle, and assisting the Information Security leadership with security testing and evaluation activities.
Job Responsibilities:
Manage the end-to-end vulnerability lifecycle - triage findings from security evaluations and scans, prioritize by risk and exploitability, and coordinate remediation with R&D product, service and engineering teams.
Participate in daily SOC operation, monitor and triage security alerts. Collaborate with Cloud operation teams in resolving security events.
Lead security incident response for Fortinet cloud services - detect, investigate, and contain incidents, coordinate cross-team remediation and recovery, and conduct post-incident reviews to capture root cause and strengthen preventive controls.
Integrate security practices into R&D’s CI/CD process - embed SAST, DAST, software composition analysis, container image scanning, secret detection and infrastructure-as-code security checks into build and release pipelines, define security gates and release criteria, and work with development teams to triage and tune results so security scales with engineering velocity.
Support security compliance requirements - provide evidence for internal and external audits and certification efforts (e.g. ISO 27001), perform CIS Benchmark assessments of cloud products and infrastructure, map results to the relevant controls, document findings, and assist R&D teams in tracking identified gaps to closure.
Participating in design and implementation of an AI based cloud security posture management system, primarily focusing on public IP scan and security exposure analysis.
Collect, analyze threat intelligence and evaluate the risks.
Skills and Qualifications:
5+ years of dedicated experience in security engineering role, e.g. Security Engineer, Penetration Tester or DevSecOps/SRE.
Hands-on experience with FortiSIEM, FortiAnalyzer, and FortiSOAR (or equivalent enterprise SIEM and SOAR tools) are required.
System administration experience with security infrastructure - hands-on deployment, configuration and day-to-day administration of firewalls (FortiGate or equivalent), VPN and SIEM, including policy and rule management, log source onboarding and health monitoring.
Experience with system backup and maintenance – Linux server administration, backup and restore procedures, patching and upgrade cycles, and high availability / disaster recovery operations.
Familiar with vulnerability scanning tools such as Nessus, Nuclei or Wiz/Lacework.
Experience of applying Agentic AI to security operations - designing and deploying AI agents that automate SOC workflows such as alert triage, threat hunting, and response orchestration, accelerating mean-time-to-detect and mean-time-to-respond.
Understanding of the security risks unique to AI systems - prompt injection, insecure agent tool/function calling, model and data poisoning and with the ability to evaluate and test LLM-backed applications.
Strong knowledge of the fundamentals of web applications including authentication, authorization, session management, HTTP protocol, web language, web server and browser architecture and implementation principle.
-
Proficient programming ability with programming languages in order to conduct security code review and develop scripts and programs to help enrich security scan efficiency and penetration testing automation and dive in-depth ability.
Educational & Certification Requirements:
Bachelor's degree in Computer Science, Information Security, Electrical Engineering or related field
The Canada base salary range for this full-time position is expected to be between $119,000 - $136,000 annually. Wage ranges are based on various factors including the labour market, job type, and job level. Exact salary offers will be determined by factors such as the candidate’s subject knowledge, skill level, qualifications, and experience.
Fortinet strives to provide you and your family with a comprehensive benefits package. Benefits eligibility starts on your first day of hire and comprises of 100% company paid medical, dental, and vision coverage, including a Health Spending Account and a Personal Spending Account that gives you flexibility to spend where you need it the most. Our Employee & Family Assistance Plan (EFAP) offers you and your family access to various services like counseling, legal advice, mental health resources etc. We also provide critical illness, disability, and life insurance, as well as a Group Registered Retirement Savings Plan (RRSP) with a company match to help you save faster for retirement. We offer competitive Paid Time Off and flexible leave policies, including paid health days, to help you take care of yourself and your family members.
All roles are eligible to participate in the Fortinet equity program. Bonus eligibility is reviewed at time of hire and annually at the Company’s discretion.
The Fortinet Team is looking for a Cloud Security Specialist to join the Information Security team within our R&D organization. This is a highly technical, hands-on role, working directly with product development, DevOps and cloud operation teams to secure Fortinet’s cloud products and service infrastructure across the development lifecycle, and assisting the Information Security leadership with security testing and evaluation activities.