Cyber Security Engineer
21 hours ago
Surrey, Metro Vancouver Regional District, Canada
Socket.dev
Full-time
€90,000 - €100,000 Contract
Free with email or Google
Save this job and keep your search organized
Create a free account to save jobs, create alerts and return to this listing from your dashboard.
Free with email or Google
Cyber Security Engineer
About GroupHEALTH
At GroupHEALTH, we're proud of the work we do – but it's how we do it that truly sets us apart. We're a fast-moving, ever‑evolving, stable organization with deep roots and a bold vision: to transform the way Canadians experience benefits. We combine agility with long‑term stability to create meaningful impact.
Here, you'll find more than just a job. You'll find a purpose‑driven, people‑first culture where kindness, collaboration, and curiosity thrive. Whether you've been here fifteen years or fifteen days, you'll notice right away – our people are genuinely invested in one another's success and delivering exceptional experiences to our clients and plan members.
About the Role
The Cyber Security Engineer will implement, operate, and continuously improve technical security controls across the organization. The role protects identities, endpoints, cloud environments, networks, applications, and data by identifying and remediating security risks, improving detection capabilities, and providing hands‑on technical support during security incidents. This is a hybrid role based out of our Surrey, BC office, working 3 days in office and 2 days from home. What to Expect in Your First 3 Months First 30 Days:
- Complete onboarding and assess the organization's technology and security environment, identifying priority vulnerabilities, misconfigurations, monitoring gaps, and remediation opportunities. First 60 Days:
- Begin remediation of prioritized security gaps across identity, endpoint, cloud, network, and infrastructure environments.
- Establish or improve vulnerability management processes to ensure critical and high‑risk vulnerabilities are identified, prioritized, tracked, remediated, and validated. First 90 Days:
- Demonstrate measurable improvement in technical security posture through remediation of priority vulnerabilities, misconfigurations, and security control gaps.
- Improve security monitoring and detection capabilities through alert tuning, enhanced detections, and technical incident response playbooks.
- Establish a prioritized security engineering backlog aligned with the Cyber Security roadmap and provide measurable technical security metrics for ongoing reporting.
What You'll Do
- Implement and maintain technical security controls across endpoints, identities, cloud platforms, networks, and infrastructure
- Administer, configure, monitor, and optimize security platforms and tools
- Monitor and investigate security alerts, suspicious activities and potential security incidents
- Perform technical investigation, containment, remediation, and root‑cause analysis during security incidents
- Support the Cyber Security Manager during P1 and P2 security incidents
- Operate and continuously improve the vulnerability management program
- Identify security vulnerabilities, misconfigurations and control gaps and coordinate remediation with technology teams
- Implement and maintain identity security controls including MFA, Conditional Access, privileged access, and least privilege
- Support endpoint, email, cloud and Microsoft 365 security controls
- Develop and improve security detections, alerts, dashboards, queries, and incident response playbooks
- Support SIEM, EDR/XDR, vulnerability management, and security monitoring capabilities
- Develop scripts and automation to improve security operations and reduce manual effort
- Support penetration testing engagements and track technical findings through remediation
- Provide technical evidence for audits, risk assessments, regulatory requirements, cyber insurance, and third‑party reviews
- Participate in security architecture and technical design reviews for new systems and significant technology changes
- Maintain accurate technical security documentation, procedures, configurations, and diagrams
- Stay current on emerging threats, vulnerabilities, attack techniques, and security technologies What We're Looking For
- Bachelor's degree in Cyber Security, Information Security, Computer Science, Information Technology, or a related field; equivalent experience considered
- 3-5 years of hands‑on experience in cyber security, security engineering, security operations, infrastructure security, or a related technical security role
- Demonstrated experience implementing and operating enterprise security controls
- Hands‑on experience investigating security alerts and incidents
- Experience with vulnerability management, security hardening, and remediation
- Experience securing Microsoft enterprise environments, including Microsoft 365, Azure, and Entra ID
- Experience with SIEM, EDR/XDR, identity security, endpoint security, and vulnerability management technologies
- Experience with PowerShell, KQL, Python, APIs, or other security automation technologies is an asset
- Experience in insurance, healthcare, financial services, or another regulated environment is an asset
- Knowledge of
About the Role
The Cyber Security Engineer will implement, operate, and continuously improve technical security controls across the organization. The role protects identities, endpoints, cloud environments, networks, applications, and data by identifying and remediating security risks, improving detection capabilities, and providing hands‑on technical support during security incidents. This is a hybrid role based out of our Surrey, BC office, working 3 days in office and 2 days from home. What to Expect in Your First 3 Months First 30 Days:
- Complete onboarding and assess the organization's technology and security environment, identifying priority vulnerabilities, misconfigurations, monitoring gaps, and remediation opportunities. First 60 Days:
- Begin remediation of prioritized security gaps across identity, endpoint, cloud, network, and infrastructure environments.
- Establish or improve vulnerability management processes to ensure critical and high‑risk vulnerabilities are identified, prioritized, tracked, remediated, and validated. First 90 Days:
- Demonstrate measurable improvement in technical security posture through remediation of priority vulnerabilities, misconfigurations, and security control gaps.
- Improve security monitoring and detection capabilities through alert tuning, enhanced detections, and technical incident response playbooks.
- Establish a prioritized security engineering backlog aligned with the Cyber Security roadmap and provide measurable technical security metrics for ongoing reporting.
What You'll Do
- Implement and maintain technical security controls across endpoints, identities, cloud platforms, networks, and infrastructure
- Administer, configure, monitor, and optimize security platforms and tools
- Monitor and investigate security alerts, suspicious activities and potential security incidents
- Perform technical investigation, containment, remediation, and root‑cause analysis during security incidents
- Support the Cyber Security Manager during P1 and P2 security incidents
- Operate and continuously improve the vulnerability management program
- Identify security vulnerabilities, misconfigurations and control gaps and coordinate remediation with technology teams
- Implement and maintain identity security controls including MFA, Conditional Access, privileged access, and least privilege
- Support endpoint, email, cloud and Microsoft 365 security controls
- Develop and improve security detections, alerts, dashboards, queries, and incident response playbooks
- Support SIEM, EDR/XDR, vulnerability management, and security monitoring capabilities
- Develop scripts and automation to improve security operations and reduce manual effort
- Support penetration testing engagements and track technical findings through remediation
- Provide technical evidence for audits, risk assessments, regulatory requirements, cyber insurance, and third‑party reviews
- Participate in security architecture and technical design reviews for new systems and significant technology changes
- Maintain accurate technical security documentation, procedures, configurations, and diagrams
- Stay current on emerging threats, vulnerabilities, attack techniques, and security technologies What We're Looking For
- Bachelor's degree in Cyber Security, Information Security, Computer Science, Information Technology, or a related field; equivalent experience considered
- 3-5 years of hands‑on experience in cyber security, security engineering, security operations, infrastructure security, or a related technical security role
- Demonstrated experience implementing and operating enterprise security controls
- Hands‑on experience investigating security alerts and incidents
- Experience with vulnerability management, security hardening, and remediation
- Experience securing Microsoft enterprise environments, including Microsoft 365, Azure, and Entra ID
- Experience with SIEM, EDR/XDR, identity security, endpoint security, and vulnerability management technologies
- Experience with PowerShell, KQL, Python, APIs, or other security automation technologies is an asset
- Experience in insurance, healthcare, financial services, or another regulated environment is an asset
- Knowledge of