Security Engineer
1 day ago
Led by Rodolphe Saadé, the CMA CGM Group, a global leader in shipping and logistics, serves more than 420 ports around the world on five continents. With its subsidiary CEVA Logistics, a world leader in logistics, and its air freight division CMA CGM AIR CARGO, the CMA CGM Group is continually innovating to offer its customers a complete and increasingly efficient range of new shipping, land, air and logistics solutions.
Committed to the energy transition in shipping, and a pioneer in the use of alternative fuels, the CMA CGM Group has set a target to become Net Zero Carbon by 2050.
Through the CMA CGM Foundation, the Group acts in humanitarian crises that require an emergency response by mobilizing the Group's shipping and logistics expertise to bring humanitarian supplies around the world.
Present in 160 countries through its network of more than 400 offices and 750 warehouses, the Group employs more than 155,000 people worldwide, including 4,000 in Marseilles where its head office is located.
POSITION SUMMARY
Responsible for securing our digital infrastructure, services, and applications across multiple environments, ensuring the confidentiality, integrity, and availability of cloud-based resources. This role is instrumental in safeguarding our cloud ecosystems and enabling secure business innovation.
RESPONSIBILITIES
- Design and implement security controls and solutions across public, private, and hybrid environments.
- Apply and maintain security baselines, guardrails, reference architectures, and security blueprints aligned with industry best practices.
- Perform security assessments using recognized frameworks, identifying risks and developing mitigation and remediation roadmaps.
- Collaborate with engineering and DevOps teams to integrate security into CI/CD pipelines and enable secure DevOps practices.
- Contribute to enabling monitoring, detecting, and responding to security threats and misconfigurations.
- Develop Identify and Access Management (IAM) policies, ensuring proper role-based access control, least privilege, and identity federation.
- Contribute to security strategy and roadmap by identifying emerging threats, opportunities for automation, and process improvements.
- Contribute to maintaining compliance with regulatory and industry standards such as ISO 27001, NIST, SOC 2, CIS Benchmarks, and GDPR.
- Support architecture and application teams by providing security guidance on architecture reviews, threat modeling, and risk assessments.
- Evaluate and implement security technologies, including workload protection, data loss prevention (DLP), encryption, container security, and secrets management.
- Collaborate with internal stakeholders to create and enforce -specific security policies, standards, and procedures.
- Stay current with evolving security trends, threat landscapes, and vendor roadmaps to ensure proactive risk management.
QUALIFICATIONS
Education:
- You hold a Bachelor's or Master's degree in Computer Science, Information Technology, or a related cybersecurity field.
- Cybersecurity & Cloud security Certifications are an asset
Knowledge & Experience:
- engineering across enterprise-scale environments.
- Experience working with multi-domain and hybrid infrastructures is highly valued.
- Experience to automated security tooling, cloud-native logging, and infrastructure-as-code (IaC) security is required.
- Strong hands-on knowledge of at least one major cloud provider (AWS, Azure, or GCP) and its security capabilities.
- Familiarity with security frameworks and compliance standards.
- Proficiency in implementing and managing security solutions in different environments and setups.
- Experience with cloud-native security tools such as AWS Security Hub, Azure Defender, GCP Security Command Center, or third-party platforms.
- Working knowledge of containers and Kubernetes security is considered an advantage.
- Experience implementing IAM controls, including RBAC, least privilege, and identity federation
Other:
- Detail-oriented, analytical, and proactive in identifying and resolving cloud security issues.
- Strong collaboration and communication skills, working seamlessly with cross-functional teams including DevOps, infrastructure, and compliance.
- You thrive in a fast-paced, cloud-first environment.
- Strong problem-solving capabilities.
- Prioritize work effectively, managing time and competing demands efficiently.
- English required and French language is an asset.
We thank all candidates for their interest in applying for this position and working at CMA CGM, please note, only those selected for an interview will be contacted.
We are an equal opportunity employer
Come along on CMA CGM's adventure
-
Lead Security Engineer
1 week ago
Montreal, Quebec, Canada US Mobile Full time $150,000 - $200,000 per yearUS Mobile is on a mission to revolutionize connectivity. Imagine a world where you can go into a single app and buy terabytes of data for every one of your devices: phone, smart devices, car, home broadband, and more. That's the future that US Mobile is building: a software platform built truly for the 21st century and the age of 5G and IoT, with world class...
-
Security Research Engineer
1 week ago
Montreal, Quebec, Canada Boostsecurity Full time $80,000 - $120,000 per yearAbout Us is a cybersecurity technology startup. Our mission is to enable software teams to easily ship secure software, and secure their software supply chains, through smart security automation that developers love. Founded by veteran industry experts in application security, cloud and OSS engineering, BoostSecurity is headquartered in Montreal, Canada,...
-
Cyber Security Engineer
1 week ago
Montreal, Quebec, Canada Vaspire Technologies Inc. Full time $85,000 - $115,000 per yearJob Description Summary:We are looking 5-8 years experienced Cybersecurity Engineer who can work in project Cybersecurity Management Plan. He/She is able to analyze Project security needs (including laws and local regulations), determine security objectives and main security risks strategy. Also, can plan security activities within development life cycle and...
-
Web Security Proxy Engineer
23 hours ago
Montreal, Quebec, Canada Saransh Inc Full time US$80,000 - US$140,000 per yearRole Title: Web Security Proxy EngineerLocation: Hybrid Onsite – Montreal, Canada (3–4 days onsite expected) – Only local profilesResponsibilitiesLead web engineerWeb Security Proxy EngineerA skilled and proactive Web Security Proxy Engineer to design, implement, and maintain secure web access infrastructure across the enterprise. This role focuses on...
-
Cloud Security Engineer
3 days ago
Montreal, Quebec, Canada Everflow Full time $100,000 - $130,000About the roleWe are seeking a proactive and skilled Cloud Security Engineer to be our primary resource for security projects within our Google Cloud Platform (GCP) and to serve as the main systems administrator for our local office and core IT operations.This dual-focus role requires expertise in building and securing cloud environments while also...
-
Cloud Security Engineer
3 days ago
Montreal, Quebec, Canada Everflow - Partner Marketing Platform Full time US$100,000 - US$130,000 per yearThe CompanyEverflow is a SaaS Partner Marketing platform for managing and scaling revenue from affiliates, partnerships, and marketing channels. Founded in 2016 by industry veterans, we are based in Oakland, Montreal and Amsterdam with a distributed team across the NAM and EMEA regions.We're a bootstrapped company (over $30M ARR) that has grown through...
-
Security Engineer
1 week ago
Montreal, Quebec, Canada Asset Inventories Full time $120,000 - $150,000 per yearOverviewWe are seeking a skilled and dedicated Security Engineer with expertise in Active Directory and Iron Port to join our team in Montreal, Canada.ResponsibilitiesCommunicate clearly and collaborate with team members to work toward successful execution of tasks; Provide Out of Hours support on an On-Call roster/rotation basisManage full life cycle of...
-
Web Security Proxy Engineer
3 days ago
Montreal, Quebec, Canada Roshan Consulting Services Full time $60,000 - $120,000 per yearCompany DescriptionRoshan Consulting Services is dedicated to empowering businesses to optimize operations and achieve efficiency through innovative solutions. Specializing in areas like robotic process automation (RPA), business process optimization, and strategic consulting, we design cutting-edge strategies to address our clients' unique challenges. With...
-
Web Security Proxy Engineer
3 days ago
Montreal, Quebec, Canada AIT Global Inc Full time $104,000 - $156,000 per yearJob Title: Web Security Proxy EngineerLocation: Montreal, QC Hybrid (3-4 days onsite in a week)Job Description:A skilled and proactive Web Security Proxy Engineer to design, implement, and maintain secure web access infrastructure across the enterprise. This role focuses on managing web proxy solutions, enforcing internet usage policies, and protecting users...
-
Security Engineer – Malware Architecture
2 weeks ago
Montreal, Quebec, Canada NOVIPRO Full time $120,000 - $180,000 per yearNOVIPRO is acting as a recruitment partner for a leading financial-sector organization known for its advanced IT infrastructure and adherence to high regulatory standards. The position sought after is Security Engineer – Malware Architecture & Operations. Key Information & TermsJob Title: Security Engineer – Malware Architecture & OperationsContract...