Security Engineer/Analyst
Toronto, Ontario, Ca
**Business/Administrative Security**- Spearheaded the initiative to successfully attain the SOC 2 Type 1 certification for Cyclica, by authoring comprehensive policies with a focus on the NIST 800-53 standards.- Conducted informative presentations and training sessions to enhance security awareness and comprehension among employees. Devised extensive documentation to bolster security measures within the team.**Security Engineering**- Guided the reengineering of Cyclica's GCP environment project structure, emphasizing on security standards. Emphasized principles of least privilege and least access.- Integrated Terraform, a novel language and framework into Cyclica's tech stack. This was aimed at transforming infrastructure management to modernize DevSecOps practices and implement Infrastructure as Code (IaC) with GitOps.- Initiated and deployed security standard-oriented code for various applications, aligning with the objective to update the organization's security practices.- Contributed to the modernization of our Ansible code.**Security Operations**- Performed a spectrum of vulnerability and network scans to assess the security posture of our applications and cloud infrastructure.- Conducted penetration testing to evaluate various aspects of our code and application. Identified bugs and exploits, and performed incidence responses to promptly rectify issues.- Implemented RMM solutions to bolster the security and monitoring of Cyclica's hardware. Authored scripts to enhance Linux OS security.- Evaluated physical security measures in compliance with SOC 2 standards, and recommended various enhancements for the company to implement.**IT Security**- Introduced a variety of IT security tools to Cyclica employees to bolster company security. These included the usage of password managers and hardware keys.- Assisted the IT team in reconfiguring our server space by installing switches, gateways, and relevant software such as NGFW.