Lead, Cyber Security Control & Defense

Scarborough, ON, CA, M1K5L1

⚠️ We'll shut down after Aug 1st - try foo🦍 for all jobs in tech ⚠️

Apply now Apply later

 

 

 

Requisition ID: 232282

Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.

 

Purpose


We are seeking a highly skilled and experienced Lead Policy Engineer specializing in Email and Web Security to join our Cybersecurity team. The successful candidate will be responsible for the design, implementation, governance, and continuous improvement of security policies related to email protection, web proxy, and content filtering technologies. This individual will lead efforts to reduce attack surfaces, mitigate threats, and ensure policy compliance across the enterprise environment.

 

Is this role right for you? In this role you will:

 

  • Lead the design and implementation of enterprise-wide policies for email and web security platforms (e.g., Microsoft Defender for Office 365, Proofpoint, Cisco Email Security, Zscaler, Symantec, Forcepoint).
  • Define and manage content filtering policies to control sensitive data movement over email and web channels.
  • Tune and optimize policies to reduce false positives while maintaining strong protection against phishing, malware, and data exfiltration.
  • Collaborate with Security Operations, IT, Legal, and Compliance teams to define acceptable use policies and incident handling workflows.
  • Perform risk assessments and impact analyses related to changes in policy or new controls.
  • Lead incident response support and forensic analysis involving email and web-based threats.
  • Document policies, technical configurations, change management records, and exceptions.
  • Review and analyze email and web security telemetry to identify patterns and policy improvements.
  • Maintain expert-level understanding of email threat vectors, web-based attacks, zero-day exploit prevention, sandboxing, TLS inspection, and user behavior analytics.
  • Assist with integration and automation of policy enforcement via APIs and SIEM 

 

Do you have the skills that will enable you to succeed in this role? We’d love to work with you if you have:

 

  • Minimum 7+ years of experience in cybersecurity, with 3+ years focused on email and web security.
  • Strong hands-on experience with one or more platforms:
  • Email: Proofpoint, Cisco ESA, Symantec
  • Web: Zscaler ZIA,  Forcepoint Web Proxy, Broadcom
  • Advanced knowledge of mail routing, SPF/DKIM/DMARC, TLS, SMTP filtering, URL filtering, and CASB functionality.
  • Solid understanding of Zero Trust, SASE, and Cloud Security Architectures.
  • Proficiency in policy development, regex, YARA rules, JSON/XML-based configurations, and policy scripting.
  • Experience with SIEM/SOAR, EDR integrations, and automated alert enrichment.
  • Strong analytical, communication, and documentation skills.
  • Familiarity with regulatory frameworks such as GDPR, HIPAA, SOX, and ISO 27001.

 

What's in it for you?

 

  • Diversity, Equity, Inclusion & Allyship - We strive to create an inclusive culture where every employee is empowered to reach their fullest potential, respected for who they are, and are embraced through bias-free practices and inclusive values across Scotiabank. We embrace diversity and provide opportunities for all employee to learn, grow & participate through our various Employee Resource Groups (ERGs) that span across diverse gender identities, ethnicity, race, age, ability & veterans.
  • Accessibility and Workplace Accommodations - We value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. Scotiabank continues to locate, remove and prevent barriers so that we can build a diverse and inclusive environment while meeting accessibility requirements.  
  • Upskilling through online courses, cross-functional development opportunities, and tuition assistance. 
  • Competitive Rewards program including bonus, flexible vacation, personal, sick days and benefits will start on day one.
  • Dynamic Ecosystem - Free tea & coffee, universal washrooms, and lots of space for team collaboration.
  • Community Engagement - No matter where you choose to work from; we offer opportunities for community engagement & belonging with our various programs.

 

 

Location(s):  Canada : Ontario : Scarborough 

Scotiabank is a leading bank in the Americas. Guided by our purpose: "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.  

At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know. If you require technical assistance, please click here. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.

Apply now Apply later

* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰

Job stats:  0  0  0
Category: Leadership Jobs

Tags: Analytics APIs Automation Banking CASB Cloud Compliance EDR Exploit GDPR Governance HIPAA Incident response ISO 27001 JSON Malware Risk assessment SASE Scripting SIEM SMTP SOAR SOX TLS XML Zero-day Zero Trust

Perks/benefits: Career development Flex vacation Salary bonus

Region: Europe
Country: United Kingdom

More jobs like this

Explore more career opportunities

Find even more open roles below ordered by popularity of job title or skills/products/technologies used.