Back


Détail du poste

Policy Engineer, CNAPP Product

Scotiabank

Toronto, ON

Policy Engineer, CNAPP Product

Scotiabank

Toronto, ON
 
Salary: Information not available
 

 

 

 

Requisition ID: 230935

Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.

 

The Team:

 

The Enterprise Security Services team is a dynamic group of cloud security professionals driving innovation and resilience across the organization’s cloud environments. Embedded within the Cloud & Platform Engineering (CAP) Program, the team plays a pivotal role in the Cloud Native Application Protection Platform (CNAPP) strategy, with a strong focus on Cloud Security Posture Management (CSPM) and Infrastructure-as-Code (IaC) Security.

 

We work at the intersection of security, engineering, and compliance, collaborating closely with platform teams, architects, and risk stakeholders to define and enforce scalable, policy-driven controls. Our mission is to empower secure cloud adoption through automation, transparency, and continuous improvement—ensuring that security is not a blocker, but a built-in enabler of innovation.

 

The Role:

 

As a Policy Engineer within the Enterprise Security Services team, you will play a strategic and hands-on role in shaping the security posture of our cloud environments. This position is central to the success of our Cloud Security Posture Management (CSPM) and Infrastructure-as-Code (IaC) Security initiatives, supporting the broader Cloud Native Application Protection Platform (CNAPP) roadmap.

 

You will be responsible for translating complex regulatory, architectural, and risk requirements into actionable, scalable cloud security policies. Working closely with platform engineering, cloud architects, and Policy-as-Code teams, you will ensure that security controls are seamlessly integrated into CI/CD pipelines and cloud-native workflows.

 

This role demands a strong technical foundation in GCP or Azure, hands-on experience with tools like Wiz, SCCE, and Terraform, and a deep understanding of policy-as-code principles. You’ll also collaborate with compliance and audit teams to ensure traceability and alignment with industry standards, while continuously optimizing policy effectiveness through data-driven insights.

 

If you're passionate about cloud security, policy automation, and enabling secure innovation at scale, this role offers a unique opportunity to make a meaningful impact.

 

Is this role right for you? In this role, you will: 

 

  • Design and implement cloud security policies that align with regulatory standards, technical design documents, and enterprise risk frameworks.
  • Collaborate with cross-functional teams including platform engineering, cloud architecture, and Policy-as-Code teams to ensure seamless policy integration and enforcement.
  • Translate control objectives into actionable policies using tools like Open Policy Agent, Terraform, and CSPM platforms such as Wiz and SCCE.
  • Support policy lifecycle management—from intake and triage to validation and deployment—ensuring alignment with the CNAPP product roadmap.
  • Work closely with compliance and audit teams to ensure traceability of policies to frameworks like CIS benchmarks and provide documentation for regulatory reviews.
  • Monitor and report on policy effectiveness, exceptions, and violations to drive continuous improvement and risk reduction.
  • Champion automation and scalability by embedding security controls into CI/CD and IaC pipelines, enabling secure development without friction.

 

Do you have the skills that will enable you to succeed in this role? We'd love to work with you if you have:

 

  • 3–5 years of hands-on experience in cloud security, platform engineering, or policy implementation—preferably in Azure or GCP environments.
  • Proficiency with Cloud Security tools such as Wiz, SCCE, Defender, Prisma, or Datadog.
  • Experience with Policy-as-Code frameworks like Open Policy Agent (OPA) and Terraform validations.
  • A strong understanding of regulatory frameworks (e.g., CIS benchmarks, NIST, ISO) and how they translate into technical controls.
  • A collaborative mindset with the ability to work across engineering, architecture, compliance, and risk teams.
  • Excellent communication skills, with the ability to explain complex security concepts to both technical and non-technical audiences.
  • A passion for automation, scalability, and continuous improvement in cloud security operations.
  • A bachelor's degree or equivalent experience in a related field.

 

What's in it for you?

 

  • Diversity, Equity, Inclusion & Allyship - We strive to create an inclusive culture where every employee is empowered to reach their fullest potential, respected for who they are, and are embraced through bias-free practices and inclusive values across Scotiabank. We embrace diversity and provide opportunities for all employee to learn, grow & participate through our various Employee Resource Groups (ERGs) that span across diverse gender identities, ethnicity, race, age, ability & veterans.
  • Accessibility and Workplace Accommodations - We value the unique skills and experiences each individual brings to the Bank and are committed to creating and maintaining an inclusive and accessible environment for everyone. Scotiabank continues to locate, remove and prevent barriers so that we can build a diverse and inclusive environment while meeting accessibility requirements.  
  • Upskilling through online courses, cross-functional development opportunities, and tuition assistance. 
  • Competitive Rewards program including bonus, flexible vacation, personal, sick days and benefits will start on day one.
  • Community Engagement - no matter where you choose to work from; we offer opportunities for community engagement & belonging with our various programs such as hackathons, contests, Humans of Digital and much more!

 

Location(s):  Canada : Ontario : Toronto 

Scotiabank is a leading bank in the Americas. Guided by our purpose: "for every future", we help our customers, their families and their communities achieve success through a broad range of advice, products and services, including personal and commercial banking, wealth management and private banking, corporate and investment banking, and capital markets.  

At Scotiabank, we value the unique skills and experiences each individual brings to the Bank, and are committed to creating and maintaining an inclusive and accessible environment for everyone. If you require accommodation (including, but not limited to, an accessible interview site, alternate format documents, ASL Interpreter, or Assistive Technology) during the recruitment and selection process, please let our Recruitment team know. If you require technical assistance, please click here. Candidates must apply directly online to be considered for this role. We thank all applicants for their interest in a career at Scotiabank; however, only those candidates who are selected for an interview will be contacted.

About Scotiabank

The Scotiabank Veterans Network (SVN) is committed to supporting veterans, reservists, and military spouses by recognizing and valuing their unique skills and experiences. As a military-friendly employer, Scotiabank actively promotes the integration of veterans into civilian careers by offering a wide range of employment opportunities across the Bank.  SVN plays a key role in this effort, leading initiatives such as a mentorship program designed to support both current and transitioning veterans.

The team was instrumental in driving recent enhancements to Scotiabank’s reservist leave policy and organized the inaugural Valour and Vision Expo in Q4 2024, where industry leaders pledged to support veterans entering the civilian workforce.  In February 2025, Scotiabank proudly served as the lead Banking Sponsor of the Invictus Games, an international multi-sport event that aids in the rehabilitation of wounded, injured, and ill service members—both active and retired.

Additionally, SVN hosts a variety of events throughout the year, including leadership symposiums and annual Remembrance Day ceremonies, to honor and support the military community.